Built for CMMC Level 2 and NIST SP 800-171

Compliance answers, quoted word for word.

Stuword answers your team’s compliance questions from your own verified documents and the controlling standard. Every answer quotes the exact clause. When your documents don’t cover something, it says so.

Now onboarding design partners: small and mid-size defense manufacturers.
Do we need MFA on the shop-floor terminals?
Stu T1 · obligation ✓ 3/3 citations verified

Yes. Your Access Control Policy requires MFA for all administrative access to production systems, naming CNC and MES terminals1. NIST SP 800-171 also requires it for network access by non-privileged accounts2.

1
“Multifactor authentication shall be enforced for remote access and for all administrative access to production systems, including CNC and MES terminals.”
Your documents§4.2Access Control Policy v3
2
“Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.”
800-171 pack3.5.3NIST SP 800-171 rev. 2
Each quote is matched against verified text before the answer is shown.
Built around
CMMC 2.0Level 2 readiness
NIST SP 800-171rev. 2 · 110 controls
DFARS252.204-7012
No CUI in pilotpre-index CUI screen
Human sign-offnamed reviewer + audit log

Live demo

Ask Stu a question.

This is the Stuword workspace for a sample manufacturer, Meridian Precision. Click an example question or type your own, then open the Library and Review queue tabs.

  1. Ask about MFA
  2. Ask about visitor tours
  3. Ask for an export classification
  4. Request an action list
  5. Approve a page in the Library
app.stuword.com/meridian/ask
Interactive
stuword
Compliance, word for word.
Meridian Precision Manufacturing
Sample workspace

Ask Stu

Cited answers from Meridian's verified documents and the NIST SP 800-171 pack — word for word. Anything outside your documents is labeled, and hard calls go to a person.

Corpus verified
71%
37 of 52 pages cleared
Queryable today
3 of 5 docs
verified content only
Citation checks · 7 days
100%
41 answers · 0 stripped citations
DocumentClassVerifiedStatus
Held before indexing — possible CUI. The pre-index screen flagged system-diagram captions and network details consistent with CUI. Your pilot excludes CUI from this hosted environment (Pilot Agreement §4). Remove the flagged sections and re-upload, or keep this document out of Stuword. Nothing from this file is queryable, and it was not embedded. Screen log #0871
Verification workbench — Access Control Policy Page 8 of 14 · avg 41s per page
Source scan · p.8

4. AUTHENTICATION REQUIREMENTS

4.1 All user accounts shall be uniquely assigned. Shared or group accounts are prohibited on systems that store or process controlled information.

4.2 Multifactor authentication shall be enforced for remote access and for all administrative access to production systems, including CNC and MES terminals.

Parsed text · anchors

§4.1All user accounts shall be uniquely assigned. Shared or group accounts are prohibited on systems that store or process controlled information.

§4.2Multifactor authentication shall be enforced for remote access and for all administrative access to production systems, including CNC and MES terminals.

⚠ Low OCR confidence on the span above. Source says CNC and MES terminals — confirm or correct before this page is queryable.
Approved pages become queryable immediately — the rest of the document stays gated.
T2 · draft awaiting review Action list: close MFA gaps requested by J. Ortiz · Production

Stu drafted a 3-item action list from §4.2 of the Access Control Policy and 800-171 §3.5.3. Employees see it only as DRAFT — NOT REVIEWED until you approve. Your approval is written to the audit log.

✓ Published — logged as audit #1284
Scope appeal Off-domain question appealed by R. Chen · HR
"Does our parental leave policy meet the new state requirement?"

Blocked by the scope gate — HR benefits isn't in Meridian's configured domains. Approving answers this request only; widening the domain list is a separate, audited admin action.

✓ Approved once — guardrails unchanged, logged #1285
Outside pilot scope Export-control question asked by J. Ortiz · Production
"What's the ECCN for the torque actuator housing?"
Export classification is contractually out of scope for this pilot and cannot be enabled from this console. The requester was routed to Meridian's empowered official. No appeal path exists for this category by design.

Guardrail audit trail

  • Jul 20 · 09:41 · scope-gate blocked export-control query · routed to empowered official · #1283
  • Jul 19 · 16:07 · guardrail policy v7 activated after eval pass (12/12) · by D. Reyes · #1281
  • Jul 19 · 11:52 · SSP upload quarantined at pre-index CUI screen · #0871
Sample tenant with scripted answers. No live model calls run on this page.

What your team gets

Answers your assessor can trace back to the page.

Generic AI tools summarize and guess. Stuword quotes your verified text, checks every citation mechanically, and keeps a person in charge of anything your team would act on.

Cited answers, not summaries

Every claim quotes and links its source clause. A mechanical check verifies each citation against the verified text before the answer is shown. A citation that doesn’t match is stripped, visibly.

Your documents, verified first

Uploads pass OCR and a page-by-page review by your designated reviewer. Nothing unverified is ever quoted, and the answer tells you when a document is still pending.

Recommendations are gated

“What should we do” lists arrive as drafts pending your named reviewer’s sign-off, recorded in an audit log. Employees never act on unreviewed output.

110
800-171 security requirements in the maintained standards pack
100%
of citations checked against verified text before display
0
unverified passages quoted to your team
1
named reviewer signs off every recommendation

How a pilot runs

Useful in week one. Verification never blocks what’s cleared.

Start with your highest-value policies. Each document becomes queryable as your reviewer clears it, with hands-on onboarding from us.

1
Day 1

Upload your corpus

Policies, procedures and plans. A pre-index screen holds back anything that looks like CUI before it enters the system.

2
Weeks 1–2

Verify page by page

Your reviewer confirms parsed text against the source scan in a side-by-side workbench.

3
From week 1

Your team asks questions

Anyone you authorize gets cited answers on the documents that have already cleared.

4
Ongoing

Review, then rely

Draft action lists queue for your compliance owner. The audit trail records who asked, what was answered and from which document version.

Security and scope

The boundaries are the point.

Stuword is designed for regulated teams, so it refuses the questions software shouldn’t answer and keeps controlled data out of the hosted pilot.

“A confidently wrong classification is the one answer nobody should get from software.” Why Stu routes export-control questions to a person

No CUI in the hosted pilot

The pilot runs on public standards plus your uncontrolled policies. Documents flagged as possible CUI are quarantined before indexing. You are never asked to put controlled data in the cloud.

Export-control questions go to people

Stuword refuses classification, jurisdiction and licensing questions by design and routes them to your empowered official or export counsel.

Informational, with the paper trail to prove it

Stuword is a research tool, not legal or regulatory advice. It gives you cited sources, verified text and named human review: a diligence record your assessor can read.

Questions

What teams ask us first.

Who is Stuword for?

Small and mid-size manufacturers in the defense supply chain preparing for CMMC Level 2, where one or two people carry compliance and everyone else keeps asking them what the policy says.

Where do the answers come from?

Only two places: the NIST SP 800-171 standard, which we maintain and verify, and your own policies after your reviewer has verified them. Stu does not answer from general web knowledge.

Do we have to upload CUI?

No. The hosted pilot excludes CUI by agreement. A pre-index screen quarantines anything that looks like controlled information before it is embedded or made queryable.

How long until my team gets value?

Most teams ask their first cited questions in week one. Each document becomes queryable as soon as its pages are verified, so you never wait for the whole corpus.

Is this legal or compliance advice?

No. Stuword reports what your verified documents and the standard say, with citations. Compliance decisions stay with your qualified staff, and the audit log shows that they did.

Design-partner pilot

See Stu answer from your own policies.

A 30-minute call with the founder. We walk through the product, look at where your CMMC preparation stands, and decide together whether a pilot makes sense.

  • A live walkthrough of the questions your team asks most
  • Which of your documents to verify first
  • Pilot scope, timeline and terms, with no obligation

We reply within one business day with times that work.

✓ Request received

Thanks. We’ll be in touch.

Look for an email from the Stuword founder within one business day with a few times to meet.