This is not a compliance audit

Millabs is not a 3PAO and does not perform independent assessments. That role exists, it is accredited, and it is constrained — an independent assessor hands you findings and is barred from fixing them.

An Enclave Fit Study is an engineering scoping study. Your application is deployed into a Millabs-operated Big Bang instance — Istio service mesh, Kyverno policy enforcement, Iron Bank image baselines — the same hardened Kubernetes substrate the DoW platforms are built on. The output is a list of what actually failed, why, and what it costs to fix.

Findings are empirical. Not an architecture opinion, not a documentation gap analysis. Test results, with logs and reproduction steps.

What the hardened baseline enforces

These are properties of the platform, not opinions about your architecture. Products arriving from commercial cloud land on the wrong side of some combination of them.

Policy admission

Containers running as root, privileged mode, missing securityContext, hostPath mounts, unbounded resource requests. Kyverno rejects the pod and your engineers have never seen the error.

Image provenance and findings

The platform does not admit images carrying critical or high findings. That is not a target to work toward — it is an admission requirement, and it is where most products from commercial cloud stop.

Missing managed services

The enclave has no managed SQL, no managed object storage, no managed cache. Your data layer assumes all three exist.

Service mesh incompatibility

Sidecar injection breaking your application's networking assumptions, mTLS conflicts, and health check and readiness probe failures.

Egress and ingress

Outbound calls to license servers, telemetry endpoints, or package registries that will never be permitted. Gateway and certificate configuration that does not match how the enclave terminates traffic.

Crypto and storage assumptions

Non-FIPS libraries, and storage classes and persistence models that do not exist on the target.

Each of these is a schedule problem, not a product problem. Each is cheap to find in a lab and expensive to find at an authorization gate.

If your product cannot be a web application, that is not the end of the path

A desktop or thick-client product faces a second problem that has nothing to do with containers: getting software installed on a government workstation is its own approval track, running in parallel with the hosting authorization and frequently slower.

Millabs has built browser-delivered virtualized environments on hardened container platforms — the application runs inside the enclave and streams to a standard workstation with no client install, authenticated against existing PKI, with self-hosted GitLab, Harbor, and PyPI so nothing reaches outside the boundary for source, images, or packages.

Where a rewrite is the wrong answer, the study says so and scopes the alternative.

What you get

A written engineering report — yours to keep and use regardless of whether Millabs does the remediation, including with another vendor.

Deployment findings Every failure encountered running your product in the hardened stack, with logs and reproduction steps.
Image and build analysis Base image sourcing recommendations, build pipeline changes, and the target vulnerability posture you must reach.
Missing dependency plan For each managed service the enclave lacks, the replacement approach and its engineering cost.
Remediation roadmap Ordered work items with effort estimates, separated into what your team can do and what requires enclave-specific experience.
Authorization pathway The approving authorities, gates, and sequence for your target environment and impact level.
Delivery walkthrough A 90-minute session with your engineering and leadership to work through the findings.

Including, where it is the answer, that your target environment is the wrong one.

THE LAB, STATED PLAINLY

Privately operated. Unaccredited. That is the point.

The Millabs Big Bang instance carries no USG authorization, holds no ATO, and is not an accredited environment. Nothing about a successful deployment in it constitutes approval by anyone, and its findings carry no evidentiary weight with an authorizing official.

That is the correct arrangement. Big Bang is openly published, so a faithful replica of the hardened baseline can be stood up outside any accreditation boundary — which makes it the right place for your product to fail. Failures in an unaccredited lab cost you a week. The same failures discovered at an authorization gate cost you a review cycle, a POA&M, and your sponsor's patience.

It is a proxy, not a replica. High fidelity for Big Bang–derived platforms; local configuration, network policy, and available services vary by installation, and the report identifies where that distinction matters. GAME WARDEN is a distinct platform and is treated as such. What the lab reliably catches is the large majority of failures that are baseline-driven rather than site-specific.

No government data, ever. The study runs on your application and, where needed, synthetic or vendor-supplied non-sensitive test data. Millabs does not accept CUI, restricted-use data, PII, or government-furnished information into this environment, and the engagement terms prohibit it.

Engagements

Each tier is defined by what it lets you decide. Fixed fee, quoted per engagement — no hourly billing, and no change orders for scope discovered during the study, because discovering scope is the point.

TIER 1
Fit Screen
One week

A single deployment attempt against the hardened baseline plus architecture review. Produces your failure inventory and a go / no-go read on the target environment.

You decide: Whether you have a three-week problem or a nine-month problem — before you commit budget.
TIER 2
Full Enclave Fit Study
Three weeks

Iterative deployment work until the product either runs or the blocking issues are fully characterized. Includes image and build pipeline analysis, replacement design for missing managed services, and the complete remediation roadmap with effort estimates.

You decide: What the whole path costs, in what order, and who does each piece. The standard engagement.
TIER 3
Multi-Domain Fit Study
Five to six weeks

For products targeting multiple impact levels, classified domains, or cross-domain information flows. Adds per-domain architecture analysis, data labeling and metadata review, and the authorization sequence across multiple approving authorities.

You decide: How the domains sequence, and which one to attempt first.
WHAT THE METHOD PRODUCES

Six months. Three deployment profiles. Zero critical or high findings.

A commercial product built for commercial cloud — object storage and a managed SQL service, neither available on the target — reached operational status across IL-2 for test, IL-4, and a classified environment in six months.

Millabs authored the OCI build scripts and sourced hardened base images to reach zero critical or high findings at submission, rather than shipping a working image and litigating findings afterward. Where the platform offered no managed SQL service at all, Millabs built a purpose-made container handling database initialization, schema migration, and steady-state operation — the data layer survived without a product rewrite. Millabs then authored the authorization artifact package in the format the reviewing authority expects, and worked inside the vendor's repository and pipeline rather than adjacent to it.

Publicly announced. Ask for the details on a walkthrough call.

That engagement took six months end to end. The Fit Study exists so you know that in week one instead of month four.

What it costs to solve this another way

Contract it

A senior DevSecOps engineer with the relevant clearances bills $225–325 per hour through a services firm — roughly $115–165K per quarter.

Hire it

The same profile runs $200–250K base in the National Capital Region — $275–375K fully loaded, annually.

Either way, not in three weeks

Recruiting someone already cleared takes three to six months. Sponsoring a clearance takes nine to eighteen.

And neither path guarantees the thing that actually matters. The scarce input is not the clearance — it is having deployed a commercial product into a hardened DoW platform and carried it through to authorization. Those two attributes correlate, but they are not the same, and a résumé cannot easily distinguish them.

Set against that, a six-month authorization slip on a federal pipeline you have already forecast is the largest number on this page by a wide margin.

After the study

A study typically identifies six to twelve months of remediation. None of these require Millabs to become your engineering department — the intent is that your engineers do the work and Millabs owns the definition of done.

Continuous Fit TestingStart here

Your team remediates on its own schedule. You push to a branch; Millabs re-runs the product through the hardened stack and returns a findings delta within two business days. Regressions surface immediately, and progress toward the target posture is measured rather than asserted. This is where most clients start. It continues after authorization as continuous-monitoring support if you want it.

Remediation Retainer

Capped hours. A standing weekly working session, architecture decision authority on anything touching the authorization boundary, unblocking as your engineers hit enclave-specific problems, and review of remediation work before it is considered complete. You are buying judgment and a schedule, not labor.

Sponsor and AO Navigation

Program office sequencing, approving authority engagement, gate preparation, and management of the review relationship. Independent of your engineering velocity, which means it proceeds in parallel and frequently determines the timeline more than any code change does.

Artifact Package

The authorization documentation set: technical and system descriptions, configuration management plan, incident response plan and test report, contingency and disaster recovery plans and tests, DIRA, hardware and software listings, business impact analysis, and control implementation narratives. Bounded, and it runs in parallel with your remediation rather than waiting on it.

Targeted Engineering Sprint

Reserved for the specific things a commercial engineering team genuinely cannot do quickly: replacement services for missing managed dependencies, hardened image build pipelines, policy-compliant manifest reconstruction, data layer rework where the enclave offers no managed database. Scoped narrowly. The objective is to transfer capability to your team, not to become a dependency.

See it before you buy it

A 30-minute call with a live walkthrough, at no cost: the pipeline running against a hardened baseline, producing a real findings delta.

You should not take an authorization claim on faith, including this one. Watch the tool work first.

lab@millabs.net
(571) 730-7459

We will confirm a time within one business day.

Who does this work

Robert D. Burckner, founder. CISSP, CCSP. 23+ years in DoW and Intelligence Community mission systems, and has personally carried a commercial product from will-not-deploy to operational inside a classified environment.

Working fluency: Platform One, Cloud One, DAF CLOUDworks, FENCES, Big Bang, Iron Bank, Party Bus, Second Front GAME WARDEN. NIST 800-37/53/137, CNSSI 1253, DoDI 8500.01 / 8510.01.

Terms

  • Fixed fee, quoted per engagement
  • Requires read access to your repository and container build definitions, and one to two hours of engineering interview time
  • Testing occurs in an unaccredited Millabs engineering lab. No government-furnished information, CUI, restricted-use data, or PII may be provided, and none will be accepted
  • Executable under a commercial SOW and mutual NDA — no federal contract vehicle required
  • Millabs Corporation is a Service-Disabled Veteran-Owned Small Business, which may carry value in your own teaming and subcontracting posture