Right-sized security.
No compliance theater.
Input Trace helps organizations across industries secure sensitive and regulated data without buying into bloated consulting models, unnecessary tools, or compliance theater. Our passion is manufacturing — of every type.
We architect working solutions mapped to NIST SP 800-171 and CMMC requirements — a dedicated Azure enclave, a hybrid cloud and on-premises environment, or improving the systems you already own — and deliver MSP services that support ongoing compliance and pragmatic security.
Built for the shop floor, defensible in assessment.
Who we serve
Anyone securing sensitive work — automated shop floors, R&D and AI/ML programs protected on-site or in the cloud, universities conducting government research, and the one-person shop delivering aerospace parts to the DoD. Real operational processes, often minimal internal IT, and a partner that understands both NIST SP 800-171 and the work itself.
Right-sized, not one-size
No two shops handle CUI the same way, so no single product is the answer. We model the business first, then fit the environment to it — a dedicated enclave, a hybrid build, or hardening what you already own. You buy what the model justifies and nothing more.
Built to hold up
Under 32 CFR 170.19, a significant change is an architectural or boundary change. We build the environment so growth stays inside a fixed architecture and boundary — clients grow without re-opening their certification, and every artifact is assessor-defensible.
Architected up front. Supported for the long haul.
A working solution, not a binder
A fixed-price architecture engagement that models your business first, then delivers a target-state design with recommended technologies, projected costs, and a sequenced implementation roadmap — a defensible plan before you purchase or deploy anything.
See our method →Ongoing compliance and pragmatic security
After the build, we can operate what we designed — managed services that keep the environment patched, monitored, and inside its assessed boundary, with the evidence and annual affirmations continuous compliance requires.
Start discovery →Two founders. No hand-offs.
Input Trace is veteran-owned and founder-operated. The people who scope your engagement are the people who build it and stand behind it in assessment.
[Co-Founder · CEO]Joshua Kuhn
CCP · CISSP
Joshua is a cybersecurity architect and U.S. Navy veteran with 15+ years securing mission-critical systems. He served as a Radioman and Information Systems Technician across three overseas deployments — supporting ship-to-shore communications, server operations, and network infrastructure aboard guided-missile destroyers. Working directly with U.S. manufacturers of Navy IT equipment gave him early insight into how much the military depends on secure, reliable suppliers.
After the Navy he moved into the private sector as a SOC Engineer at Netscout, focusing on DDoS mitigation and large-scale threat response. He later joined Mercedes-Benz Mobility AG, where he advanced to Principal Information Security Architect — leading security design across more than 1,100 global applications spanning cloud, hybrid, and on-prem environments.
At Input Trace, Joshua brings that combined military and enterprise experience to U.S. manufacturers — helping defense suppliers achieve CMMC Level 2 readiness and protect the systems the military relies on.
[Co-Founder · CTO]Jon Meaney
CCA · CCP · CISSP
Jon is a cybersecurity architect with 10+ years of experience analyzing complex distributed systems. His career spans embedded systems development — writing low-level ECU firmware for automotive platforms — enterprise networking, deploying global network environments for Google, and large-scale application security at Mercedes-Benz.
He now specializes in guiding organizations through NIST SP 800-171 implementation. At Input Trace, he leads the CMMC client-readiness program, focused on reducing cost and complexity for organizations pursuing CMMC Level 2 certification.
The program is built around detailed, repeatable workflows that guide customers step-by-step through creating high-quality Plans, Policies, and Procedures — including the System Security Plan — along with structured evidence collection and a clear process for remediating non-compliant environments.

