Government contractors

Agents that pass the DCAA audit.

GoodHelp gives federal contractors AI agents with the controls their auditors already expect — hash-chained ledger, segregation-of-duty approvals, and signed evidence export. Built on the same infrastructure that already serves ~600+ DCAA-aligned contractors via our sister brand Hour Timesheet.

Designed for DCAA-aligned complianceHash-chained action ledgerSigned evidence pack

You already live with this.

  • DCAA isn't optional — it's a contract condition. One failed audit kills the contract.
  • Every system that touches time, expense, or labor distribution is in your audit scope (SF 1408).
  • Most AI-agent platforms can't produce an audit trail an auditor would accept.
  • You can't afford a five-person compliance team — but you can't afford a finding either.

Controls your auditors already expect.

Pass the audit

Hash-chained action ledger, KMS-rooted, exportable as a signed evidence pack.

Stay in segregation

Every sensitive action is gated by approval. No single-actor end-to-end. Enforced fail-CLOSED (SOD_REQUIRE_AUDIT_AVAILABLE=true): if the SoD audit context is unavailable the approval is blocked rather than allowed.

Keep records the way contract clauses require

7-year retention via the Regulated Industry compliance profile. Records survive personnel turnover.

Run lean

Controller plus Office Manager can operate the back office. No new compliance hire required.

The same engineering team your auditors already trust.

~600+

DCAA-aligned contractors served by sister brand Hour Timesheet — same engineering team, same security posture (DCAA reviews per-system; ask in your walkthrough about which controls map across)

17

Production agents running LMNTL itself

7 years

Retention via Regulated Industry profile

Where federal contractor teams put us to work.

Dunning agent with HITL escalation

Chases failed payments with the cadence your CFO would design. Every action logged to the hash-chained ledger.

Vendor invoice review

Classifies, flags anomalies, queues for approval per SoD policy. Material actions never bypass an approver.

Monthly closing helper

Assembles the ledger snapshot, surfaces variances, requires Controller approval before close.

Audit-evidence assembly

On-demand signed evidence pack for any window, any agent, any action — JSON manifest plus body, KMS-rooted signature.

Unallowable-cost screen (design-partner pattern)

The vendor-invoice-review primitive composes into an unallowables screen on top of your own classification rules (entertainment, alcohol, lobbying, bad debt — your CAS-tagged categories). Every classification logged to the hash-chained ledger. Available as a design-partner build today; pre-built template on the roadmap.

Purchasing-system SoD watchdog (design-partner pattern)

The SoD approval primitive composes into a same-principal-initiating-and-approving watch on your purchase requisitions above a threshold you set. Available as a design-partner build today; pre-built template on the roadmap.

Where GoodHelp sits relative to your other tools.

Cost-accounting and timekeeping systems are out of scope here — we don’t replace Deltek Costpoint or Unanet. GoodHelp runs the operations work that has been hard to put inside the same control envelope until now.

CapabilityGoodHelpGeneric agent platformsDeltek Costpoint
Hash-chained action ledgerDifferent scope (cost accounting)
SoD approval gates on agent actionsDifferent scope
Signed evidence export
Runs your operations (not just bookkeeping)

Comparison reflects publicly documented capabilities as of 2026-05-24. Customer mileage may vary by configuration.

What federal contractor teams ask first.

Do you claim DCAA certification?

No. We are designed for DCAA alignment — we produce audit-ready evidence, but we do not represent ourselves as certified. We are also NOT FedRAMP-authorized, ITAR-registered, CMMC-certified, or CUI-authorized. See our Trust Center for the full posture.

What's in the action ledger?

Every agent action: who initiated, what tool was invoked, what was the input, what was the output, KMS-chained to the previous entry. Exportable as a signed evidence pack — a JSON manifest plus body (CSV/TSV/JSON), with an asymmetric KMS-rooted signing key.

Can a single user push something through without approval?

No, when the SoD policy is configured. Sensitive actions require a separate principal’s approval per the SoD policy. Calibration: SoD enforcement is fail-CLOSED (SOD_REQUIRE_AUDIT_AVAILABLE=true) — if the audit context is unavailable the approval is blocked rather than allowed. Review the precise current behavior in our platform documentation before configuring agents for fund-moving systems.

How does this work with Hour Timesheet?

GoodHelp is a sibling product under the LMNTL-AI parent. The same engineering team and security posture that serves ~600+ DCAA-aligned contractors via Hour Timesheet built GoodHelp. DCAA reviews are per-system; ask in your walkthrough about which controls map across. GoodHelp extends the same control envelope to the operations work that has been hard to put inside it until now.

Can GoodHelp appear in our SF 1408 IT-system inventory?

Yes for unclassified, FOUO-free operational data. GoodHelp is hosted in GCP us-west1 (US-only). It is NOT authorized for CUI, ITAR, or CMMC environments. The Trust Center documents the controls (hash-chained ledger, SoD, tenant isolation, retention) you’ll list in section 5 of your SF 1408.

What about ITAR / CUI / CMMC?

We don’t support those today. Don’t ship CUI or ITAR-controlled data through GoodHelp.

Pricing?

$5/agent per month plus LLM passthrough margin (15% BYOK / 30% managed). Per-run cost cap enforced. Federal contractors — ask about NET-30 invoicing and annual commit so the spend fits a corporate-card-restricted procurement environment.

What does GoodHelp NOT do?

We do not perform cost accounting (use Deltek/Unanet for that), do not submit your incurred-cost proposal, and do not replace your timekeeping system. We help you produce the evidence that supports those — and we run the operations work that has been hard to put inside the same control envelope until now.

What we do not claim

Honest > shiny. Where we don’t have the certification, we don’t claim it.

  • DCAA-compliant / DCAA-certified
  • FedRAMP-authorized / GovCloud
  • ITAR / CMMC / CUI
  • SOC 2 (hosting-level attestation, not certified)
  • “Immutable” — nothing is. We say tamper-evident.
  • “Blockchain” — we say hash-chained, append-only ledger.

We say DCAA-aligned, audit-ready architecture, and controls regulated-industry customers expect. Every stronger claim has to be defensible by a specific shipped feature.

Tell us about your next audit.

Thirty minutes with a Trust Center walkthrough — bring your auditor’s checklist; we’ll walk through the controls one by one.