Register:ITAR6 recordsSHA3-256 chainedSealed Amended head sha3:cbbd16d777b4902d47c33e0514ab584c11c5cb653542ce277123408df7bd4640Intact

ITAR / EAR / USML categories I to XXI

Export-controlled data boundaries, with evidence of enforcement.

ITAR governs defense articles, services, and technical data; EAR governs dual-use items. Both require that export-controlled technical data stay inside boundaries only US persons can reach. PolicyCortex records those boundaries and every change to them as hash-chained evidence inside your GovCloud or GCC High tenant, so the disclosure trail your export compliance officer needs can be recomputed, not reconstructed.

Request AccessBook a call

Access is reviewed. Scope and onboarding are agreed with your team.

REC 0000OBLIGATIONsha3-256bfd0e1f46418f1f95ce772d70e87e1386d265f6ba0a4bc580be240e5f514da69prev:5cecdc9b97a5

What export controls ask you to prove

Export-controlled technical data may only be accessible to US persons, and a deemed export happens the moment a foreign person can reach it, wherever the server sits. For a cloud estate that means a boundary: which storage, which regions, which identities, and which sharing paths hold ITAR or EAR data, and proof that the boundary held on every date in question. When DDTC asks, the answer is a disclosure trail, not a policy document.

Dashboards answer with today's configuration. The obligation is about the interval: was the boundary intact between these two dates, and if it was not, when did it open and who or what opened it.

itar.scope
USML categories I through XXI. Which resources hold technical data is a declared scope on every record.
itar.regions
AWS GovCloud, Azure Government, and GCC High are observed clouds. A scoped resource outside US-controlled regions is a finding, not an assumption.
itar.access
US-person status lives in your identity provider (Entra ID, Okta, AWS IAM Identity Center). PolicyCortex records who held which role as of a date; it does not adjudicate persons.
itar.disclosure
A DDTC inquiry is answered from the record. PolicyCortex is a control-evidence layer, not a DDTC submission tool.
REC 0001EVIDENCEsha3-256f2082cd79a18a87516cf4c61b4665489123c441cd1e43632d912015ad179221cprev:bfd0e1f46418

The evidence behind the boundary

The boundary as a record, not a diagram. Where each proof files:

Boundary state
Proof of state: which storage accounts, shares, regions, and identities held export-controlled data as of any date, captured from the provider APIs and content hashed.
Boundary change
Proof of change: every alteration to a share, a region lock, or a role on a scoped resource, with actor, authority, before and after hashes, and a rollback identifier. An opening in the boundary is a row with a timestamp.
Machine actions
Proof of agency: what any autonomous action on scoped resources was permitted to do before it ran, and what it did.
Declared gaps
When a collector was down or a region unobserved, the trail says so with interval and reason, so the absence of a finding is never mistaken for compliance.
Retention
Seven years, append only. The disclosure trail for a DDTC inquiry is a replay of the chain, not an archaeology project.
Exhibit SB-11collectors and artifacts, as shipped
The PolicyCortex evidence system: registered collectors and artifacts grouped by control, each artifact with source, resource path, capture time, size, and SHA hash

Exhibit SB-11 · collectors writing hashed artifacts per control: the disclosure trail as it lands, with source, path, capture time, and digest. Illustrative demo data; the interface is real.

REC 0002VERIFICATIONsha3-2564046eec80ed27ea4a3f8568d05b2b72f7079c5c4f15c8c49288378f7000e0c73prev:f2082cd79a18

How the disclosure trail is verified

For an export-controls question the recomputation runs over an interval: the trail between two dates either recomputes intact, or it names the first record after which the boundary can no longer be shown to have held.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

REC 0003EVALUATIONsha3-256bfcc97268c7fcf75bd546dca8f2ece70b80e3dddb213cead9b79459da49e3b17prev:4046eec80ed2

Access and onboarding in GovCloud or GCC High

Read-only onboarding runs inside AWS GovCloud, Azure Government, or GCC High after the export-control boundary is agreed. USML-scoped resources are declared on every record, establishing the disclosure trail from the first capture.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

eval.mode
SHADOW. Watch only; nothing executes.
eval.onboarding
Access is reviewed. Scope and onboarding are agreed with your team.
eval.location
Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
eval.egress
None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
eval.after
You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
REC 0004DELIVERYsha3-2567021ca7bd76782414ab885138b4354634a5a68b06a52f8196559974d7665b13eprev:bfcc97268c7f

Delivery, if you want the record stood up for you

Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.

engagement.scope
Thirty days. One agreed primary cloud environment.
engagement.outcome
An evidence package built and defended through assessor review.
engagement.limit
The independent assessor decides. No certification is guaranteed.

Every term of the engagement, on its own page.

REC 0005QUESTIONSsha3-256cbbd16d777b4902d47c33e0514ab584c11c5cb653542ce277123408df7bd4640prev:7021ca7bd767

Questions assessors and buyers ask

How is US-person status verified?

In your identity provider. Entra ID, Okta, and AWS IAM Identity Center carry the US-person attribute; PolicyCortex records which identities held which roles on scoped resources as of a date. It does not adjudicate a person's status.

What about foreign persons with licenses?

Some USML categories allow access by foreign persons in covered countries under proper licensing. Licensing decisions are yours and your export compliance officer's; the record shows who had access to what, and when, so the license and the access can be compared.

What is a deemed export in a cloud estate?

Technical data moved to a region or a principal where a non-US person could reach it. Proof of change records the move with actor, authority, and timestamp. The disposition (allowed, review, blocked) is your compliance officer's call, made on the record.

Does this satisfy DDTC?

PolicyCortex produces the disclosure trail; DDTC inquiries are answered from the record. The platform is a control-evidence layer, not a DDTC submission tool, and it does not make the determination.

Where does the data live?

In your own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.

What happens when a collector is down?

The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Prove the boundary held, for any interval they name.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000OBLIGATIONbfd0e1f464185cecdc9b97a5
REC 0001EVIDENCEf2082cd79a18bfd0e1f46418
REC 0002VERIFICATION4046eec80ed2f2082cd79a18
REC 0003EVALUATIONbfcc97268c7f4046eec80ed2
REC 0004DELIVERY7021ca7bd767bfcc97268c7f
REC 0005QUESTIONScbbd16d777b47021ca7bd767

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:cbbd16d777b4. The product does the same thing to your evidence.

Photograph: Trevor Paglen, CC0 1.0. Source