Defense export controls, enforced at runtime.
ITAR governs defense articles, services, and technical data under USML categories. EAR governs dual-use. Both require US-persons-only access enforcement and clear-text deemed-export controls. PolicyCortex enforces these at the cloud layer continuously — and produces the disclosure trail your export compliance officer needs.

- CAP-01US-persons-only enforcementAccess automatically gated; foreign-person attempts logged + blocked.
- CAP-02Deemed-export detectionSharing patterns analyzed; export-significant moves flagged.
- CAP-03Disclosure trailTamper-evident audit log · 7y retention.
- CAP-04GovCloud / GCC-H onlyResources outside US-controlled regions blocked.
- CAP-05Auto-remediationMisconfigured shares rolled back automatically.
- CAP-06USML category-awareCategories I-XXI mapped to scope policies.
- 01ScopeTech-data + USML-categorized resources identified.
- 02EnforceAccess policies bound to US-person attribute. Region locks applied.
- 03DiscloseAudit trail maintained, exportable for DDTC inquiries.
- DOE National LabActive consultant
- MITRECybersecurity engineering
- USAAFinancial-grade ops
- FrontierProduction cloud architecture
Founder runs every engagement personally. 4 U.S. patent applications filed.
How is US-person attribute verified?
Identity provider integration. PolicyCortex consumes attestation from Entra ID / Okta / AWS IAM Identity Center — your IdP carries the US-person flag, we enforce based on it.
What about cleared foreign persons?
USML category-specific. Some categories allow access by foreign persons in covered countries with proper licensing. PolicyCortex tracks licensing state and adjusts gating per category.
Deemed-export detection — what triggers it?
Sharing patterns: tech data moved to a region or principal where a non-US person could access. We surface the pattern, the disposition (allowed / review / blocked) flows through your compliance officer.
Does this satisfy DDTC?
PolicyCortex produces the disclosure trail. DDTC inquiries respond from the audit log. The platform is a control + evidence layer, not a DDTC submission tool.
Defense exports. Enforced at runtime, not at audit.
$15,000 flat for the 30-day pilot. US-persons-only access, GovCloud-only deployment, audit-grade evidence.
