---
title: "ITAR Compliance Evidence for Cloud Tenants"
description: "ITAR and EAR technical data in the cloud: declared boundaries, US regions, and a hash-chained disclosure trail your export compliance officer can verify."
url: https://policycortex.com/solutions/itar-compliance
sealed: 2026-09-02
amended: 2026-09-05
register: solutions/itar-compliance
records: 6
digest: sha3:cbbd16d777b4902d47c33e0514ab584c11c5cb653542ce277123408df7bd4640
---

# Export-controlled data boundaries, with evidence of enforcement.

ITAR / EAR / USML categories I to XXI

ITAR governs defense articles, services, and technical data; EAR governs dual-use items. Both require that export-controlled technical data stay inside boundaries only US persons can reach. PolicyCortex records those boundaries and every change to them as hash-chained evidence inside your GovCloud or GCC High tenant, so the disclosure trail your export compliance officer needs can be recomputed, not reconstructed.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Access is reviewed. Scope and onboarding are agreed with your team.

## What export controls ask you to prove

Export-controlled technical data may only be accessible to US persons, and a deemed export happens the moment a foreign person can reach it, wherever the server sits. For a cloud estate that means a boundary: which storage, which regions, which identities, and which sharing paths hold ITAR or EAR data, and proof that the boundary held on every date in question. When DDTC asks, the answer is a disclosure trail, not a policy document.

Dashboards answer with today's configuration. The obligation is about the interval: was the boundary intact between these two dates, and if it was not, when did it open and who or what opened it.

- **itar.scope**: USML categories I through XXI. Which resources hold technical data is a declared scope on every record.
- **itar.regions**: AWS GovCloud, Azure Government, and GCC High are observed clouds. A scoped resource outside US-controlled regions is a finding, not an assumption.
- **itar.access**: US-person status lives in your identity provider (Entra ID, Okta, AWS IAM Identity Center). PolicyCortex records who held which role as of a date; it does not adjudicate persons.
- **itar.disclosure**: A DDTC inquiry is answered from the record. PolicyCortex is a control-evidence layer, not a DDTC submission tool.

## The evidence behind the boundary

The boundary as a record, not a diagram. Where each proof files:

- **Boundary state**: Proof of state: which storage accounts, shares, regions, and identities held export-controlled data as of any date, captured from the provider APIs and content hashed.
- **Boundary change**: Proof of change: every alteration to a share, a region lock, or a role on a scoped resource, with actor, authority, before and after hashes, and a rollback identifier. An opening in the boundary is a row with a timestamp.
- **Machine actions**: Proof of agency: what any autonomous action on scoped resources was permitted to do before it ran, and what it did.
- **Declared gaps**: When a collector was down or a region unobserved, the trail says so with interval and reason, so the absence of a finding is never mistaken for compliance.
- **Retention**: Seven years, append only. The disclosure trail for a DDTC inquiry is a replay of the chain, not an archaeology project.

![The PolicyCortex evidence system: registered collectors and artifacts grouped by control, each artifact with source, resource path, capture time, size, and SHA hash](https://policycortex.com/images/pcx-evidence-system-artifacts-1600.webp)

Exhibit SB-11 · collectors writing hashed artifacts per control: the disclosure trail as it lands, with source, path, capture time, and digest. Illustrative demo data; the interface is real.

## How the disclosure trail is verified

For an export-controls question the recomputation runs over an interval: the trail between two dates either recomputes intact, or it names the first record after which the boundary can no longer be shown to have held.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

**Stated limit.** PolicyCortex is not an assessor and does not certify anything. It produces the records a compliance decision rests on; the assessor, the authorizing official, or the accountable official makes the determination. What is not connected is not observed, and the record says so.

## Access and onboarding in GovCloud or GCC High

Read-only onboarding runs inside AWS GovCloud, Azure Government, or GCC High after the export-control boundary is agreed. USML-scoped resources are declared on every record, establishing the disclosure trail from the first capture.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

- **eval.mode**: SHADOW. Watch only; nothing executes.
- **eval.onboarding**: Access is reviewed. Scope and onboarding are agreed with your team.
- **eval.location**: Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- **eval.egress**: None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- **eval.after**: You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.

## Delivery, if you want the record stood up for you

Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.

- **engagement.scope**: Thirty days. One agreed primary cloud environment.
- **engagement.outcome**: An evidence package built and defended through assessor review.
- **engagement.limit**: The independent assessor decides. No certification is guaranteed.

[Every term of the engagement, on its own page.](https://policycortex.com/engagement)

## Questions assessors and buyers ask

**Q: How is US-person status verified?**
A: In your identity provider. Entra ID, Okta, and AWS IAM Identity Center carry the US-person attribute; PolicyCortex records which identities held which roles on scoped resources as of a date. It does not adjudicate a person's status.

**Q: What about foreign persons with licenses?**
A: Some USML categories allow access by foreign persons in covered countries under proper licensing. Licensing decisions are yours and your export compliance officer's; the record shows who had access to what, and when, so the license and the access can be compared.

**Q: What is a deemed export in a cloud estate?**
A: Technical data moved to a region or a principal where a non-US person could reach it. Proof of change records the move with actor, authority, and timestamp. The disposition (allowed, review, blocked) is your compliance officer's call, made on the record.

**Q: Does this satisfy DDTC?**
A: PolicyCortex produces the disclosure trail; DDTC inquiries are answered from the record. The platform is a control-evidence layer, not a DDTC submission tool, and it does not make the determination.

**Q: Where does the data live?**
A: In your own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.

**Q: What happens when a collector is down?**
A: The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Prove the boundary held, for any interval they name. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | OBLIGATION | bfd0e1f46418 | 5cecdc9b97a5 |
| REC 0001 | EVIDENCE | f2082cd79a18 | bfd0e1f46418 |
| REC 0002 | VERIFICATION | 4046eec80ed2 | f2082cd79a18 |
| REC 0003 | EVALUATION | bfcc97268c7f | 4046eec80ed2 |
| REC 0004 | DELIVERY | 7021ca7bd767 | bfcc97268c7f |
| REC 0005 | QUESTIONS | cbbd16d777b4 | 7021ca7bd767 |

Head sha3:cbbd16d777b4902d47c33e0514ab584c11c5cb653542ce277123408df7bd4640. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
