Talk to an Expert
EAR Solutions

EAR technical data, with the carve-out working for you.

The Export Administration Regulations govern the dual-use world: commercial items with military applications, controlled by Commerce instead of State. Different list, different rules, and one encryption provision that changes everything about how you store it.

EAR vs ITAR

Know which regime owns your data

ITAR is the State Department's regime: defense articles and services on the U.S. Munitions List, administered by DDTC. EAR belongs to Commerce's Bureau of Industry and Security: dual-use items on the Commerce Control List, each with an ECCN, and the broad EAR99 category for items not specifically listed.

The line matters because the obligations differ: licensing, permitted destinations, deemed-export handling, and recordkeeping all follow the list your item sits on. Plenty of companies handle both, an ITAR program for the defense work and EAR controls for the dual-use catalog, and the classification call in between is where mistakes get expensive.

  • Export Controlled Materials platform built for EAR-defined data
  • Full encryption in transit and at rest
  • Tamper-proof audit trail and systematic monitoring
  • Two-factor authentication and provider shielding
  • U.S.-based hosting, end to end
  • Secure File Editing: work on documents without data ever leaving the room
The encryption carve-out

Properly encrypted isn't an export

The EAR provision

Under 15 CFR §734.18, unclassified technical data secured end to end with FIPS 140 validated cryptographic modules, and not intentionally stored in embargoed destinations, is not treated as an export in transmission and storage.

15 CFR §734.18 · the 2016 end-to-end encryption rule

The ITAR counterpart

Since 2020, §120.54 gives ITAR technical data an equivalent path: properly end-to-end encrypted data in transit is not an export event. Two regimes, one architectural answer.

22 CFR §120.54

What it means in practice

The carve-outs reward exactly one design: data encrypted the whole way, access controlled by user, and storage locations you can prove. That is the RegDOX architecture, not a configuration you assemble.

Engineered default, evidenced in the audit trail

EAR and ITAR, one platform

Dual-regime companies run one enclave for both datasets, with need-to-know permissioning keeping each program's data where its rules require.

One system · both lists

Regulatory provisions summarized for orientation, not legal advice. Classification and licensing decisions remain yours.

Next step

Sort your data onto the right list.

Bring your product catalog and your questions. We’ll walk through which regime owns what, and where the carve-outs can work for you.

(800) 517-3171 · Nashua, NH · U.S. data centers & personnel