Trust & Compliance / ITAR
ITAR compliance for technical data in the cloud.
ITAR restricts who may access defense-related technical data. XQ helps contractors keep ITAR data compliant in cloud and hybrid environments by encrypting each object with customer-held keys, allowing decryption only by authorized U.S. persons in approved jurisdictions through geofenced policy, and keeping an immutable record of every access.
Built for Defense manufacturers and contractors with USML technical data · Export compliance officers · Engineering teams collaborating with international partners
At a glance
RegulationITAR, 22 CFR Parts 120–130
ControlsWho can decrypt, and from which jurisdictions
KeysCustomer-held — SaaS, private cloud or on-premises
RecordsImmutable, HMAC-signed access log
Works with Microsoft GCC Moderate · Microsoft 365 · AWS · Azure · Google Cloud
Only authorized U.S. persons can open it
Identity- and attribute-based policy is checked every time a file is opened.
Keep data out of proscribed countries
Geofencing blocks decryption outside approved jurisdictions.
Use the cloud with confidence
Customer-held keys mean cloud providers can never read your technical data.
What ITAR requires
The International Traffic in Arms Regulations (22 CFR Parts 120–130) control defense articles and technical data on the U.S. Munitions List. Only U.S. persons may access that technical data unless a release is authorized, and sharing it with a foreign person — even an employee — can itself be an export.
- Release of technical data is defined broadly (22 CFR § 120.56), so access control matters as much as storage location.
- Sending or storing technical data that is end-to-end encrypted can fall outside the definition of an export when the conditions in 22 CFR § 120.54 are met.
- Registrants must keep records of their activities (22 CFR § 122.5).
- Violations carry civil and criminal penalties under the Arms Export Control Act (22 U.S.C. 2778), with a voluntary-disclosure path (22 CFR § 127.12).
How XQ addresses ITAR controls
| ITAR need | How XQ addresses it |
|---|---|
| Limit access to authorized U.S. persons | RBAC and ABAC policy is evaluated for each object at the moment of decryption, so only authorized identities can open technical data — wherever the file has been copied. |
| Keep data out of proscribed locations | Geofencing restricts decryption by jurisdiction, live, at the moment of access; XQ geolocates every access request. |
| End-to-end encryption in the cloud | Every object is encrypted with its own key, and keys are held separately by you — cloud and service providers cannot read the data. |
| Recordkeeping | An immutable, HMAC-signed log records who accessed which object, when and from where, including denied attempts. |
| Key custody | Host the XQ key and policy service as SaaS, in a private cloud or on-premises, so unauthorized parties never hold your keys. |
Mapping ITAR controls to a GCC Moderate or AWS environment?
GCC Moderate + XQ for ITAR
Organizations on Microsoft’s Government Community Cloud (GCC Moderate) can add XQ’s data sovereignty, geofencing and role-based access controls to protect ITAR technical data at the object level, combining GCC Moderate’s foundation with controls that follow the data. The implementation plan below walks through the architecture.
Related resources and articles
FAQ
ITAR, answered directly.
Can ITAR technical data be stored in the cloud?
It can, when it is protected appropriately. ITAR’s end-to-end encryption provision (22 CFR § 120.54) lets properly encrypted technical data be sent or stored without being an export when its conditions are met, including cryptographic strength and not storing the data in proscribed countries such as Russia. XQ’s per-object encryption, customer-held keys and geofencing are designed around those conditions; confirm your specific use with export-control counsel.
How does XQ stop foreign persons from opening ITAR files?
Access policy travels with each file. Before a key is released, XQ checks the requester’s identity, role and attributes and where the request comes from, so an unauthorized person cannot decrypt the file even if they receive a copy.
Can cloud providers access our ITAR data?
No. Data is encrypted before it reaches the cloud, and you control the keys — optionally in your own environment — not the storage or cloud provider.
Is Microsoft GCC Moderate enough for ITAR on its own?
GCC Moderate provides a U.S.-based government cloud foundation, but on its own it leaves gaps for ITAR technical data: granular classification and marking, controls that stop unauthorized foreign-person access, need-to-know access and detailed audit. XQ adds per-object encryption, geofencing, role- and attribute-based policy and an immutable access log on top of GCC Moderate; confirm your architecture with export-control counsel.
What records does XQ keep for ITAR?
Every access attempt on every protected object is logged with who, when and where, in a tamper-evident, HMAC-signed trail you can export for audits and investigations.
Keep ITAR data compliant in the cloud.
Talk to our team about protecting technical data in GCC Moderate, AWS and partner workflows.