Trust & Compliance / ITAR

ITAR compliance for technical data in the cloud.

ITAR restricts who may access defense-related technical data. XQ helps contractors keep ITAR data compliant in cloud and hybrid environments by encrypting each object with customer-held keys, allowing decryption only by authorized U.S. persons in approved jurisdictions through geofenced policy, and keeping an immutable record of every access.

Built for Defense manufacturers and contractors with USML technical data · Export compliance officers · Engineering teams collaborating with international partners

At a glance

RegulationITAR, 22 CFR Parts 120–130

ControlsWho can decrypt, and from which jurisdictions

KeysCustomer-held — SaaS, private cloud or on-premises

RecordsImmutable, HMAC-signed access log

Works with Microsoft GCC Moderate · Microsoft 365 · AWS · Azure · Google Cloud

Only authorized U.S. persons can open it

Identity- and attribute-based policy is checked every time a file is opened.

Keep data out of proscribed countries

Geofencing blocks decryption outside approved jurisdictions.

Use the cloud with confidence

Customer-held keys mean cloud providers can never read your technical data.

What ITAR requires

The International Traffic in Arms Regulations (22 CFR Parts 120–130) control defense articles and technical data on the U.S. Munitions List. Only U.S. persons may access that technical data unless a release is authorized, and sharing it with a foreign person — even an employee — can itself be an export.

  • Release of technical data is defined broadly (22 CFR § 120.56), so access control matters as much as storage location.
  • Sending or storing technical data that is end-to-end encrypted can fall outside the definition of an export when the conditions in 22 CFR § 120.54 are met.
  • Registrants must keep records of their activities (22 CFR § 122.5).
  • Violations carry civil and criminal penalties under the Arms Export Control Act (22 U.S.C. 2778), with a voluntary-disclosure path (22 CFR § 127.12).

How XQ addresses ITAR controls

ITAR needHow XQ addresses it
Limit access to authorized U.S. personsRBAC and ABAC policy is evaluated for each object at the moment of decryption, so only authorized identities can open technical data — wherever the file has been copied.
Keep data out of proscribed locationsGeofencing restricts decryption by jurisdiction, live, at the moment of access; XQ geolocates every access request.
End-to-end encryption in the cloudEvery object is encrypted with its own key, and keys are held separately by you — cloud and service providers cannot read the data.
RecordkeepingAn immutable, HMAC-signed log records who accessed which object, when and from where, including denied attempts.
Key custodyHost the XQ key and policy service as SaaS, in a private cloud or on-premises, so unauthorized parties never hold your keys.

Mapping ITAR controls to a GCC Moderate or AWS environment?

GCC Moderate + XQ for ITAR

Organizations on Microsoft’s Government Community Cloud (GCC Moderate) can add XQ’s data sovereignty, geofencing and role-based access controls to protect ITAR technical data at the object level, combining GCC Moderate’s foundation with controls that follow the data. The implementation plan below walks through the architecture.

Related resources and articles

ITAR, answered directly.

Can ITAR technical data be stored in the cloud?

It can, when it is protected appropriately. ITAR’s end-to-end encryption provision (22 CFR § 120.54) lets properly encrypted technical data be sent or stored without being an export when its conditions are met, including cryptographic strength and not storing the data in proscribed countries such as Russia. XQ’s per-object encryption, customer-held keys and geofencing are designed around those conditions; confirm your specific use with export-control counsel.

How does XQ stop foreign persons from opening ITAR files?

Access policy travels with each file. Before a key is released, XQ checks the requester’s identity, role and attributes and where the request comes from, so an unauthorized person cannot decrypt the file even if they receive a copy.

Can cloud providers access our ITAR data?

No. Data is encrypted before it reaches the cloud, and you control the keys — optionally in your own environment — not the storage or cloud provider.

Is Microsoft GCC Moderate enough for ITAR on its own?

GCC Moderate provides a U.S.-based government cloud foundation, but on its own it leaves gaps for ITAR technical data: granular classification and marking, controls that stop unauthorized foreign-person access, need-to-know access and detailed audit. XQ adds per-object encryption, geofencing, role- and attribute-based policy and an immutable access log on top of GCC Moderate; confirm your architecture with export-control counsel.

What records does XQ keep for ITAR?

Every access attempt on every protected object is logged with who, when and where, in a tamper-evident, HMAC-signed trail you can export for audits and investigations.

Keep ITAR data compliant in the cloud.

Talk to our team about protecting technical data in GCC Moderate, AWS and partner workflows.