CONTROLLED // EXPORT-CONTROLLED TECHNICAL DATA MAY NOT BE SHARED WITHOUT AUTHORIZATION

ITAR · EAR · CUI

Move export-controlled data without moving outside the rules.

SecureExport is the export compliance platform for defense and aerospace teams: encrypted transfer of export-controlled files, a complete chain of custody, automated screening, and records your auditors will actually thank you for.

End-to-end encrypted Audit-ready by default Built for regulated exporters
Transfer record TX-2026-0847 USML CAT VIII
  • M. Alvarez uploaded technical data package (3 files)ENCRYPTED
  • Recipient screened against denied-party listsSCREENED
  • D. Okafor (Empowered Official) reviewed authorizationAPPROVED
  • R. Ellison downloaded — identity verified, access loggedDELIVERED
SHA-256 e3b0c442…b855 · retained per record-keeping policy

Who it's for

Built for teams the regulations were written about

Email attachments, consumer file-sharing links, and "we'll document it later" are how export violations happen. SecureExport replaces them with one controlled channel.

22 CFR 120–130

Defense manufacturers

Share ITAR technical data with primes, suppliers, and foreign partners under the authorizations you actually hold — with the paper trail to prove it.

15 CFR 730–774

Aerospace & dual-use

Manage EAR-controlled drawings, specs, and software across programs without guessing who's allowed to see what.

32 CFR 2002

CUI handlers

Give government and prime customers confidence that controlled unclassified information is handled, marked, and tracked correctly.

Capabilities

Every transfer accounted for. Every decision on record.

CAPABILITYSE-01

Controlled transfer

Send export-controlled files through an encrypted channel built for enterprise security standards — not a consumer sharing link.

  • End-to-end encryption in transit and at rest
  • Verified recipient identity before delivery
  • Expiring, revocable access
CAPABILITYSE-02

Chain of custody

Every upload, review, approval, and download is logged automatically. Know exactly who exported, who approved, and who received each file.

  • Tamper-evident, timestamped audit log
  • File integrity hashing on every transfer
  • Records retained to meet record-keeping requirements
CAPABILITYSE-03

Denied-party screening

Recipients are screened automatically against restricted- and denied-party lists before anything moves — every transfer, not just onboarding.

  • Automated screening on every transaction
  • Rescreening as lists change
  • Screening results attached to the record
CAPABILITYSE-04

Compliance workflow

Route transfers through the approvals your export control plan requires — empowered official sign-off, license references, authorization tracking.

  • Configurable approval chains
  • License & agreement references on each transfer
  • Audit-ready exports for regulators and primes

Meet Sero

An export compliance assistant that's read the regulations

Sero helps your team work through classification questions, screening results, and process steps in plain language — inside the platform, with your transfer context at hand. Sero supports your compliance team's judgment; it doesn't replace it.

SEROcompliance assistant
Can I send this wiring diagram to our UK supplier under our existing TAA?
Possibly — your TAA covers technical data for this program, but the scope depends on whether the diagram falls under the agreement's defined data categories and whether the supplier is a listed foreign party. Here's what to check before this transfer, and I've flagged it for Empowered Official review. ▸ Ref: TAA scope · USML category · foreign party list

Platform & trust

Infrastructure chosen for the data it carries

Export-controlled data has residency and access requirements most SaaS platforms were never designed for. SecureExport was.

US sovereign cloud

Hosted in Microsoft Azure Government — US data residency with access restricted to screened US persons at the infrastructure level.

Enterprise identity

Single sign-on, role-based access, and least-privilege controls that map to how your export control plan defines responsibility.

Audit-ready records

Complete, exportable records for internal audits, prime flow-down requirements, and regulator requests — available on demand, not reconstructed after the fact.

FAQ

Questions your compliance team will ask

Straight answers on ITAR compliant file sharing, hosting, screening, and the records SecureExport keeps.

Q-01

Is SecureExport ITAR compliant?

SecureExport is built for ITAR technical data: files move through an encrypted channel with verified recipient identity, every transfer is screened and logged, and records are retained to meet ITAR record-keeping requirements. Compliance itself always rests with the exporter and your authorizations — SecureExport gives your team the controls, approvals, and records to operate inside them.

Q-02

Where is SecureExport data hosted?

SecureExport is hosted in Microsoft Azure Government, with US data residency and infrastructure access restricted to screened US persons.

Q-03

How does denied-party screening work?

Every recipient is screened automatically against restricted- and denied-party lists before a transfer moves — not just at onboarding. Recipients are rescreened as lists change, and screening results are attached to the transfer record.

Q-04

What does the chain of custody record capture?

Every upload, review, approval, and download, in a tamper-evident, timestamped audit log with file integrity hashing on every transfer. Records are retained to meet record-keeping requirements and export on demand for auditors, primes, and regulators.

Q-05

Can transfers follow our existing approval process?

Yes. Approval chains are configurable to match your export control plan — including empowered official sign-off — and each transfer carries its license and agreement references.

Q-06

How is SecureExport different from email or consumer file-sharing links?

Consumer tools move files; SecureExport moves them inside your export controls. Recipient identity is verified before delivery, access expires and can be revoked, every transfer is screened against denied-party lists, and the audit record is produced automatically instead of reconstructed later.

Q-07

Does SecureExport support CUI?

Yes. SecureExport gives teams handling controlled unclassified information one controlled channel where CUI is handled, marked, and tracked correctly under 32 CFR 2002.

Q-08

What is Sero?

Sero is SecureExport's compliance assistant. It helps your team work through classification questions, screening results, and process steps in plain language, inside the platform with your transfer context at hand. Sero supports your compliance team's judgment; it doesn't replace it.

Q-09

Is SecureExport an alternative to Kiteworks or Descartes Global EASE?

Yes. SecureExport is the system of record for export-controlled technical data: it manages the license and agreement records behind each program, screens every recipient, and documents all file access, approvals, and transfers — along with the controlled transfer itself. Broad secure-content platforms like Kiteworks cover many content types without the export-control workflow; trade compliance suites like Descartes OCR Global EASE center on compliance program paperwork rather than the data. See the full comparison.

Get started

See your first controlled transfer in under 30 minutes

Walk through the platform with our team, using a scenario from your own programs. We'll show you the transfer, the approval, and the record it leaves behind.

WHAT A DEMO COVERS
01  A controlled transfer, end to end
02  Screening & approval workflow
03  The audit record it produces
04  Deployment & identity integration
Demo requestFORM SE-100

Prefer email? [email protected]
SECUREEXPORT // ONE CONTROLLED CHANNEL FOR EXPORT-CONTROLLED DATA