Can I keep controlled engineering data in the cloud?
Often yes, if the encryption is right and nobody else holds the keys. The provider's administrators are part of your access question.
Written for: Teams using commercial cloud, SaaS, or contract manufacturers
The short answer
- Qualifying end to end encryption can keep transmission and storage out of scope.
- Every condition applies together, including that nobody else holds the keys.
- Provider administrators and subprocessors are inside your access boundary.
- A travelling laptop carries what it can reach, not just what is stored on it.
The rule that makes cloud workable
Both regimes contain provisions under which sending, taking, or storing unclassified technical data is not treated as an export when the data is secured end to end with qualifying cryptography, the recipient is authorized, and the means of decryption are not provided to anyone else. This is what allows ordinary cloud use without treating every backup as a shipment abroad.
Every condition, not most of them
These provisions are lists of conditions and they operate together. Qualifying cryptography, end to end, no keys handed to the provider, and the data not intentionally stored in a prohibited destination. Meeting three of four is not meeting them. A provider who can read your plaintext or who holds your keys defeats the whole structure regardless of how strong the algorithm is.
The administrators nobody counted
If a provider's staff can reach the plaintext, then their locations and nationalities are inside your boundary. That includes support engineers during an incident, subprocessors you have never spoken to, and whichever region a backup replicates into. Approving a vendor means knowing the data path, the storage and support locations, and who holds the keys, before data goes in rather than after.
Laptops are the same question in a smaller box
A device leaving the country carries whatever is on it, including data it can merely reach. The usual answer is a clean device with nothing local, reaching data over an encrypted connection under conditions decided in advance and written down.
The rules behind this
- 15 CFR 734.18
- 22 CFR 120.54
- 15 CFR 734.13
This is a plain reading of published rules, not legal advice, and it is not a determination about your item. What decides your case is your exact configuration, your parties, and your destination. The limits, in full.
Next
- What is a deemed export?
- Does encryption in my product trigger export controls?
- Find out what applies to you
Related questions
ITAR or EAR, which one applies to me?
Two regimes, two agencies, and the wrong guess is expensive. The test is what the item is and what it was designed for, not what industry you are in.
What does EAR99 actually mean?
It means no Commerce entry describes your item. It does not mean you can ship it anywhere, and it is not a licence.
Can I hire an engineer who is not a U.S. citizen?
Yes. Export control regulates what you show them, not who you employ, and treating it as a hiring rule creates a different legal problem.
What is a deemed export?
Showing controlled technology to a foreign person inside the United States counts as exporting it to their country. Nothing has to ship.