ECCN.DEV by Cancelli

Can I keep controlled engineering data in the cloud?

Often yes, if the encryption is right and nobody else holds the keys. The provider's administrators are part of your access question.

Written for: Teams using commercial cloud, SaaS, or contract manufacturers

The short answer

  • Qualifying end to end encryption can keep transmission and storage out of scope.
  • Every condition applies together, including that nobody else holds the keys.
  • Provider administrators and subprocessors are inside your access boundary.
  • A travelling laptop carries what it can reach, not just what is stored on it.

The rule that makes cloud workable

Both regimes contain provisions under which sending, taking, or storing unclassified technical data is not treated as an export when the data is secured end to end with qualifying cryptography, the means of decryption are not provided to any third party, and the destination conditions the provision sets are met. The two lists of conditions are not the same list, and the next section sets both out. The ITAR adds a condition the EAR does not: under 22 CFR 120.54(b)(2)↗ the intended recipient has to be the originator, a U.S. person in the United States, or somebody otherwise authorized to receive the technical data. 15 CFR 734.18↗ sets no recipient condition. This is what allows ordinary cloud use without treating every backup as a shipment abroad.

Every condition, not most of them

These are lists of conditions and they operate together, so meeting most of them is not meeting them. 22 CFR 120.54(a)(5)↗ has five. The technical data has to be unclassified; secured using end to end encryption; secured using cryptographic modules compliant with FIPS 140-2 or its successors, supplemented by software implementation, cryptographic key management and other procedures and controls in accordance with guidance in current NIST publications, or by other cryptographic means providing security strength at least comparable to the 128 bits of AES-128; not intentionally sent to a person in, or stored in, a country proscribed in 22 CFR 126.1↗; and not sent from a country proscribed in 126.1. The last one is about where the sender is standing rather than where the data lands, and it is the one that gets missed, because it catches a laptop opened on a trip rather than anything about the storage arrangement. The module condition is one clause with two legs on the FIPS side, and the supplement is the leg that gets dropped: a validated module whose keys nobody manages meets the first half of that condition and not the condition.

The EAR's four are not the ITAR's five

15 CFR 734.18(a)(5)↗ is built the same way and its conditions are different ones. The data has to be unclassified, secured using end to end encryption, secured using FIPS 140-2 compliant modules supplemented by software implementation, cryptographic key management and other procedures and controls in accordance with guidance in current NIST publications, or other equally or more effective cryptographic means, and not intentionally stored in a country listed in Country Group D:5. So the country list is a different list from 126.1, the condition reaches storage rather than storage and sending to a person there, and there is no condition at all about the country the data was sent from. An arrangement built to the EAR provision is not automatically inside the ITAR one, which matters the moment the same tenancy holds both kinds of data.

Who holds the keys decides it

A provider who can read your plaintext, or who holds your keys, fails the end to end condition under both provisions rather than weakening it. Both define end to end encryption to require that the means of decryption are not provided to any third party, at 22 CFR 120.54(b)(1)(ii)↗ and 15 CFR 734.18(b)↗. That is a condition about who can decrypt, not about how strong the algorithm is, and no amount of key length answers it.

The administrators nobody counted

If a provider's staff can reach the plaintext, then their locations and nationalities are inside your boundary. That includes support engineers during an incident, subprocessors you have never spoken to, and whichever region a backup replicates into. Approving a vendor means knowing the data path, the storage and support locations, and who holds the keys, before data goes in rather than after.

Laptops are the same question in a smaller box

A device leaving the country carries whatever is on it, including data it can merely reach. The usual answer is a clean device with nothing local, reaching data over an encrypted connection under conditions decided in advance and written down.

The rules behind this

This is a plain reading of published rules, not legal advice, and it is not a determination about your item. What decides your case is your exact configuration, your parties, and your destination. The limits, in full.

Next

Related questions