ECCN.DEV by Cancelli

Can I keep controlled engineering data in the cloud?

Often yes, if the encryption is right and nobody else holds the keys. The provider's administrators are part of your access question.

Written for: Teams using commercial cloud, SaaS, or contract manufacturers

The short answer

  • Qualifying end to end encryption can keep transmission and storage out of scope.
  • Every condition applies together, including that nobody else holds the keys.
  • Provider administrators and subprocessors are inside your access boundary.
  • A travelling laptop carries what it can reach, not just what is stored on it.

The rule that makes cloud workable

Both regimes contain provisions under which sending, taking, or storing unclassified technical data is not treated as an export when the data is secured end to end with qualifying cryptography, the recipient is authorized, and the means of decryption are not provided to anyone else. This is what allows ordinary cloud use without treating every backup as a shipment abroad.

Every condition, not most of them

These provisions are lists of conditions and they operate together. Qualifying cryptography, end to end, no keys handed to the provider, and the data not intentionally stored in a prohibited destination. Meeting three of four is not meeting them. A provider who can read your plaintext or who holds your keys defeats the whole structure regardless of how strong the algorithm is.

The administrators nobody counted

If a provider's staff can reach the plaintext, then their locations and nationalities are inside your boundary. That includes support engineers during an incident, subprocessors you have never spoken to, and whichever region a backup replicates into. Approving a vendor means knowing the data path, the storage and support locations, and who holds the keys, before data goes in rather than after.

Laptops are the same question in a smaller box

A device leaving the country carries whatever is on it, including data it can merely reach. The usual answer is a clean device with nothing local, reaching data over an encrypted connection under conditions decided in advance and written down.

The rules behind this

This is a plain reading of published rules, not legal advice, and it is not a determination about your item. What decides your case is your exact configuration, your parties, and your destination. The limits, in full.

Next

Related questions