Skip to main content

Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal

Export controls and trade sanctions — does any of this apply to you? We have subsidiaries in jurisdictions that make my trade-compliance team nervous.?

The question a General Counsel / Chief Legal Officer (CLO) asks.

The short answer

No ITAR, no export-controlled tech — general commercial SaaS at the unrestricted end of classification. The live edge is sanctions, and that's managed: built-in screening with audit-logged results, payment-layer enforcement inherited from Stripe, and contractual territory restrictions.

The full executive answer

Minimal but not zero, and I'll draw the boundary precisely. What we are: a commercially available, general-purpose business-analytics SaaS. We ship no hardware, no defence articles, nothing ITAR touches; publicly available commercial software of this kind sits at the unrestricted end of export-control classification (EAR99-type territory in US terms), and standard encryption in a commercial SaaS benefits from broad license exceptions. We have no US-person technical-data flows of the kind that trigger deemed-export analysis. So the classic export-control machinery mostly doesn't attach — that's the honest core, and I won't manufacture compliance theatre around a risk we don't carry.

What we DO actively manage is the sanctions side, which is the live edge of trade compliance for any SaaS: providing services to sanctioned persons or embargoed territories is prohibited regardless of how benign the software is. Controls: a sanctions-screening module is built into the compliance layer of the platform with screening events recorded at elevated severity in the audit trail, and the payment layer inherits Stripe's and Lemon Squeezy's regulated sanctions programmes — a sanctioned entity's payment fails independently of our own checks. Contractually, our terms prohibit use in embargoed jurisdictions and by restricted parties, which gives both of us the compliance hook your trade team will want to see.

One forward-looking note your team may care about: AI-model export controls are an evolving area (US restrictions have so far targeted model weights and compute, not downstream SaaS applications like ours) — we track it through the same regulatory-horizon monitoring as the AI Act, and because we consume frontier models via US providers' APIs rather than exporting weights, the current restrictions sit upstream of us, with the providers carrying that compliance burden. If your subsidiaries' footprint includes specific jurisdictions of concern, the practical step is naming them in the contract's territory schedule so screening and geo-controls align with your map.

Grounded in: EAR (EAR99 classification context / License Exception ENC); OFAC sanctions programmes; ITAR (non-applicability); EU dual-use regulation 2021/821 (non-applicability for standard commercial SaaS).

Want this answered live, on your data?