Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
Export controls and trade sanctions — does any of this apply to you? We have subsidiaries in jurisdictions that make my trade-compliance team nervous.?
The question a General Counsel / Chief Legal Officer (CLO) asks.
The short answer
No ITAR, no export-controlled tech — general commercial SaaS at the unrestricted end of classification. The live edge is sanctions, and that's managed: built-in screening with audit-logged results, payment-layer enforcement inherited from Stripe, and contractual territory restrictions.
The full executive answer
Minimal but not zero, and I'll draw the boundary precisely. What we are: a commercially available, general-purpose business-analytics SaaS. We ship no hardware, no defence articles, nothing ITAR touches; publicly available commercial software of this kind sits at the unrestricted end of export-control classification (EAR99-type territory in US terms), and standard encryption in a commercial SaaS benefits from broad license exceptions. We have no US-person technical-data flows of the kind that trigger deemed-export analysis. So the classic export-control machinery mostly doesn't attach — that's the honest core, and I won't manufacture compliance theatre around a risk we don't carry.
What we DO actively manage is the sanctions side, which is the live edge of trade compliance for any SaaS: providing services to sanctioned persons or embargoed territories is prohibited regardless of how benign the software is. Controls: a sanctions-screening module is built into the compliance layer of the platform with screening events recorded at elevated severity in the audit trail, and the payment layer inherits Stripe's and Lemon Squeezy's regulated sanctions programmes — a sanctioned entity's payment fails independently of our own checks. Contractually, our terms prohibit use in embargoed jurisdictions and by restricted parties, which gives both of us the compliance hook your trade team will want to see.
One forward-looking note your team may care about: AI-model export controls are an evolving area (US restrictions have so far targeted model weights and compute, not downstream SaaS applications like ours) — we track it through the same regulatory-horizon monitoring as the AI Act, and because we consume frontier models via US providers' APIs rather than exporting weights, the current restrictions sit upstream of us, with the providers carrying that compliance burden. If your subsidiaries' footprint includes specific jurisdictions of concern, the practical step is naming them in the contract's territory schedule so screening and geo-controls align with your map.
Grounded in: EAR (EAR99 classification context / License Exception ENC); OFAC sanctions programmes; ITAR (non-applicability); EU dual-use regulation 2021/821 (non-applicability for standard commercial SaaS).
The natural next questions
Related governed answers
- Before I put my team on your paper: what's your standard liability and indemnification structure, and where's your actual flexibility?
- Under the EU AI Act, are you the provider and am I the deployer? Because if your workforce-analysis modules are Annex III high-risk, one of us owes Brussels a conformity assessment — and I want to know which of us it is.?
- You keep saying your controls live in code. What does that actually mean — how would my compliance team verify a control is operating?
Want this answered live, on your data?