ITAR Compliance Software
ITAR compliance software for defense manufacturers. US-only data residency, US-persons access controls, and audit trails for controlled technical data.
ITAR technical data sits in your ERP right now, and one foreign national viewing a controlled drawing is a deemed export with penalties up to $1.1M per access. WorkCell is ITAR compliance software built for defense manufacturers and aligned to what ITAR asks of the systems that hold controlled technical data: US-only data residency, US-persons-only access and support, per-tenant isolation, and audit logging on production access. Our DDTC registration is in progress. Treat WorkCell as the ITAR software compliance layer under your existing quality, engineering, and shop floor work.
Sound Familiar?
Cloud ERP with foreign support staff
Your SaaS vendor's support and infra teams sit in India, Ireland, or the Philippines, which means every time they touch the database on your behalf they're a foreign person accessing ITAR technical data.
No way to enforce US persons only
Your ERP has user accounts but no concept of citizenship, so a single onboarding mistake puts a foreign national inside controlled technical data without any export control catching it.
Data residency audits you can't pass
A prime asks where your drawings, backups, and DR copies physically live and who can reach them, and your current vendor can't produce a clean US-only answer in writing.
Losing a DoD program over the stack
Security reviews from primes now reject non-compliant SaaS outright, and an ITAR-ineligible ERP is enough to disqualify you from the flowdown on a $10M subcontract.
Core Capabilities
US-only data residency
Production runs in US regions only, AWS us-east-1 and us-east-2, with no cross-region replication to any non-US region. Your tenant is isolated from every other tenant, and no foreign support organization sits anywhere in the path. That US-only boundary is the baseline any ITAR ERP has to meet.
US persons access enforcement
ITAR requires that only US persons reach controlled technical data, and WorkCell is aligned to that standard. Every person with access to production infrastructure is a US person, access to your tenant is controlled, and there is no path by which a foreign person at WorkCell touches your data.
USML-aware document marking
ITAR and EAR expect controlled technical data to be identified by USML category or ECCN and handled consistently wherever it appears, including search, export, and print. This ITAR compliance software is aligned to that standard for the drawings, specs, BOMs, and routings it holds.
Deemed export audit logs
ITAR expects you to be able to reconstruct who reached controlled technical data and when. Access to production is logged through CloudTrail, and WorkCell is aligned to the deemed export recordkeeping DDTC and your primes ask for.
Controlled backups and disaster recovery
Snapshots, backups, and DR copies stay inside the same US-only boundary as production, because nothing replicates outside US regions. An outage never moves your data somewhere it should not be.
US-staffed support and administration
Every engineer, support rep, and database administrator with access to your tenant is a US person on US soil, which removes the deemed export exposure most cloud ERPs carry by default.
By The Numbers
Maximum DDTC civil penalty per ITAR violation, adjusted annually for inflation and counted per document, per access, per day
22 CFR 127.10, DDTC Civil Monetary Penalty Adjustments
Honeywell consent agreement with DDTC in 2021 for unauthorized exports of technical drawings covering F-35, F-22, B-1B, and Apache parts to China, Taiwan, Canada, Ireland, and Mexico
US State Department DDTC Consent Agreement
Maximum criminal prison sentence per willful ITAR violation under the Arms Export Control Act, plus criminal fines up to $1M per violation
22 USC 2778(c)
Connected Modules
Engineering
Controlled technical data starts here, in drawings, CAD files, specs, and ECOs, and its controlled status has to follow it into every BOM, routing, and work order that references it. Engineering is aligned to that requirement.
Quality
Inspection plans, first articles, and nonconformance records for ITAR parts are controlled technical data, and they live inside the same US-only, single-tenant boundary as the rest of your data.
Shop Floor
Routers and work orders put controlled technical data in front of operators, which is where deemed export exposure runs highest. Shop Floor is aligned to the US-persons standard ITAR sets for that access.
Common Questions
What is ITAR compliance software?
ITAR compliance software is any system that stores, transmits, or provides access to ITAR-controlled technical data and enforces the State Department's export control rules around it. In practice that means US-only data residency, US-persons-only access and support, document-level controlled data marking against the US Munitions List, and deemed export audit logs that let you prove who saw what and when.
Do I need ITAR compliance if I'm a sub-tier defense manufacturer?
If you manufacture, handle drawings for, or furnish services related to anything on the US Munitions List, yes. DDTC registration and ITAR obligations flow down from the prime to every sub-tier that touches the technical data, regardless of company size, and your customer will require written confirmation before they release drawings.
Is a generic SaaS ERP ITAR compliant out of the box?
Almost never. Most cloud ERPs replicate data to non-US regions, use foreign support staff who can touch production data, and have no concept of US-persons access at the record level. Unless the vendor has a dedicated ITAR tenant with US-only infrastructure, US-person support, and citizenship-aware access controls, assume it's not ITAR compliant.
What is US persons access under ITAR?
A US person under ITAR is a US citizen, lawful permanent resident (green card holder), or protected individual under 8 USC 1324b(a)(3). US persons access means only those users can view, download, or otherwise touch ITAR technical data. Any release to a foreign person, even one standing in your US office, is a deemed export requiring a DDTC license.
What counts as technical data under ITAR?
Technical data is any information required to design, produce, repair, or modify a defense article on the US Munitions List. That includes drawings, 3D models, CAD files, specs, work instructions, inspection plans, process data, and source code. If it describes how to build or maintain the controlled item, ITAR covers it.
How does ITAR differ from EAR compliance?
ITAR is administered by the State Department's DDTC and covers defense articles and services on the US Munitions List. EAR (the Export Administration Regulations) is administered by the Commerce Department's BIS and covers dual-use items on the Commerce Control List, tagged with ECCNs. Many defense manufacturers handle both, and a single ERP has to mark, segregate, and log access for each.
ITAR Compliance Software
Run ITAR workloads on infrastructure that stays inside the United States.