[ITAR Compliance]

ITAR Compliance Software

ITAR compliance software for defense manufacturers. US-only data residency, US-persons access controls, and audit trails for controlled technical data.

ITAR technical data sits in your ERP right now, and one foreign national viewing a controlled drawing is a deemed export with penalties up to $1.1M per access. WorkCell is ITAR compliance software built for defense manufacturers and aligned to what ITAR asks of the systems that hold controlled technical data: US-only data residency, US-persons-only access and support, per-tenant isolation, and audit logging on production access. Our DDTC registration is in progress. Treat WorkCell as the ITAR software compliance layer under your existing quality, engineering, and shop floor work.

Sound Familiar?

Cloud ERP with foreign support staff

Your SaaS vendor's support and infra teams sit in India, Ireland, or the Philippines, which means every time they touch the database on your behalf they're a foreign person accessing ITAR technical data.

No way to enforce US persons only

Your ERP has user accounts but no concept of citizenship, so a single onboarding mistake puts a foreign national inside controlled technical data without any export control catching it.

Data residency audits you can't pass

A prime asks where your drawings, backups, and DR copies physically live and who can reach them, and your current vendor can't produce a clean US-only answer in writing.

Losing a DoD program over the stack

Security reviews from primes now reject non-compliant SaaS outright, and an ITAR-ineligible ERP is enough to disqualify you from the flowdown on a $10M subcontract.

Core Capabilities

US-only data residency

Production runs in US regions only, AWS us-east-1 and us-east-2, with no cross-region replication to any non-US region. Your tenant is isolated from every other tenant, and no foreign support organization sits anywhere in the path. That US-only boundary is the baseline any ITAR ERP has to meet.

US persons access enforcement

ITAR requires that only US persons reach controlled technical data, and WorkCell is aligned to that standard. Every person with access to production infrastructure is a US person, access to your tenant is controlled, and there is no path by which a foreign person at WorkCell touches your data.

USML-aware document marking

ITAR and EAR expect controlled technical data to be identified by USML category or ECCN and handled consistently wherever it appears, including search, export, and print. This ITAR compliance software is aligned to that standard for the drawings, specs, BOMs, and routings it holds.

Deemed export audit logs

ITAR expects you to be able to reconstruct who reached controlled technical data and when. Access to production is logged through CloudTrail, and WorkCell is aligned to the deemed export recordkeeping DDTC and your primes ask for.

Controlled backups and disaster recovery

Snapshots, backups, and DR copies stay inside the same US-only boundary as production, because nothing replicates outside US regions. An outage never moves your data somewhere it should not be.

US-staffed support and administration

Every engineer, support rep, and database administrator with access to your tenant is a US person on US soil, which removes the deemed export exposure most cloud ERPs carry by default.

By The Numbers

$1.197M

Maximum DDTC civil penalty per ITAR violation, adjusted annually for inflation and counted per document, per access, per day

22 CFR 127.10, DDTC Civil Monetary Penalty Adjustments

$20M

Honeywell consent agreement with DDTC in 2021 for unauthorized exports of technical drawings covering F-35, F-22, B-1B, and Apache parts to China, Taiwan, Canada, Ireland, and Mexico

US State Department DDTC Consent Agreement

20 years

Maximum criminal prison sentence per willful ITAR violation under the Arms Export Control Act, plus criminal fines up to $1M per violation

22 USC 2778(c)

Common Questions

What is ITAR compliance software?

ITAR compliance software is any system that stores, transmits, or provides access to ITAR-controlled technical data and enforces the State Department's export control rules around it. In practice that means US-only data residency, US-persons-only access and support, document-level controlled data marking against the US Munitions List, and deemed export audit logs that let you prove who saw what and when.

Do I need ITAR compliance if I'm a sub-tier defense manufacturer?

If you manufacture, handle drawings for, or furnish services related to anything on the US Munitions List, yes. DDTC registration and ITAR obligations flow down from the prime to every sub-tier that touches the technical data, regardless of company size, and your customer will require written confirmation before they release drawings.

Is a generic SaaS ERP ITAR compliant out of the box?

Almost never. Most cloud ERPs replicate data to non-US regions, use foreign support staff who can touch production data, and have no concept of US-persons access at the record level. Unless the vendor has a dedicated ITAR tenant with US-only infrastructure, US-person support, and citizenship-aware access controls, assume it's not ITAR compliant.

What is US persons access under ITAR?

A US person under ITAR is a US citizen, lawful permanent resident (green card holder), or protected individual under 8 USC 1324b(a)(3). US persons access means only those users can view, download, or otherwise touch ITAR technical data. Any release to a foreign person, even one standing in your US office, is a deemed export requiring a DDTC license.

What counts as technical data under ITAR?

Technical data is any information required to design, produce, repair, or modify a defense article on the US Munitions List. That includes drawings, 3D models, CAD files, specs, work instructions, inspection plans, process data, and source code. If it describes how to build or maintain the controlled item, ITAR covers it.

How does ITAR differ from EAR compliance?

ITAR is administered by the State Department's DDTC and covers defense articles and services on the US Munitions List. EAR (the Export Administration Regulations) is administered by the Commerce Department's BIS and covers dual-use items on the Commerce Control List, tagged with ECCNs. Many defense manufacturers handle both, and a single ERP has to mark, segregate, and log access for each.

[Get Started]

ITAR Compliance Software

Run ITAR workloads on infrastructure that stays inside the United States.