What is the item or data?
Confirm export jurisdiction and classification, including the relevant USML category where the information is subject to ITAR.
Quantum secure · GDPR & ISO 27001 focused
My MX Data provides a controlled file exchange route for organizations handling sensitive drawings, specifications, instructions and program files. Named-recipient access, MFA, configurable permissions and detailed activity records can support the operational controls around an ITAR compliance program.
My MX Data does not determine export jurisdiction, classify items, issue DDTC registrations or grant export authorization. Your organization remains responsible for the legal and compliance decisions governing each release.
No credit card required. Up to 5 users.
SCOPE CONFIRMEDPackage linked to internal jurisdiction and classification record.
RECIPIENT APPROVEDNamed account matched to the authorized organization and access purpose.
EXCHANGE RECORDEDRecipient verification and file activity added to the release history.
ITAR controls apply to defense articles, defense services and related technical data within the U.S. Munitions List framework. A secure transfer should begin only after the organization has answered the legal and operational questions around the release.
The Directorate of Defense Trade Controls administers the ITAR under 22 CFR parts 120 through 130.
Technology can enforce the access route that follows. It cannot independently decide whether the information is ITAR-controlled, whether a party may receive it or whether a license, agreement or exemption applies.
Confirm export jurisdiction and classification, including the relevant USML category where the information is subject to ITAR.
Identify the person and organization, including U.S. person or foreign person status and any relevant screening considerations.
Connect the transfer to the applicable license, agreement, exemption or internal basis approved by export compliance.
Confirm destination, end user, end use and any country restrictions before access is provisioned.
The ITAR definition is specific. Classification should be performed by qualified personnel using the current regulations, contract context and technical facts.
Blueprints, drawings, plans, photographs and documentation required for the design or development of a defense article may fall within technical data.
Manufacturing instructions, assembly information, processes and other required production data can require controlled handling.
Instructions required for operation, repair, testing, maintenance or modification of a defense article may be controlled technical data.
Certain software directly related to defense articles can fall within the ITAR definition and should be assessed with the applicable USML controls.
General scientific, mathematical or engineering principles commonly taught in schools and universities, public-domain information, basic marketing information and general system descriptions are excluded from the definition. Review the current 22 CFR 120.33 technical data definition before building controls around assumptions.
The workflow should connect export compliance approval to the exact file, recipient and evidence record used for delivery.
Confirm jurisdiction, USML category and the scope of the technical data package.
Link the release to the relevant approval, agreement, license or exemption analysis.
Confirm the named user, organization, status, location and approved purpose.
Apply authentication, permissions and the approved technical safeguards.
Retain the release activity with the wider export authorization and compliance evidence.
ITAR includes a rule for certain unclassified technical data secured with qualifying end-to-end encryption and other conditions. Organizations must assess every requirement in 22 CFR 120.54 rather than treating encryption alone as permission to release or store data anywhere.
User provisioning should implement an approved decision, not replace it. The organization should know who the person is, why access is required and which authorization covers the release.
Confirm the individual and the relevant U.S. person or foreign person analysis before granting access.
Check the employer, location, end user and destination against the approved transaction.
Provide only the approved package and permissions required for the person’s role.
Grant role-based access after confirming training, need and internal approval.
Do not provision until export compliance confirms the required authorization or a valid basis.
Match the user, company, technical-data scope and purpose to the approved transaction.
Hold the release and resolve identity, organization, destination and authority.
This matrix is an operational illustration, not a legal determination. The definitions of U.S. person and foreign person should be applied by qualified personnel to the actual facts.
DDTC’s Compliance Program Guidelines describe a wider organizational system. Secure file exchange can support several parts of it, but the program must be tailored to the organization’s actual ITAR activities and risks.
Leadership sets expectations, allocates resources and supports a culture in which compliance concerns can be raised.
Processes address DDTC registration, jurisdiction, classification, licenses, agreements, exemptions and related activities.
Records connect transactions, approvals, exports, exemptions and changes in a form that can be located and reproduced.
Organizations need routes for detecting, investigating, escalating and addressing potential violations and disclosures.
Training should reflect job responsibilities, risk exposure and the decisions employees are expected to make.
The program should identify ITAR activities, business functions, data locations, foreign-person exposure and control weaknesses.
Testing and monitoring help determine whether written controls operate consistently and whether corrective actions work.
A practical manual brings policies, responsibilities, approvals and templates into a usable operating framework.
Review the official DDTC ITAR Compliance Program Guidelines and tailor the program with qualified export-control counsel and specialists.
File events can support oversight and investigation, but they should sit alongside classification, approvals, screening, licenses, agreements, exemptions and other required records.
ITAR recordkeeping requirements can include records concerning defense articles, technical data, defense services and related export documentation. Required registrants generally retain covered records for the applicable period described in the regulation.
My MX Data can help operationalize an approved release through identity, access and file-activity controls.
Use accountable user accounts rather than broad links or shared credentials for sensitive exchanges.
Explore platform featuresMove approved files through an encrypted exchange route with additional recipient verification.
See encrypted file sharingUse My MX Data’s patented anonymize, shard and restore methodology within the protected exchange.
Understand the protection modelRetain a clearer account of sender, recipient and file events for oversight and investigation.
Read about audit trailsGive designated administrators a clearer way to manage users, exchanges and operational policy.
View the product walkthroughExplore file-sharing considerations for NIST SP 800-171 where controlled unclassified information is also in scope.
View NIST 800-171 guidanceSet the exchange route around the intended recipient and approved interaction with the file.
Review permission featuresUse a structured business-to-business exchange for suppliers, customers and program partners.
Explore secure file exchangeEach scenario requires its own jurisdiction, authorization and party analysis. The common need is a controlled route after those decisions have been made.
Deliver approved drawings, specifications and change packages to the named team responsible for a controlled manufacturing task.
classification • authorized recipient • activity recordShare approved diagnostic, repair or maintenance instructions with the identified service organization under the applicable authority.
scope control • verified user • protected deliveryExchange design-review files, test results and technical comments among the approved program participants.
need to know • version context • recorded handoffProvide approved logs, correspondence and transaction evidence to authorized reviewers through a restricted route.
evidence integrity • named reviewer • traceabilityMy MX Data can support controlled file handoffs and the activity evidence around them. Compliance depends on how the organization classifies, authorizes, configures and operates the service within its wider export-control program.
Registration is not certification. ITAR registration provides the U.S. Government with information about certain activities and is generally a precondition to licensing. The regulation states that registration does not confer export rights or privileges.
Named accounts, MFA, permissions, protected exchange and activity records can reduce uncertainty around delivery.
Qualified personnel decide whether the item or information is subject to ITAR, the EAR or another control regime.
The platform does not screen parties, interpret licenses or determine whether a foreign person may receive access.
Activity history should be retained with classification, authorization, transaction and compliance documentation.
A technology control works best inside a documented program with accountable owners, trained users and regular testing.
These answers give practical context, not legal advice. Confirm the current rules and your organization’s facts with qualified export-control professionals.
Visit all FAQsThe International Traffic in Arms Regulations are found in 22 CFR parts 120 through 130. They govern defense articles, defense services, technical data, exports, temporary imports, brokering and related activities within the U.S. defense trade-control system.
The regulations are administered by the U.S. Department of State’s Directorate of Defense Trade Controls. The U.S. Munitions List in 22 CFR 121.1 identifies categories of defense articles and related technical data subject to ITAR.
Organizations should begin with the official DDTC ITAR overview and the current regulatory text.
No single software product creates ITAR compliance. A secure exchange can support access control, transmission protection and activity evidence, but ITAR compliance depends on the organization’s classification, registrations, authorizations, screening, policies, training, recordkeeping and monitoring.
Before a user is provisioned, the organization should already know:
The tool should then implement the approved route rather than make the legal decision.
Technical data can include information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance or modification of defense articles. The definition expressly includes formats such as blueprints, drawings, photographs, plans, instructions and documentation.
It can also include specified classified information, information covered by an invention secrecy order and software directly related to defense articles.
The definition excludes some material, including general scientific, mathematical or engineering principles commonly taught in schools and universities, public-domain information, basic marketing information and general system descriptions. Review 22 CFR 120.33 and obtain a qualified classification decision for the actual data.
The answer depends on the data, users, locations, architecture and the precise regulatory conditions. Cloud does not automatically mean permitted or prohibited.
22 CFR 120.54 identifies certain activities involving unclassified technical data that are not treated as exports, reexports or retransfers when all listed conditions are satisfied. Those conditions include qualifying end-to-end encryption, approved cryptographic strength and restrictions involving countries identified under 22 CFR 126.1.
Organizations should document how encryption, key management, access, backups, support personnel, storage locations and incident response satisfy the rule. Read the complete 22 CFR 120.54 conditions before relying on them.
No. The ITAR does not describe DDTC registration as a product or company certification. Registration is primarily a way for the U.S. Government to know who is engaged in specified manufacturing, exporting, temporarily importing and defense-service activities.
Registration is generally a precondition to obtaining licenses or other approvals, subject to the regulations. It does not confer export rights or privileges.
Organizations should review 22 CFR 122.1 and determine whether registration requirements or exemptions apply to their activities.
Access should not be granted merely because the person works for the organization or can sign into the system. The organization must assess the person’s status, the technical data, the activity and the authorization required for the release.
A sound process normally connects HR, export compliance, IT and the program owner so the account is not provisioned before the legal and operational decision is complete.
Where authorization is required, the scope, provisos and technology-control measures should be reflected in the user’s permissions. The DDTC risk guidance specifically highlights weak controls for unauthorized access by foreign-person employees as a risk area.
Under 22 CFR 122.5, required registrants must maintain specified records concerning defense articles, technical data, defense services, brokering and related transactions. The regulation generally requires covered records to be maintained for five years from the applicable license or approval expiration, or from the transaction date in specified circumstances.
Electronic records must be reproducible and sufficiently legible and readable. Changes should be recorded with who made them and when.
A platform activity history can contribute useful evidence, but it should be retained with the broader authorization, classification, transaction and compliance records required by the organization. Review the full recordkeeping rule.
Start with the organization’s actual data flows and authorizations rather than a generic checklist. Identify where technical data is created, stored, backed up, transmitted and accessed, including administrators, support personnel, integrations and subcontractors.
Evaluate at least:
Then document how the service fits into the organization’s licenses, agreements, technology-control plans, retention schedule and compliance manual. A tailored enterprise review is more reliable than relying on a marketing label alone.
Bring export compliance, engineering, security and approved external partners into a more accountable exchange, with clearer controls around recipient access and a more useful activity history.
No credit card required. Up to 5 users.
Free for 7 days · up to 5 users
Trusted for 150K+ exchanges weekly
No credit card required. Set up in minutes.
Check your inbox, your MX trial details are on their way. Welcome to properly secure file sharing.