Skip to main content
ITAR-focused technical data exchange

ITAR compliant file sharing for controlled defense workflows

My MX Data provides a controlled file exchange route for organizations handling sensitive drawings, specifications, instructions and program files. Named-recipient access, MFA, configurable permissions and detailed activity records can support the operational controls around an ITAR compliance program.

My MX Data does not determine export jurisdiction, classify items, issue DDTC registrations or grant export authorization. Your organization remains responsible for the legal and compliance decisions governing each release.

Start my 7-day free trial

No credit card required. Up to 5 users.

Discuss your ITAR workflow
Named recipientsAccountable user access
MFA protectionExtra verification step
Permission controlsDefined exchange route
Activity recordsUseful release evidence
Before technical data is released

The file is only one part of the export decision

ITAR controls apply to defense articles, defense services and related technical data within the U.S. Munitions List framework. A secure transfer should begin only after the organization has answered the legal and operational questions around the release.

The Directorate of Defense Trade Controls administers the ITAR under 22 CFR parts 120 through 130.

Technology can enforce the access route that follows. It cannot independently decide whether the information is ITAR-controlled, whether a party may receive it or whether a license, agreement or exemption applies.

What is the item or data?

Confirm export jurisdiction and classification, including the relevant USML category where the information is subject to ITAR.

Who will receive access?

Identify the person and organization, including U.S. person or foreign person status and any relevant screening considerations.

What authorizes the release?

Connect the transfer to the applicable license, agreement, exemption or internal basis approved by export compliance.

Where and why will it go?

Confirm destination, end user, end use and any country restrictions before access is provisioned.

Technical data in context

Not every defense-related file is treated the same way

The ITAR definition is specific. Classification should be performed by qualified personnel using the current regulations, contract context and technical facts.

Design and development files

Blueprints, drawings, plans, photographs and documentation required for the design or development of a defense article may fall within technical data.

Production and manufacturing data

Manufacturing instructions, assembly information, processes and other required production data can require controlled handling.

Operation, repair and testing

Instructions required for operation, repair, testing, maintenance or modification of a defense article may be controlled technical data.

Directly related software

Certain software directly related to defense articles can fall within the ITAR definition and should be assessed with the applicable USML controls.

The definition also identifies information that is not technical data

General scientific, mathematical or engineering principles commonly taught in schools and universities, public-domain information, basic marketing information and general system descriptions are excluded from the definition. Review the current 22 CFR 120.33 technical data definition before building controls around assumptions.

A controlled release path

Five decisions before an ITAR-sensitive file moves

The workflow should connect export compliance approval to the exact file, recipient and evidence record used for delivery.

Classify

Confirm jurisdiction, USML category and the scope of the technical data package.

Authorize

Link the release to the relevant approval, agreement, license or exemption analysis.

Verify

Confirm the named user, organization, status, location and approved purpose.

Protect

Apply authentication, permissions and the approved technical safeguards.

Record

Retain the release activity with the wider export authorization and compliance evidence.

Encryption is important, but encryption is not the whole authorization decision

ITAR includes a rule for certain unclassified technical data secured with qualifying end-to-end encryption and other conditions. Organizations must assess every requirement in 22 CFR 120.54 rather than treating encryption alone as permission to release or store data anywhere.

Access follows authorization

Do not turn a shared folder into the access decision

User provisioning should implement an approved decision, not replace it. The organization should know who the person is, why access is required and which authorization covers the release.

Identity and status

Confirm the individual and the relevant U.S. person or foreign person analysis before granting access.

Organization and destination

Check the employer, location, end user and destination against the approved transaction.

Need and scope

Provide only the approved package and permissions required for the person’s role.

Illustrative access decision matrixpolicy owner required
ScenarioStatusControl response
Approved U.S. person employeeProvision

Grant role-based access after confirming training, need and internal approval.

Foreign person employeeReview

Do not provision until export compliance confirms the required authorization or a valid basis.

Approved U.S. supplier userReview

Match the user, company, technical-data scope and purpose to the approved transaction.

Unknown or unverified accountStop

Hold the release and resolve identity, organization, destination and authority.

This matrix is an operational illustration, not a legal determination. The definitions of U.S. person and foreign person should be applied by qualified personnel to the actual facts.

Beyond the transfer tool

Eight elements DDTC identifies for an effective compliance program

DDTC’s Compliance Program Guidelines describe a wider organizational system. Secure file exchange can support several parts of it, but the program must be tailored to the organization’s actual ITAR activities and risks.

Management commitment

Leadership sets expectations, allocates resources and supports a culture in which compliance concerns can be raised.

Registration and authorization

Processes address DDTC registration, jurisdiction, classification, licenses, agreements, exemptions and related activities.

Recordkeeping

Records connect transactions, approvals, exports, exemptions and changes in a form that can be located and reproduced.

Reporting violations

Organizations need routes for detecting, investigating, escalating and addressing potential violations and disclosures.

ITAR training

Training should reflect job responsibilities, risk exposure and the decisions employees are expected to make.

Risk assessment

The program should identify ITAR activities, business functions, data locations, foreign-person exposure and control weaknesses.

Audits and monitoring

Testing and monitoring help determine whether written controls operate consistently and whether corrective actions work.

Compliance manual

A practical manual brings policies, responsibilities, approvals and templates into a usable operating framework.

Review the official DDTC ITAR Compliance Program Guidelines and tailor the program with qualified export-control counsel and specialists.

Reconstruct the release

An activity log is most useful when it connects to the authorization record

File events can support oversight and investigation, but they should sit alongside classification, approvals, screening, licenses, agreements, exemptions and other required records.

ITAR recordkeeping requirements can include records concerning defense articles, technical data, defense services and related export documentation. Required registrants generally retain covered records for the applicable period described in the regulation.

release evidence / ACTUATOR-V17recorded
CLASSIFICATIONInternal reference USML-CAT-VII-042 linked
AUTHORIZATIONRelease basis and scope approved by export compliance
RECIPIENTNamed supplier user matched to approved organization
MFA VERIFIEDSecond factor completed before access
FILE OPENEDACTUATOR-V17.ZIP accessed by named user
REVIEW READYExchange history available to designated administrators
Defense trade file-sharing scenarios

Practical workflows that need more than ordinary email

Each scenario requires its own jurisdiction, authorization and party analysis. The common need is a controlled route after those decisions have been made.

engineering supply chain

Prime-to-supplier technical packages

Deliver approved drawings, specifications and change packages to the named team responsible for a controlled manufacturing task.

classification • authorized recipient • activity record
maintenance and repair

MRO and field-support exchanges

Share approved diagnostic, repair or maintenance instructions with the identified service organization under the applicable authority.

scope control • verified user • protected delivery
program collaboration

Controlled engineering reviews

Exchange design-review files, test results and technical comments among the approved program participants.

need to know • version context • recorded handoff
assurance and response

Audit and investigation evidence

Provide approved logs, correspondence and transaction evidence to authorized reviewers through a restricted route.

evidence integrity • named reviewer • traceability
A supporting control, not an ITAR certification

Where My MX Data fits in an ITAR compliance program

My MX Data can support controlled file handoffs and the activity evidence around them. Compliance depends on how the organization classifies, authorizes, configures and operates the service within its wider export-control program.

Registration is not certification. ITAR registration provides the U.S. Government with information about certain activities and is generally a precondition to licensing. The regulation states that registration does not confer export rights or privileges.

MX can control the approved file handoff

Named accounts, MFA, permissions, protected exchange and activity records can reduce uncertainty around delivery.

Your organization determines jurisdiction and classification

Qualified personnel decide whether the item or information is subject to ITAR, the EAR or another control regime.

Your organization approves the recipient and release

The platform does not screen parties, interpret licenses or determine whether a foreign person may receive access.

Required records extend beyond file events

Activity history should be retained with classification, authorization, transaction and compliance documentation.

Policies, training and monitoring remain essential

A technology control works best inside a documented program with accountable owners, trained users and regular testing.

ITAR compliance FAQs

What defense, engineering and compliance teams usually ask

These answers give practical context, not legal advice. Confirm the current rules and your organization’s facts with qualified export-control professionals.

Visit all FAQs
01What is ITAR and who administers it?

The International Traffic in Arms Regulations are found in 22 CFR parts 120 through 130. They govern defense articles, defense services, technical data, exports, temporary imports, brokering and related activities within the U.S. defense trade-control system.

The regulations are administered by the U.S. Department of State’s Directorate of Defense Trade Controls. The U.S. Munitions List in 22 CFR 121.1 identifies categories of defense articles and related technical data subject to ITAR.

Organizations should begin with the official DDTC ITAR overview and the current regulatory text.

02Does using secure file-sharing software make a company ITAR compliant?

No single software product creates ITAR compliance. A secure exchange can support access control, transmission protection and activity evidence, but ITAR compliance depends on the organization’s classification, registrations, authorizations, screening, policies, training, recordkeeping and monitoring.

Before a user is provisioned, the organization should already know:

  • What the item or data is and how it is classified.
  • Who the recipient is and whether the person may receive access.
  • Which license, agreement, exemption or other basis covers the release.
  • Which destination, end user and end use are approved.

The tool should then implement the approved route rather than make the legal decision.

03What counts as ITAR technical data?

Technical data can include information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance or modification of defense articles. The definition expressly includes formats such as blueprints, drawings, photographs, plans, instructions and documentation.

It can also include specified classified information, information covered by an invention secrecy order and software directly related to defense articles.

The definition excludes some material, including general scientific, mathematical or engineering principles commonly taught in schools and universities, public-domain information, basic marketing information and general system descriptions. Review 22 CFR 120.33 and obtain a qualified classification decision for the actual data.

04Can ITAR-controlled technical data be stored or sent through the cloud?

The answer depends on the data, users, locations, architecture and the precise regulatory conditions. Cloud does not automatically mean permitted or prohibited.

22 CFR 120.54 identifies certain activities involving unclassified technical data that are not treated as exports, reexports or retransfers when all listed conditions are satisfied. Those conditions include qualifying end-to-end encryption, approved cryptographic strength and restrictions involving countries identified under 22 CFR 126.1.

Organizations should document how encryption, key management, access, backups, support personnel, storage locations and incident response satisfy the rule. Read the complete 22 CFR 120.54 conditions before relying on them.

05Does DDTC registration mean a business is ITAR certified?

No. The ITAR does not describe DDTC registration as a product or company certification. Registration is primarily a way for the U.S. Government to know who is engaged in specified manufacturing, exporting, temporarily importing and defense-service activities.

Registration is generally a precondition to obtaining licenses or other approvals, subject to the regulations. It does not confer export rights or privileges.

Organizations should review 22 CFR 122.1 and determine whether registration requirements or exemptions apply to their activities.

06Can a foreign person employee access ITAR-controlled technical data?

Access should not be granted merely because the person works for the organization or can sign into the system. The organization must assess the person’s status, the technical data, the activity and the authorization required for the release.

A sound process normally connects HR, export compliance, IT and the program owner so the account is not provisioned before the legal and operational decision is complete.

Where authorization is required, the scope, provisos and technology-control measures should be reflected in the user’s permissions. The DDTC risk guidance specifically highlights weak controls for unauthorized access by foreign-person employees as a risk area.

07How long must ITAR records be retained?

Under 22 CFR 122.5, required registrants must maintain specified records concerning defense articles, technical data, defense services, brokering and related transactions. The regulation generally requires covered records to be maintained for five years from the applicable license or approval expiration, or from the transaction date in specified circumstances.

Electronic records must be reproducible and sufficiently legible and readable. Changes should be recorded with who made them and when.

A platform activity history can contribute useful evidence, but it should be retained with the broader authorization, classification, transaction and compliance records required by the organization. Review the full recordkeeping rule.

08What should an organization assess before choosing an ITAR file-sharing service?

Start with the organization’s actual data flows and authorizations rather than a generic checklist. Identify where technical data is created, stored, backed up, transmitted and accessed, including administrators, support personnel, integrations and subcontractors.

Evaluate at least:

  • Identity and access: named accounts, MFA, approval workflows and prompt removal of access.
  • Data protection: encryption design, key management, storage architecture and recovery processes.
  • Location and personnel: where data and backups reside and who may administer or support the environment.
  • Evidence and response: activity history, change records, alerting, incident support and exportable records.

Then document how the service fits into the organization’s licenses, agreements, technology-control plans, retention schedule and compliance manual. A tailored enterprise review is more reliable than relying on a marketing label alone.

Give technical data a controlled route

See how My MX Data can support your ITAR file-sharing workflow

Bring export compliance, engineering, security and approved external partners into a more accountable exchange, with clearer controls around recipient access and a more useful activity history.

Start my 7-day free trial

No credit card required. Up to 5 users.

Talk through the workflow
Named-recipient accessConfigurable permissionsMFADetailed activity records