Delaware LLC SAM.gov Registered CAGE Code 22H91 Microsoft Government Community Cloud — Validated (Cat 2/3)
Independent Research & Advisory

Decision support for national security and economic statecraft.

Structured analysis and advisory support across threat finance, export controls, sanctions, strategic sourcing, and cybersecurity — built for organizations and counsel operating where regulation, security, and geopolitics intersect.

Threat Finance Export Controls Sanctions Strategic Sourcing Cybersecurity
What Sanctir Protects

Identify material risk before it becomes financial loss.

Intelligence, compliance analysis, and decision support for organizations operating across defense, regulated technology, critical supply chains, and international markets.

Protect Revenue

Preserve eligibility

Maintain access to government contracts, transactions, investments, and regulated markets that a compliance failure would foreclose.

Reduce Exposure

Surface risk early

Identify sanctions, export-control, cybersecurity, ownership, and supply-chain risks before they create liability.

Improve Decisions

Defensible judgment

Convert fragmented legal, technical, geopolitical, and commercial information into decisions an executive can stand behind.

Create Advantage

See it first

Identify regulatory, technological, and geopolitical developments before they are fully priced into the market.


Positioning

Sanctir applies structured analytic tradecraft to regulatory and security questions that must withstand legal, technical, and executive review.

The practice serves defense and dual-use firms, investment funds, and outside counsel facing questions that cross cybersecurity, export control, sanctions, and supply-chain lines at once — where a single regulatory regime rarely tells the whole story.

Engagements are structured under a documented methodology: dual-axis probability and confidence labeling, tiered evidence standards, explicit statement of limits, and prohibition on advocacy language. The method is published openly, so the reasoning behind an assessment is visible before an engagement begins.

Featured Research

Published assessments

Independent analysis on cybersecurity attestation, export controls, and counterparty screening. Each assessment states its governing judgment, probability, analytic confidence, and limits.

Your Subcontractor’s Engineer Does Not Exist

What a North Korean placement inside a defense contractor costs a company that did nothing wrong — and what converts it from a victim into a respondent.
SB-2026-04 · 9 Aug 2026

Cleared Does Not Mean Examined

Why a compliance screening program can pass every audit and still not detect the thing it exists to catch.
SB-2026-03 · 9 Aug 2026

The Export Rule Controls Your Data. It Never Tells You How to Protect It.

Where a cybersecurity obligation comes from when the export regulation prescribes none — 10 CFR Part 810, the CUI framework, and why applicability is a contract question.
SB-2026-02 · 30 Jul 2026

The Deadline Went Away. The Obligations Did Not.

What the July 2026 CMMC Phase II suspension changed, what it did not, and what a contractor remains responsible for under representations already made.
SB-2026-01 · 20 Jul 2026
Browse all publications →

Strategic Supply-Chain Intelligence

See the dependency before it becomes the exposure.

Supplier relationships carry risk that financial statements and standard diligence do not show: concentration in a single foreign source, beneficial ownership that resolves to a restricted party, a tier-three dependency no one mapped.

Sanctir applies the same node-control and beneficial-ownership methodology used in its sanctions and threat-finance research to commercial sourcing — mapping dependency, ownership, and adversarial exposure across a supply base so that decisions rest on the actual structure, not the org chart.

Explore supply-chain intelligence
  • Dependency mapping — concentration and single-source risk across tiers
  • Beneficial-ownership resolution — who ultimately controls a supplier
  • Adversarial exposure — restricted-party and jurisdiction risk in the base
  • Sourcing strategy — where to diversify before disruption forces it
Methodology

How the analysis is built

Assessments apply a documented analytic method drawn from intelligence tradecraft — so a reader can see not just the conclusion, but the reasoning and its limits.

Probability & Confidence

Dual-axis labeling

Likelihood and analytic confidence stated separately and explicitly, never collapsed into a single vague adjective.

Evidence

Tiered standards

Sources classified by reliability, with the strength of each supporting judgment made visible rather than assumed.

Discipline

Limits stated, advocacy barred

Each assessment names what it does not cover and what would change the judgment. The work informs a decision; it does not argue for one.

Read the full methodology

Current Analysis

Cybersecurity assurance and attestation risk

A standing area of practice: whether an organization's cybersecurity posture and documentation actually substantiate what it has attested to the government — and where the gap creates enforcement exposure.

Latest Assessment

Your subcontractor’s engineer does not exist.

North Korean IT workers obtained employment at more than 100 US companies using the identities of real Americans; one placement reached ITAR-controlled technical data at a defense contractor. The identity checks did not fail because the adversary was sophisticated — they failed because the adversary bought a real identity. This assessment traces where legal exposure actually attaches: not to the hire, but to what a company does once it could have known. Detection capability, not hiring outcome, determines whether a company stands as a victim or a respondent.

Published 9 August 2026 · Read the assessment
Read the assessment

Companion assessment. Cleared Does Not Mean Examined — the same structural argument applied to counterparty screening: a program that clears without examining cannot state its own failure rate, and process metrics cannot produce the one number an enforcement authority asks for. Read SB-2026-03 →


Engagement Paths

How organizations work with Sanctir

Engagements are scoped to the decision at hand — from a single bounded assessment to ongoing advisory and expert support for counsel and investment teams.

Fixed-Scope Assessment

A bounded question, answered on a defined timeline

Classification analyses, sanctions counterparty review, cybersecurity attestation defensibility, or a supply-chain dependency map — scoped, priced, and delivered as a discrete work product.

Fixed fee · Defined deliverables
Ongoing Advisory

Standing analytic support as conditions change

Retained advisory for organizations navigating live regulatory, sanctions, or sourcing exposure that evolves over time and requires continuity of judgment.

Retainer · Ongoing
Expert & Litigation Support

Technical analysis for counsel and decision-makers

Independent expert analysis, structured assessments, and testimony support on cybersecurity, export control, and sanctions questions in litigation and enforcement contexts.

Hourly · Per engagement
About

About Sanctir

Sanctir is an independent research and advisory practice operating at the intersection of national security, regulation, and economic statecraft. It serves defense and dual-use firms, investment funds, and outside counsel facing questions that cross cybersecurity, export control, sanctions, and supply-chain lines.

The practice is built on a documented analytic method — dual-axis probability and confidence labeling, tiered evidence standards, explicit statement of limits, and a prohibition on advocacy language — applied in every published assessment under CC BY 4.0. Prospective clients can see how the analysis is constructed before an engagement begins.

Scope is deliberately defined. Sanctir delivers assessments, classification analyses and supporting memoranda, and compliance and diligence analysis — work product structured for audit, legal review, and executive decision-making. It does not provide managed security services or staff augmentation.

Principal

Sanctir is led by Collin B. George, CISSP. His background spans national security analysis, cybersecurity, and export control and sanctions compliance. He is the author of the Sanctir assessment series, published open-source under CC BY 4.0.

Sanctir maintains no current government affiliation. Engagements are subject to conflict-of-interest review. Full principal background ›

Method

  • Structured analytic tradecraft
  • Dual-axis probability / confidence labeling
  • Tiered evidence standards
  • Explicit limits and unknowns

Domains

  • Threat finance & sanctions
  • Export controls (ITAR / EAR)
  • Strategic supply-chain intelligence
  • Cybersecurity assurance
  • National security policy

Research

  • Sanctir assessment series (CC BY 4.0)
  • Published under CC BY 4.0
  • Independent research program

Flag of the United States
Commitment

A commitment that does not shift with the political calendar.

Sanctir supports the people who defend the country — in the armed forces, in law enforcement, and in the intelligence community, serving now or having served — and the firms that equip them. That commitment is independent of any administration.

Contact

Discuss an engagement

An initial scoping conversation is provided at no charge. Reach out on whichever channel suits the sensitivity of what you need to discuss.

Response time

Initial response within two business days. Scoping proposals within one week of an initial conversation.

Engagement format

Fixed-fee assessments, retained advisory, and hourly expert support. Fully remote, nationwide.

Before you write

Do not send classified, export-controlled, or privileged material. Describe the situation in general terms first; use Signal or PGP for anything specific. Contact does not create an engagement or confidentiality obligation absent a signed agreement.