Navigate export controls
Whether a commodity, technology, or data flow is controlled, at what level, and how to structure classification, licensing, and deemed-export handling to hold up on review.
Export control questions turn on specifics: the technical characteristics of an item, the citizenship of the people who can access it, the jurisdictions data moves through. A determination that is not tied precisely to those facts does not survive scrutiny.
Sanctir provides commodity jurisdiction and ECCN classification, deemed-export risk analysis for organizations with foreign-national staff, technology control plan development, and voluntary self-disclosure preparation — each documented so the basis for the finding is explicit and defensible.
Work spans ITAR (22 CFR 120–130) and the EAR (15 CFR 730–774), including BIS Entity List exposure in the supply base.
For firms weighing what an export-control obligation actually requires of their systems: The Export Rule Controls Your Data. It Never Tells You How to Protect It. — where a cybersecurity obligation actually comes from when an export-control regulation controls your information but prescribes no control set. 10 CFR Part 810, the CUI framework, and why applicability is a contract question, not a question about the data. Read SB-2026-02 →
Discuss an engagement
An initial scoping conversation is provided at no charge. Describe the situation in general terms first; use an encrypted channel for anything specific.