Skip to content Skip to footer

ITAR Compliance

ITAR compliance requires more than encryption. It requires unilateral control over decryption.

Picture of GuardWare
GuardWare

International Traffic in Arms Regulations (ITAR), codified at 22 CFR Parts 120-130, govern the handling, storage, access, and transfer of defence-related technical data. For Australian, UK, Canadian, and European organisations participating in US defence programmes, ITAR applies to controlled technical data regardless of where the organisation is located. 

The central ITAR challenge for organisations operating in cloud environments is structural: who controls decryption? Even where customer-controlled keys are used, most enterprise encryption architectures leave the cloud provider as a mandatory participant in decryption operations. Under 22 CFR Part 120, this structural dependency, regardless of whether it is ever exercised, is the problem ITAR-governed organisations must eliminate. 

GuardWare PROTECT was designed specifically to resolve this. It separates cryptography, identity, and policy into independently governed layers, enabling organisations to leverage Microsoft Azure for identity and collaboration while ensuring decryption authority remains entirely under their control. 

The challenge 

Most cloud encryption architectures fail ITAR’s structural requirement for independent decryption control. 

Traditional cloud-managed encryption, including Azure Key Vault, Microsoft Information Protection, Bring Your Own Key, and customer-managed keys, continues to rely on cloud-provider infrastructure for decryption operations. This creates a structural dependency that is incompatible with strict ITAR sovereignty requirements. 

The issue is not whether Microsoft is a trusted partner. The issue is that Microsoft remains structurally capable of influencing decryption, which ITAR does not permit. 

How GuardWare solves it 

PROTECT implements a decoupled architecture that separates cryptography, identity, and policy into independently governed layers. Four operating modes address progressively stringent sovereignty requirements.

The Outcome 
  • Decryption authority held unilaterally by your organisation with no cloud provider dependency 
  • Hardware-bound decryption via TPM for air-gapped and hybrid environments 
  • Real-time policy enforcement including geographic restrictions aligned with 22 CFR Part 125 
  • Remote key revocation for any protected file at any time 
  • Multi-organisation governance for defence supply chains and joint ventures 
  • Supports Microsoft Azure, Azure Virtual Desktop, AWS, Google Cloud, private cloud, and on-premises environments 
How it works
Online Mode

provides cloud-managed encryption for standard deployments.

Offline Mode

moves decryption into hardware the organisation physically controls, with no ongoing dependency on Microsoft. Once provisioned, decryption occurs within the device's Trusted Platform Module. Microsoft infrastructure is not required.

ITAR Mode

adds a real-time independent policy layer that enables revocation, geographic restriction, and contextual enforcement beyond what cloud identity alone provides. The GuardWare Policy Server performs a second independent private-key operation. Both must succeed for decryption to complete. Neither layer alone is sufficient.

Oversight Mode

extends this to multi-organisation defence partnerships where two or more organisations must each approve decryption independently.

ITAR Mode compliance alignment 

PROTECT’s Offline, ITAR, and Oversight modes address the structural requirement of 22 CFR Parts 120-130 for independent organisational control of decryption. ITAR Mode’s geographic enforcement supports the access conditions that export licences impose under 22 CFR Part 125. Oversight Mode’s multi-party governance supports joint-venture accountability requirements under ITAR’s shared-responsibility framework. 

PROTECT also supports CMMC 2.0 Level 2 and Level 3, NIST SP 800-171, DISP, and ISO 27001 requirements. 

Common Questions

ITAR (International Traffic in Arms Regulations) is a US regulatory framework codified at 22 CFR Parts 120-130 that governs the handling, storage, access, and transfer of defence-related technical data. Organisations participating in US defence programmes, including those in Australia, the UK, Canada, and Europe, are subject to ITAR requirements when handling controlled technical data. Non-compliance carries civil penalties, criminal prosecution, and debarment from US defence contracts.

Standard cloud encryption does not satisfy ITAR's structural requirement for independent organisational control of decryption. Even with customer-managed keys, BYOK provisions, or HSM-backed key storage, most architectures leave the cloud provider as a mandatory participant in decryption operations. ITAR requires that the data-owning organisation holds unilateral decryption authority. GuardWare PROTECT achieves this through a decoupled architecture where decryption occurs in hardware the organisation physically controls.

Yes, with GuardWare PROTECT. PROTECT makes Microsoft Azure ITAR-capable by separating decryption authority from Azure Key Vault. Organisations retain all the operational benefits of Microsoft 365 and Azure Virtual Desktop while ensuring decryption authority over controlled data remains entirely under their own control.

ITAR Mode is the highest-assurance single-organisation configuration in GuardWare PROTECT. It adds a real-time independent policy layer operated by a GuardWare Policy Server under the organisation's control. Decryption requires both a TPM-bound hardware operation on the end-user device and a second independent operation by the Policy Server. Neither layer alone is sufficient. Microsoft is not a decryption participant.

Oversight Mode extends ITAR Mode for defence supply chains and joint ventures where two or more independent organisations must each approve decryption. No single organisation can unilaterally decrypt files protected under this mode. Each participating organisation operates its own Policy Server with its own independent key pair.

Yes. PROTECT Offline Mode and ITAR Mode support air-gapped deployments. Once a device is provisioned with the relevant security-group keys via the TPM, decryption does not require network connectivity. PROTECT is designed for defence laboratories, submarines, aircraft deployments, remote engineering teams, and other environments with intermittent or no connectivity.

Yes. GuardWare PROTECT provides a technical architectural solution to ITAR's sovereignty requirements. It does not constitute legal advice. Organisations subject to ITAR should engage qualified ITAR counsel to confirm their specific compliance obligations before deployment.

Webinar

The Insider Threat You Can't Fire: Cybersecurity in Education.

Jun 24, 2026 12:00PM AEST