ITAR Compliance
ITAR compliance requires more than encryption. It requires unilateral control over decryption.
International Traffic in Arms Regulations (ITAR), codified at 22 CFR Parts 120-130, govern the handling, storage, access, and transfer of defence-related technical data. For Australian, UK, Canadian, and European organisations participating in US defence programmes, ITAR applies to controlled technical data regardless of where the organisation is located.
The central ITAR challenge for organisations operating in cloud environments is structural: who controls decryption? Even where customer-controlled keys are used, most enterprise encryption architectures leave the cloud provider as a mandatory participant in decryption operations. Under 22 CFR Part 120, this structural dependency, regardless of whether it is ever exercised, is the problem ITAR-governed organisations must eliminate.
GuardWare PROTECT was designed specifically to resolve this. It separates cryptography, identity, and policy into independently governed layers, enabling organisations to leverage Microsoft Azure for identity and collaboration while ensuring decryption authority remains entirely under their control.
The challenge
Most cloud encryption architectures fail ITAR’s structural requirement for independent decryption control.
Traditional cloud-managed encryption, including Azure Key Vault, Microsoft Information Protection, Bring Your Own Key, and customer-managed keys, continues to rely on cloud-provider infrastructure for decryption operations. This creates a structural dependency that is incompatible with strict ITAR sovereignty requirements.
The issue is not whether Microsoft is a trusted partner. The issue is that Microsoft remains structurally capable of influencing decryption, which ITAR does not permit.
How GuardWare solves it
PROTECT implements a decoupled architecture that separates cryptography, identity, and policy into independently governed layers. Four operating modes address progressively stringent sovereignty requirements.
The Outcome
- Decryption authority held unilaterally by your organisation with no cloud provider dependency
- Hardware-bound decryption via TPM for air-gapped and hybrid environments
- Real-time policy enforcement including geographic restrictions aligned with 22 CFR Part 125
- Remote key revocation for any protected file at any time
- Multi-organisation governance for defence supply chains and joint ventures
- Supports Microsoft Azure, Azure Virtual Desktop, AWS, Google Cloud, private cloud, and on-premises environments
How it works
Online Mode
provides cloud-managed encryption for standard deployments.
Offline Mode
moves decryption into hardware the organisation physically controls, with no ongoing dependency on Microsoft. Once provisioned, decryption occurs within the device's Trusted Platform Module. Microsoft infrastructure is not required.
ITAR Mode
adds a real-time independent policy layer that enables revocation, geographic restriction, and contextual enforcement beyond what cloud identity alone provides. The GuardWare Policy Server performs a second independent private-key operation. Both must succeed for decryption to complete. Neither layer alone is sufficient.
Oversight Mode
extends this to multi-organisation defence partnerships where two or more organisations must each approve decryption independently.
ITAR Mode compliance alignment
PROTECT’s Offline, ITAR, and Oversight modes address the structural requirement of 22 CFR Parts 120-130 for independent organisational control of decryption. ITAR Mode’s geographic enforcement supports the access conditions that export licences impose under 22 CFR Part 125. Oversight Mode’s multi-party governance supports joint-venture accountability requirements under ITAR’s shared-responsibility framework.
PROTECT also supports CMMC 2.0 Level 2 and Level 3, NIST SP 800-171, DISP, and ISO 27001 requirements.
Common Questions
What is ITAR compliance?
ITAR (International Traffic in Arms Regulations) is a US regulatory framework codified at 22 CFR Parts 120-130 that governs the handling, storage, access, and transfer of defence-related technical data. Organisations participating in US defence programmes, including those in Australia, the UK, Canada, and Europe, are subject to ITAR requirements when handling controlled technical data. Non-compliance carries civil penalties, criminal prosecution, and debarment from US defence contracts.
Does cloud encryption satisfy ITAR requirements?
Standard cloud encryption does not satisfy ITAR's structural requirement for independent organisational control of decryption. Even with customer-managed keys, BYOK provisions, or HSM-backed key storage, most architectures leave the cloud provider as a mandatory participant in decryption operations. ITAR requires that the data-owning organisation holds unilateral decryption authority. GuardWare PROTECT achieves this through a decoupled architecture where decryption occurs in hardware the organisation physically controls.
Can organisations use Microsoft Azure and remain ITAR compliant?
Yes, with GuardWare PROTECT. PROTECT makes Microsoft Azure ITAR-capable by separating decryption authority from Azure Key Vault. Organisations retain all the operational benefits of Microsoft 365 and Azure Virtual Desktop while ensuring decryption authority over controlled data remains entirely under their own control.
What is PROTECT ITAR Mode?
ITAR Mode is the highest-assurance single-organisation configuration in GuardWare PROTECT. It adds a real-time independent policy layer operated by a GuardWare Policy Server under the organisation's control. Decryption requires both a TPM-bound hardware operation on the end-user device and a second independent operation by the Policy Server. Neither layer alone is sufficient. Microsoft is not a decryption participant.
What is PROTECT Oversight Mode?
Oversight Mode extends ITAR Mode for defence supply chains and joint ventures where two or more independent organisations must each approve decryption. No single organisation can unilaterally decrypt files protected under this mode. Each participating organisation operates its own Policy Server with its own independent key pair.
Does GuardWare PROTECT support air-gapped environments?
Yes. PROTECT Offline Mode and ITAR Mode support air-gapped deployments. Once a device is provisioned with the relevant security-group keys via the TPM, decryption does not require network connectivity. PROTECT is designed for defence laboratories, submarines, aircraft deployments, remote engineering teams, and other environments with intermittent or no connectivity.
Should organisations seek legal advice on ITAR compliance?
Yes. GuardWare PROTECT provides a technical architectural solution to ITAR's sovereignty requirements. It does not constitute legal advice. Organisations subject to ITAR should engage qualified ITAR counsel to confirm their specific compliance obligations before deployment.
Related Use Cases
Do you know where your sensitive data is?
Stop your IP and Design files from being stolen?
Stopping your confidential files from being stolen?
How are you measuring your AI risk today?
How to Protect Data Even After a Breach or Theft
ITAR Compliance and Sovereign Data Encryption
Protecting IP During Tenders and Procurement Processes
Securing Construction Drawings and Project Files
Securing Engineering Files and CAD Data
Sensitive Data Discovery and Classification


