Cloud Services and the EAR
Cloud computing creates unique export control challenges because encrypted data and encryption software may be stored on servers in multiple jurisdictions. The EAR applies to cloud-based encryption software and technology, and the location of servers, the nationality of users, and the accessibility of encryption functionality all factor into the compliance analysis.
BIS has provided guidance clarifying that storing encrypted data on foreign servers does not by itself constitute an export of encryption software if the data remains encrypted and the encryption keys are not accessible from the foreign server.
When Cloud Triggers Export Control
An export occurs when encryption software is made available to foreign persons, whether through cloud access or direct download. If a cloud service provides encryption functionality — not just encrypted storage — the encryption software embedded in the service may require classification and potentially a license or license exception.
SaaS applications with client-side encryption components should classify the client-side software. Server-side encryption infrastructure is typically not 'exported' if it remains under U.S. control, but providing access to the encryption capability to foreign users may constitute a deemed export.
Practical Compliance for Cloud
Cloud service providers should maintain awareness of where their infrastructure is located, who has access to encryption functionality, and whether end-to-end encryption keys are managed by the user or by the provider. Access controls that restrict cloud service availability by geography can help manage export control obligations.
Multi-tenant cloud architectures should evaluate whether providing encryption-as-a-service to foreign customers constitutes an export of encryption items. The analysis depends on the specific service architecture and the degree to which encryption functionality is made available to the end user.