Understanding Encryption Export Controls
Encryption software is subject to export controls under the US Export Administration Regulations (EAR, 15 CFR §§ 730-774) administered by the Bureau of Industry and Security (BIS). The Wassenaar Arrangement (42 participating states) also establishes international controls on dual-use cryptographic goods.
However, not all encryption software requires an export license. The EAR contains important exceptions for publicly available software and certain categories of cryptographic functionality.
ZeyroVault's source code is not publicly available, so ZeyroVault does not rely on the 'publicly available' exclusion under the EAR (15 CFR § 734.3(b)(3) and § 742.15(b)(1)). Instead, the relevant considerations are the client-side nature of the tools, their use of standard algorithms through the browser's Web Crypto API, and the origin-based scope of the EAR (15 CFR Part 734).
EAR Classification: ECCN 5D002
Under the Commerce Control List (CCL), encryption software is generally classified under ECCN 5D002 (Information Security software). This classification requires an export license unless a License Exception applies or the software is not subject to the EAR (for example, publicly available encryption software).
For encryption software generally, two mechanisms are commonly discussed: the exclusion for publicly available software (15 CFR § 734.3(b)(3) and § 734.7) and License Exception ENC for mass-market software (15 CFR § 740.17). ZeyroVault does not rely on the publicly available exclusion because its source code is not publicly available:
- Publicly available exclusion (15 CFR § 734.3(b)(3) and § 734.7): Publicly available encryption source code is not subject to the EAR. This exclusion requires the source code to be genuinely available to the public; it does not apply to ZeyroVault because its source code is not publicly available.
- License Exception ENC (15 CFR § 740.17): Mass-market encryption software that meets the criteria in Note 3 to Category 5 Part 2 may be exported under License Exception ENC after self-classification (or a BIS classification where required).
Export Considerations for ZeyroVault's Client-Side Tools
ZeyroVault's encryption tools operate entirely within the user's browser using the Web Crypto API (SubtleCrypto). The main export-control considerations are:
1. No Reliance on Public Availability - ZeyroVault's source code is not publicly available, so the 'publicly available' exclusion (15 CFR § 734.3(b)(3)) does not apply. The position instead rests on the factors below.
2. No Proprietary Cryptography - ZeyroVault does not implement, distribute, or transmit proprietary cryptographic algorithms. All cryptographic operations use the browser's built-in Web Crypto API, which is part of the standard browser platform. The cryptographic implementation is provided by the browser platform itself, not by ZeyroVault.
BIS Note on Publicly Available Code: Under BIS guidance, an item is not considered publicly available merely because it incorporates or calls publicly available open-source code (such as the browser's Web Crypto API); the item as a whole is assessed separately. ZeyroVault's tools are therefore evaluated as a whole under the factors above, not as publicly available encryption software.
3. Client-Side Architecture - No encryption software is downloaded to or executed on ZeyroVault servers. No cryptographic keys leave the user's device. The user's browser performs all operations locally using its existing cryptographic capabilities.
4. Standard Cryptography - ZeyroVault uses only standard, publicly documented algorithms (AES-GCM, SHA-256/384/512, HMAC-SHA256, PBKDF2). The BIS notification mechanism in 15 CFR § 742.15(b)(2) applies only to publicly available encryption source code that provides or performs 'non-standard cryptography' as defined in 15 CFR § 772.1; it does not apply to ZeyroVault because the source code is not publicly available. ZeyroVault's tools are not designed to perform non-standard cryptography.
5. Origin-Based Scope - The EAR is origin-based (15 CFR Part 734): it applies to items located in the United States, US-origin items, and foreign-made items that incorporate more than a de minimis amount of controlled US-origin content or are produced from US-origin technology in certain circumstances. Software developed and operated outside the United States by a non-US person without controlled US-origin content is generally outside the scope of the EAR. Deployers should evaluate these factors for their own distribution and consult export control counsel.
Browser-Based Cryptography: Technical Details
ZeyroVault uses the following Web Crypto API interfaces, all of which are part of the standard browser platform and NOT proprietary encryption software:
- window.crypto.subtle.encrypt/decrypt (AES-GCM, AES-CBC) for symmetric encryption
- window.crypto.subtle.digest (SHA-256, SHA-384, SHA-512) for cryptographic hashing
- window.crypto.subtle.importKey/generateKey (HMAC-SHA256) for message authentication codes
- window.crypto.subtle.sign/verify (HMAC) for digital signatures
- window.crypto.subtle.deriveKey (PBKDF2) for key derivation
- window.crypto.subtle.exportKey for key export (JWT signing)
All cryptographic algorithms used are standard (AES, SHA, HMAC, PBKDF2) and are implemented by the browser platform rather than by ZeyroVault. ZeyroVault's code contains no cryptographic algorithm implementations — only API calls to standard browser interfaces.
Self-Classification and Reporting
Under 15 CFR § 740.17(b)(1) and Supplement No. 6 to Part 742, an exporter may self-classify mass-market encryption software and use License Exception ENC where applicable. The 'publicly available' exclusion (15 CFR § 742.15(b)(1)) does not apply to ZeyroVault because its source code is not publicly available.
ZeyroVault's tools rely on standard browser Web Crypto APIs rather than proprietary cryptographic implementations. Organizations deploying or redistributing the tools should evaluate classification for their own deployment. We recommend:
- Classify Your Deployment: Determine the ECCN for your own build — generally 5D002, or 5D992.c if it meets the mass-market criteria in Note 3 to Category 5 Part 2 — and apply the applicable License Exception (15 CFR § 740.17(b)).
- Document Architecture: Maintain documentation showing that all cryptographic operations use standard browser Web Crypto API, not proprietary implementations.
- Reassess If the Source Becomes Public: If the source code is published in the future, the publicly available exclusion (15 CFR § 742.15(b)(1)) and, for non-standard cryptography, the BIS notification (15 CFR § 742.15(b)(2)) may become relevant. Until then, neither applies to ZeyroVault.
- Consult Counsel: For commercial redistribution, consult with export control counsel to confirm classification.
EU and International Encryption Controls
Beyond US law, encryption exports are regulated internationally under the Wassenaar Arrangement (42 participating states) and EU Dual-Use Regulation (EU 2021/821):
- General Software Note (GSN), Annex I: The GSN decontrols software that is generally available to the public or in the public domain, but it explicitly does not apply to Category 5 Part 2 (Information Security). Encryption software is therefore assessed under the Cryptography Note below.
- Cryptography Note (Note 3 to Category 5 Part 2): Mass-market encryption software that is generally available to the public and whose cryptographic functionality cannot easily be changed by the user is generally not controlled. Client-side Web Crypto API usage through a standard browser supports this assessment.
- Germany (BAFA): The German Federal Office for Economic Affairs and Export Control (BAFA) administers encryption export controls. Publicly available open-source software using standard cryptographic libraries is generally not subject to export licensing.
- UK (ECJU): The Export Control Joint Unit (ECJU) follows EU-style dual-use controls. Publicly available software is exempt from licensing requirements under UK export control regulations.
User Responsibilities
ZeyroVault provides client-side tools, but users should be aware of their own obligations:
- Sanctioned Destinations: Exports or reexports to countries and regions subject to comprehensive US sanctions (currently including Cuba, Iran, North Korea, Syria, Russia, Belarus, and the Crimea, Donetsk, Luhansk, Kherson, and Zaporizhzhia regions of Ukraine) may require authorization or may be prohibited.
- US Law Does Not Prohibit Use Abroad: US export controls apply to exports, reexports, and transfers of controlled items — not to the mere use of encryption within another country. Most users worldwide can lawfully use standard encryption without US authorization.
- Denied Parties: Users must not export to individuals or entities on BIS's Denied Persons List, Entity List, or Unverified List.
- End-Use Restrictions: Encryption software may not be exported for use in proliferation of weapons of mass destruction (WMD) or other prohibited end-uses.
- Local Laws: Users are responsible for complying with encryption regulations in their own jurisdiction, which may differ from US law. Some jurisdictions regulate the import, use, or provision of commercial cryptography (for example, China's Cryptography Law and the Commercial Cryptography Regulations); users should confirm their local obligations.
These restrictions concern exports and end-uses; they do not prohibit users from using standard encryption within their own country. ZeyroVault does not restrict access based on geography, but users must ensure their use complies with applicable laws.
Frequently Asked Questions
Does ZeyroVault need an export license for encryption tools?
ZeyroVault's source code is not publicly available, so the 'publicly available' exclusion does not apply. ZeyroVault's tools run entirely in the user's browser, use only standard algorithms through the Web Crypto API, and are not sold or distributed as standalone encryption products. Whether US export controls apply to a particular export depends on facts such as the item's origin and US-content (15 CFR Part 734); software developed and operated outside the United States by a non-US person without controlled US-origin content is generally outside the scope of the EAR. Consult export control counsel for your specific situation.
How should I classify ZeyroVault if I redistribute it?
If you deploy or redistribute ZeyroVault's tools commercially, evaluate the classification of your own build. Mass-market encryption software that meets the criteria in Note 3 to Category 5 Part 2 may be classified as 5D992.c and exported under License Exception ENC (15 CFR § 740.17(b)(1)); other builds are generally classified as ECCN 5D002. Maintain documentation showing that all cryptographic operations use the standard Web Crypto API. Consult export control counsel for your specific deployment.
Why does using Web Crypto API matter for export compliance?
The Web Crypto API is part of the standard browser platform, implemented by the browser itself (Google Chrome, Mozilla Firefox, Apple Safari, Microsoft Edge). ZeyroVault's code does not contain cryptographic algorithm implementations — it calls standard browser APIs. This means: (1) ZeyroVault is not exporting proprietary encryption software; (2) The cryptographic implementation is provided by the browser platform itself, not by ZeyroVault; (3) The user's browser already has encryption capabilities before visiting ZeyroVault. This architectural choice is central to the design of our tools.
Can users outside the US access ZeyroVault encryption tools?
Yes. The tools are designed to be accessible worldwide, and US export controls do not prohibit users in other countries from using standard encryption. ZeyroVault does not rely on the publicly available exclusion; its position is based on the client-side, standard-cryptography design and the origin-based scope of the EAR. All cryptographic operations run locally in the user's browser. Users remain responsible for complying with their own local encryption regulations.
Is ZeyroVault open source?
No. ZeyroVault's source code is not currently publicly available, and ZeyroVault does not claim to be open source. Because the source code is private, the 'publicly available' exclusion under 15 CFR § 734.3(b)(3) does not apply to ZeyroVault. You can still verify the client-side behavior of the tools in your browser (for example, using the Network tab or testing offline).
Does US law prohibit the use of encryption by users in other countries?
No. US export controls under the EAR apply to exports, reexports, and transfers of controlled encryption items — they do not prohibit the use of encryption within another country. Most users worldwide can lawfully use standard encryption (such as AES or TLS) without any US authorization. The practical limits concern exports: shipments or downloads to comprehensively sanctioned destinations (currently including Cuba, Iran, North Korea, Syria, Russia, Belarus, and the Crimea, Donetsk, Luhansk, Kherson, and Zaporizhzhia regions of Ukraine), transfers to denied or listed parties, and prohibited end-uses (for example, WMD proliferation). Users should also check their own country's rules, which may regulate the import or use of cryptography independently of US law.
References
This guide is based on official US export regulations and international frameworks. It was last reviewed on August 13, 2026; regulations change, so verify details against the official texts linked below.
- Bureau of Industry and Security (BIS) - Export Administration Regulations
- EAR Part 734 - Scope of the EAR (Publicly Available, § 734.3(b)(3))
- EAR § 742.15 - Encryption items (publicly available source code and non-standard cryptography notification)
- ENC License Exception (15 CFR § 740.17)
- BIS - Encryption items not subject to the EAR
- Wassenaar Arrangement - Dual-Use List
- EU Dual-Use Regulation 2021/821
Legal Notice and Accuracy of Cited Provisions
The information on this page is provided for general information only and does not constitute legal advice. Laws, regulations, and administrative interpretations change over time, and the provisions referenced above are summaries of the underlying rules. The authoritative text is the official version published by the relevant authority (for example, the U.S. eCFR and BIS, EUR-Lex, or the official gazettes of other jurisdictions). ZeyroVault reviewed this page on August 13, 2026 and intends to review it periodically, but cannot guarantee that it reflects the latest rules when you read it. Consult a qualified professional for your specific situation.