Theme
ECCN and export restrictions
Syncplify is a corporation based in the United States, so the export of its software is governed by the US Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS) of the Department of Commerce, and by the sanctions programs administered by the Office of Foreign Assets Control (OFAC) of the Department of the Treasury. This page answers the questions that compliance teams ask most often.
Classification
Syncplify makes software only, no hardware. Syncplify has self classified all of its products under ECCN 5D002, in Category 5, Part 2 (Information Security) of the Commerce Control List.
ECCN 5D002 covers software that performs, or is designed to perform, the functions of the information security items controlled under ECCN 5A002. In plain terms: software that uses cryptography for data confidentiality with a "described security algorithm", which the regulation defines as a symmetric algorithm with a key length above 56 bits, or an asymmetric algorithm whose security rests on integer factorization above 512 bits (for example RSA), on discrete logarithms in a multiplicative group of a finite field above 512 bits (for example Diffie-Hellman over Z/pZ), or on discrete logarithms in any other group above 112 bits (for example Diffie-Hellman over an elliptic curve). Syncplify software uses exactly this kind of cryptography: TLS and SSH on the wire, and strong encryption at rest.
The authoritative text is the Commerce Control List, Supplement No. 1 to Part 774 of the EAR, published in the Electronic Code of Federal Regulations.
What this means for buying and using Syncplify software
Commercial encryption software classified under ECCN 5D002 is generally exportable from the United States to most destinations under the provisions of the EAR that apply to encryption items (License Exception ENC, section 740.17 of the EAR), and Syncplify sells its software worldwide on that basis. Whether your own reexport or transfer of the software requires anything further depends on your destination, your end users and your end use, and remains your responsibility.
Sanctions screening and embargoed destinations
The Departments of State, Treasury and Commerce maintain lists of sanctioned and restricted parties: companies, organizations and individuals. As a US company, Syncplify screens every export sale against these lists and is prohibited from accepting orders from any listed party.
Syncplify is also prohibited from exporting its products to destinations under a comprehensive US embargo. As of the date of this page these are Cuba, Iran, North Korea, and the Crimea, so called Donetsk People's Republic and so called Luhansk People's Republic regions of Ukraine. Russia and Belarus are subject to extensive US export restrictions that, in practice, prevent the sale of encryption software to them.
These lists change. The authoritative sources are OFAC's sanctions programs and country information and BIS's Country Groups in Supplement No. 1 to Part 740 of the EAR.
Questions
For further questions about export restrictions, customers can open a support request from the Syncplify Customer Center; anyone can write to support@syncplify.com.