Questa pagina non è ancora disponibile in italiano ed è mostrata in inglese. Pagine disponibili in italiano

SOVEREIGN DEPLOYMENTS · DEFENSIVE CYBER SECURITY

For the companies that defend networks. Stated plainly, including who this is not for.

A security vendor's diligence file is read with its own trade in mind. Customers pass their network-security obligations down as contract terms, export regimes draw their lines at what a tool does and what its maker knows, and investors ask for the line-of-business record that shows which side of those lines the company works on. A sovereign deployment produces that record inside the vendor's own perimeter, as the work happens.

The review is conducted under mutual NDA, with the vendor's security and technical leads in the room. Nothing is uploaded and nothing is trialled.

THE SECTOR AS THE LAW MEETS IT

Obligations that flow down, and controls that turn on knowledge.

Each entry is a published rule with its primary source. Whether a given product, transfer or customer falls under any of them is a question for the vendor and its counsel, never for a platform.

Jurisdiction

Showing rules for European Union

The argument on this page does not change with the selection. The citations do.

Every jurisdiction is shown below, grouped and labelled.

European Union

  • Export control

    Europe reaches unlisted cyber-surveillance items on end-use grounds. Exporting a cyber-surveillance item on no list still requires authorisation where the competent authority so informs the exporter, and an exporter aware through its own due diligence that such an item is intended for internal repression or serious violations of human rights or international humanitarian law must notify the authority. A due-diligence duty is a documentation duty: findings, dates, decisions.

    Regulation (EU) 2021/821, Art. 5

    Source checked

  • Export control

    The Commission published guidelines for exporters on exactly this duty. The Commission published guidelines for exporters on exactly that duty, on 11 October 2024.

    Recommendation (EU) 2024/2659

    Source checked

  • Network security

    Security providers are themselves in the network rules. Managed service providers and managed security service providers are themselves among the sectors of high criticality of the network-security directive. The obligations of every regulated customer arrive at the vendor as flow-down questionnaires, contract terms and evidence requests, answered from the vendor’s own records, repeatedly.

    Directive (EU) 2022/2555, Annex I, sector 9

    Source checked

United States

  • Export control

    The export exception is written for defenders and withdrawn at knowledge. The United States authorises exports of cybersecurity items under a dedicated licence exception whose availability ends where the exporter knows, or has reason to know, that the item will be used to affect the confidentiality, integrity or availability of information or information systems without authorisation from the system’s owner, operator or administrator. The regime draws the defensive line at what the maker knows; what a vendor knew and documented becomes the operative fact.

    EAR, 15 CFR § 740.22

    Source checked

Ledger entries are published in English only, and cite each instrument by its own official name.

WHAT A SOVEREIGN DEPLOYMENT CHANGES

The vendor's conduct record, kept on the vendor's own terms.

A security company holds itself to in-perimeter standards; its compliance rail should meet them. On a sovereign deployment the raise, the customer diligence and the export due-diligence file run on infrastructure the vendor controls. Product documentation and research material sit behind a narrower door than the deck, with jurisdiction gating and per-person, per-document access under the vendor's own rules, and every grant, access and resolution becomes a dated, signed entry as it happens. What the vendor knew, checked and decided about a customer or a transfer, and when, is answerable from a record made at the time, which is precisely the fact the knowledge-shaped regimes turn on.

The perimeter claim is made per configuration: with identity verification, screening and mail in the vendor's own mode, no document, key or event leaves the perimeter in normal operation; in the connected timestamping postures, the one egress is a SHA-256 fingerprint sent for independent timestamping. The vendor's security team approves every update before it lands.

The plausible configuration
For a defensive-security vendor: identity verification client-supplied or hosted, as the investor base allows; screening client-supplied, feeding the vendor's own customer and end-use diligence; mail on vendor infrastructure with the delivery-evidence downgrade stated; timestamping in the default connected posture. Decided per engagement, in writing: the switchboard, with every consequence stated.
WHO THIS IS FOR, AND WHO IT IS NOT FOR

The line is drawn here, on the page.

This page addresses companies whose business is defending information systems: detection and response, managed security, vulnerability research conducted under disclosure norms, and the vendors that build for them. It does not address, and Exedra Gate does not offer sovereign deployments to, businesses dealing in zero-day exploits, offensive-cyber services, surveillance-for-hire or intelligence services built on operating where oversight is thin. The product's entire premise is verifiable evidence; demand driven by opacity is demand for the opposite product, and it is declined.

WHAT EXEDRA GATE DOES NOT SOLVE HERE

Stated before anyone asks.

  • NO LICENCE

    No export-control conclusion, ever. The platform classifies no item, determines no licence or notification requirement, and its access records are evidence of conduct, not an authorisation. Whether an exception applies to a transfer remains the exporter's determination with counsel and the competent authority.

  • NOT A SHIELD

    No security outcome for anyone's product. The platform keeps the vendor's compliance and diligence record; it hardens no product, certifies no practice and makes no one, vendor or customer, secure. Claims about the vendor's own product remain the vendor's to make and to prove.

  • NO COVER

    A record is not a defence in itself. A dated due-diligence trail shows what was known and decided, which helps exactly as far as the conduct it records was sound. It launders nothing, and it is not offered as protection against the consequences of a bad decision it faithfully documents.

THE CLOSE

The questionnaire returns every year. The answers should not be rebuilt.

An architectural review with the vendor's security and technical leads, under mutual NDA, covers the deployment shapes, the switchboard and its claim consequences, and what an engagement would scope for the vendor's raise, diligence and due-diligence files. A short note on the business and its jurisdictions is enough to begin.

Exedra Gate is a technology platform, not a broker, dealer, custodian, escrow provider, or investment adviser. It never holds, routes, or settles investor funds, does not recommend offerings to investors, and charges no success-based fees. It does not classify items under any export-control list, does not determine whether a licence, exception or notification applies, and provides no security outcome for any product. Sovereign deployments are offered to defensive-security businesses as described above and not to dealers in exploits, offensive-cyber or surveillance services. A sovereign deployment is an implementation engagement, scoped per client. Records and timestamps attest integrity and existence as of a date, not the lawfulness of any export or transaction; that judgment remains with the vendor and its counsel.

Regulatory references on this page are orientation, not legal advice: see Sources & verification.