Esta página ainda não está disponível em português e é apresentada em inglês. Páginas disponíveis em português
For the companies that defend networks. Stated plainly, including who this is not for.
A security vendor's diligence file is read with its own trade in mind. Customers pass their network-security obligations down as contract terms, export regimes draw their lines at what a tool does and what its maker knows, and investors ask for the line-of-business record that shows which side of those lines the company works on. A sovereign deployment produces that record inside the vendor's own perimeter, as the work happens.
The review is conducted under mutual NDA, with the vendor's security and technical leads in the room. Nothing is uploaded and nothing is trialled.
Obligations that flow down, and controls that turn on knowledge.
Each entry is a published rule with its primary source. Whether a given product, transfer or customer falls under any of them is a question for the vendor and its counsel, never for a platform.
Showing rules for European Union
The argument on this page does not change with the selection. The citations do.
Every jurisdiction is shown below, grouped and labelled.
European Union
- Export control
Europe reaches unlisted cyber-surveillance items on end-use grounds. Exporting a cyber-surveillance item on no list still requires authorisation where the competent authority so informs the exporter, and an exporter aware through its own due diligence that such an item is intended for internal repression or serious violations of human rights or international humanitarian law must notify the authority. A due-diligence duty is a documentation duty: findings, dates, decisions.
- Export control
The Commission published guidelines for exporters on exactly this duty. The Commission published guidelines for exporters on exactly that duty, on 11 October 2024.
- Network security
Security providers are themselves in the network rules. Managed service providers and managed security service providers are themselves among the sectors of high criticality of the network-security directive. The obligations of every regulated customer arrive at the vendor as flow-down questionnaires, contract terms and evidence requests, answered from the vendor’s own records, repeatedly.
United States
- Export control
The export exception is written for defenders and withdrawn at knowledge. The United States authorises exports of cybersecurity items under a dedicated licence exception whose availability ends where the exporter knows, or has reason to know, that the item will be used to affect the confidentiality, integrity or availability of information or information systems without authorisation from the system’s owner, operator or administrator. The regime draws the defensive line at what the maker knows; what a vendor knew and documented becomes the operative fact.
Ledger entries are published in English only, and cite each instrument by its own official name.
The vendor's conduct record, kept on the vendor's own terms.
A security company holds itself to in-perimeter standards; its compliance rail should meet them. On a sovereign deployment the raise, the customer diligence and the export due-diligence file run on infrastructure the vendor controls. Product documentation and research material sit behind a narrower door than the deck, with jurisdiction gating and per-person, per-document access under the vendor's own rules, and every grant, access and resolution becomes a dated, signed entry as it happens. What the vendor knew, checked and decided about a customer or a transfer, and when, is answerable from a record made at the time, which is precisely the fact the knowledge-shaped regimes turn on.
The perimeter claim is made per configuration: with identity verification, screening and mail in the vendor's own mode, no document, key or event leaves the perimeter in normal operation; in the connected timestamping postures, the one egress is a SHA-256 fingerprint sent for independent timestamping. The vendor's security team approves every update before it lands.
The line is drawn here, on the page.
This page addresses companies whose business is defending information systems: detection and response, managed security, vulnerability research conducted under disclosure norms, and the vendors that build for them. It does not address, and Exedra Gate does not offer sovereign deployments to, businesses dealing in zero-day exploits, offensive-cyber services, surveillance-for-hire or intelligence services built on operating where oversight is thin. The product's entire premise is verifiable evidence; demand driven by opacity is demand for the opposite product, and it is declined.
Stated before anyone asks.
- NO LICENCE
No export-control conclusion, ever. The platform classifies no item, determines no licence or notification requirement, and its access records are evidence of conduct, not an authorisation. Whether an exception applies to a transfer remains the exporter's determination with counsel and the competent authority.
- NOT A SHIELD
No security outcome for anyone's product. The platform keeps the vendor's compliance and diligence record; it hardens no product, certifies no practice and makes no one, vendor or customer, secure. Claims about the vendor's own product remain the vendor's to make and to prove.
- NO COVER
A record is not a defence in itself. A dated due-diligence trail shows what was known and decided, which helps exactly as far as the conduct it records was sound. It launders nothing, and it is not offered as protection against the consequences of a bad decision it faithfully documents.
The questionnaire returns every year. The answers should not be rebuilt.
An architectural review with the vendor's security and technical leads, under mutual NDA, covers the deployment shapes, the switchboard and its claim consequences, and what an engagement would scope for the vendor's raise, diligence and due-diligence files. A short note on the business and its jurisdictions is enough to begin.
Exedra Gate is a technology platform, not a broker, dealer, custodian, escrow provider, or investment adviser. It never holds, routes, or settles investor funds, does not recommend offerings to investors, and charges no success-based fees. It does not classify items under any export-control list, does not determine whether a licence, exception or notification applies, and provides no security outcome for any product. Sovereign deployments are offered to defensive-security businesses as described above and not to dealers in exploits, offensive-cyber or surveillance services. A sovereign deployment is an implementation engagement, scoped per client. Records and timestamps attest integrity and existence as of a date, not the lawfulness of any export or transaction; that judgment remains with the vendor and its counsel.
Regulatory references on this page are orientation, not legal advice: see Sources & verification.