User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.
MCM-67 — Export Control Classification Review
ECCN (or equivalent) classification covering cryptographic and AI components, reviewed per release.
MCM-67 — Export Control Classification Review
← Back to Legal & Compliance Readiness overview
As Legal Counsel,
I want an export control classification completed for the platform, including any cryptographic or AI components,
so that MCM can be sold internationally without violating export control regimes such as the EAR or ITAR.
Acceptance Criteria
- An Export Control Classification Number determination (or equivalent under applicable regimes) is completed for the platform, covering any cryptographic functionality and the AI assistant's components.
- Restricted-destination and denied-party screening is incorporated into the sales/contracting process before a deal is signed with a customer or reseller outside the home jurisdiction.
- Any third-party component — open-source or licensed — carrying its own export restriction is identified via the SBOM review (see MCM-62) and reconciled with the platform's overall classification.
- The classification is re-reviewed whenever a materially new capability is added — new cryptographic functionality, or a new AI capability — rather than treated as a one-time determination.
- Sales/Deal Desk has a documented checklist to flag deals requiring export review before contracting proceeds.
Technical Design
The classification review draws on the same dependency inventory produced for the SBOM to catch any component carrying its own export restriction, and is retriggered whenever a release adds cryptographic or AI functionality that could change the platform's own classification.