Export compliance. Classified, screened, and cleared to ship worldwide.
Caver is classified under the U.S. Export Administration Regulations and exports under License Exception ENC by self-classification. In practice: any organization outside a U.S.-embargoed destination can evaluate and run Caver today, with no export-license paperwork between you and your deployment.
Commerce Control List Category 5, Part 2 (information security software).
15 CFR 740.17(b)(1), by self-classification under the U.S. Export Administration Regulations.
Caver is commercial security software with no defense-article nexus. EAR jurisdiction only.
AES-256-GCM for stored secrets, TLS for data in transit. No proprietary or non-standard algorithms, no cryptanalytic capability.
Caver may be exported and reexported to organizations in any destination not embargoed by the United States, with no individual export license and no approval delay.
Caver monitors and analyzes. It contains no intrusion, exploitation, or command-and-control capability, and is not subject to the EAR cybersecurity-items (intrusion software) controls.
Every order and evaluation request is screened against the U.S. consolidated denied-party lists (Treasury, Commerce, State) before delivery.
Caver is not exported to destinations embargoed or comprehensively sanctioned by the United States, or to parties on U.S. government restricted lists. Some countries regulate the import or local use of encryption independently of U.S. law; check your local rules. This page is a statement of RedEye Security's classification under the EAR, made by self-classification per 15 CFR 740.17(b)(1); it is provided for information and is not legal advice. Export questions: [email protected].