Export Control, Data Handling, and Automated Conformance Assessment

This page explains how documents are handled by the platform, how automated analysis features work, and the responsibilities of users when uploading and analyzing technical documents.

Enterprise-Grade Security Certifications

Our platform infrastructure is built with enterprise-grade security and maintains the following certifications:

SOC 2 Type II Certification

SOC 2 (Service Organization Control 2) Type II certification demonstrates that our platform meets rigorous standards for security, availability, processing integrity, confidentiality, and privacy. This certification is audited by independent third parties and ensures that appropriate controls are in place to protect customer data.

ISO 27001 Certification

ISO 27001 is the international standard for information security management systems (ISMS). This certification validates that our platform implements comprehensive security controls, risk management processes, and continuous improvement practices to protect sensitive information.

What this means for you: Your data is stored and processed using industry-leading security standards with encryption at rest and in transit, regular security audits, and comprehensive access controls.

These certifications relate to information security controls and do not by themselves determine regulatory or export-control compliance for user-provided content.

Purpose of the Automated Assessment Tool

This platform provides automated, AI-assisted analysis to support preliminary, internal self-assessment of user-provided documents against selected checklist criteria derived from Nadcap AC7114.

The tool is intended to:

  • Assist experienced professionals with internal preparation
  • Identify potential gaps or areas requiring further review
  • Support internal quality and readiness efforts

This tool does not replace professional judgment, official audits, or regulatory certification.

Important Limitations

The automated analysis provided by this platform:

  • Is preliminary and non-authoritative
  • Does not grant approval, certification, or accreditation
  • Does not replace official Nadcap audits, checklists, or auditor determinations
  • May be incomplete, inaccurate, or based on assumptions

Any PASS / FAIL or similar output is provided for guidance only and must not be relied upon as a final determination of compliance.

You remain fully responsible for all decisions made based on use of this tool.

PASS / FAIL Output – Scope and Limitations

PASS / FAIL results represent an automated interpretation of uploaded content against selected checklist elements using probabilistic AI analysis.

By using this feature, you acknowledge that:

  • PASS / FAIL outputs are indicative only, not authoritative determinations
  • Results may not capture all requirements or contextual factors
  • Final compliance determinations require independent professional judgment and official Nadcap review
  • Any reliance on the output of this tool is at your sole discretion and risk
Platform Role and Limitations

The platform functions as a user-directed, automated analysis service.

The platform does not:

  • Provide certification, accreditation, or official compliance determinations
  • Perform human audits or professional reviews
  • Assume responsibility for regulatory or contractual compliance decisions
  • Represent itself as an authorization or approval under ITAR, EAR, or Nadcap

Users retain full ownership and responsibility for all uploaded content.

Intended Use

This tool is designed to support internal review and preparation by qualified professionals.

It must not be:

  • Represented to customers, auditors, or regulators as an official conformance determination
  • Used as a substitute for required audits or certifications
  • Relied upon as the sole basis for regulatory or contractual decisions
Agreement to These Terms

By using this platform and its automated analysis features, you acknowledge that you have read and understood this notice and agree to use the tool in accordance with the limitations and responsibilities described above.

What This Means?

How Your Documents Move Through the Platform

Data Lifecycle Overview

To provide clarity and transparency, the platform handles documents in two different ways depending on how they are used.

1️⃣ Automated Conformance Analysis (Temporary Processing)

When you upload a document for AI-assisted conformance assessment (e.g., checklist alignment review):

Step 1 – Upload

Your document is securely transmitted using encrypted connections.

Step 2 – Temporary Encrypted Storage

The document is temporarily stored in encrypted cloud storage solely for automated processing.

Step 3 – Automated Analysis

The document is analyzed by automated systems to generate a preliminary assessment (such as PASS / FAIL or gap identification).

  • No human review occurs
  • Content is not used for AI model training
  • Content is not shared or benchmarked

Step 4 – Automatic Deletion

When analysis is complete or your session ends:

  • The uploaded document is automatically deleted
  • The analysis output is not permanently retained

This process is designed to support transient analysis only.

2️⃣ Document Storage Features (Intentional Retention)

In other areas of the platform, users may upload and store documents (such as personnel records or internal documents).

Step 1 – Upload

Documents are securely transmitted using encrypted connections.

Step 2 – Encrypted Storage

Documents are stored in encrypted cloud storage.

Step 3 – Access Control

Access is controlled by your organization's user permissions and account settings.

Step 4 – Retention

Documents remain stored until:

  • You delete them
  • Your organization removes them
  • Account termination triggers data removal per applicable retention policies

Stored documents are not accessed by company personnel except where required for system maintenance or legally required obligations.

Security Protections Applied to All Documents

Across both workflows:

  • Encryption in transit and at rest
  • Strict access controls
  • Role-based permissions
  • Regular security audits
  • SOC 2 Type II and ISO 27001 certified infrastructure

Your Responsibility

You remain responsible for:

  • Determining whether uploaded documents are subject to export control laws
  • Controlling access within your organization

If you have questions about data security, certifications, or compliance obligations, please contact us:

info@assistandt.com