Need to know. Now prove it.
Everyone knows the rule. Almost nobody can show the evidence on demand.
The rule is settled. The evidence is not.
Technical data reaches authorized persons on a need-to-know basis. Foreign-person access is an export, whether or not anything ships.
Safeguard CUI to NIST 800-171 and prove it. The clause is in force today, and the attested score is a False Claims Act exposure.
Phase II is suspended pending review, but Phase 1 self-assessment continues — and what you self-attest still has to be true.
Deny by default. Granted by exception.
Need-to-know stops being a policy everyone agrees with and becomes the state of the system.
Illustrative of the access model, not of any program's actual data.
What changes with Lakekeeper.
Need-to-know access and the access record become properties of the catalog.
Lakekeeper helps enforce the need-to-know access and audit trails that export-control and CUI programs require. It does not by itself make an organization ITAR- or CMMC-certified, and it is not a guarantee of export-control compliance.
Controlled data stays controlled —
and every access stays on the record.
Bring your export-control officer or security lead, plus whoever owns your catalog.
Sources: US Department of State consent agreements with RTX Corporation (Aug 2024) and General Electric Company (Apr 2026); US Department of Justice settlement with MORSECORP Inc. (Mar 2025); DOJ FY2025 False Claims Act statistics, Civil Cyber-Fraud Initiative.