Solutions / Aerospace & Defense

Need to know. Now prove it.

Everyone knows the rule. Almost nobody can show the evidence on demand.

ITAR / EARCUIDFARS 252.204-7012NIST 800-171Deployable today
$200M
Largest ITAR settlement to date
RTX, 2024 — 750 violations, external compliance officer imposed
$36M
Unauthorized technical-data exports
GE Aerospace, April 2026 — 116 violations, data to the PRC
−142
Actual score, where 104 was self-attested
MORSECORP, DOJ 2025. The scale runs −203 to 110
$52M
DOJ cyber-fraud settlements, FY2025
Across nine cases — more than tripled two years running

The rule is settled. The evidence is not.

ITAR / EARStrict liability

Technical data reaches authorized persons on a need-to-know basis. Foreign-person access is an export, whether or not anything ships.

DFARS 252.204-7012In force

Safeguard CUI to NIST 800-171 and prove it. The clause is in force today, and the attested score is a False Claims Act exposure.

CMMCPhase 1 active

Phase II is suspended pending review, but Phase 1 self-assessment continues — and what you self-attest still has to be true.

Deny by default. Granted by exception.

Need-to-know stops being a policy everyone agrees with and becomes the state of the system.

Eng AEng BSub 1Sub 2AnalystModelDesign dataTest resultsSupplier CADProgram docs
Granted — explicit need to know No access — the default

Illustrative of the access model, not of any program's actual data.

What changes with Lakekeeper.

Need-to-know access and the access record become properties of the catalog.

Today
With Lakekeeper
Access
Shared drives, standing logins, credentials that outlived the program.
Supports ITAR / EAR · CUI
Deny by default at table and view level. Need-to-know is enforced, not assumed.
Evidence
Reconstructed by hand at audit time, from logs never designed to answer the question.
Supports NIST 800-171 audit & accountability
Every read, write and transformation is an append-only system event.
Attestation
A score asserted from a system that cannot show its own state.
Supports DFARS 7012 · FCA exposure
The score is derived from what the catalog enforces, and can be re-derived on demand.
Provenance
Engineering and test data with no reliable trace of where it came from.
Supports Certification & safety programs
Every dataset carries its lineage, from source through every derivation.

Lakekeeper helps enforce the need-to-know access and audit trails that export-control and CUI programs require. It does not by itself make an organization ITAR- or CMMC-certified, and it is not a guarantee of export-control compliance.

Controlled data stays controlled —
and every access stays on the record.

Book a 30-minute walkthrough

Bring your export-control officer or security lead, plus whoever owns your catalog.

Sources: US Department of State consent agreements with RTX Corporation (Aug 2024) and General Electric Company (Apr 2026); US Department of Justice settlement with MORSECORP Inc. (Mar 2025); DOJ FY2025 False Claims Act statistics, Civil Cyber-Fraud Initiative.

← Back to all solutions