Solutions / Aerospace & Defense

Controlled data, only for the people cleared to see it. Every access provable.

Export-controlled technical data and Controlled Unclassified Information must reach only authorized people on a strict need-to-know basis — and every access must be traceable. Lakekeeper enforces that at the data catalog itself: need-to-know access, no standing or shared credentials, and a complete access record your export-control and CMMC programs can put in front of an auditor.

ITAR / EAR technical dataControlled Unclassified Information (CUI)CMMC / NIST 800-171Need-to-know accessDeployable today
The problem in plain terms

The rule is need-to-know. The hard part is proving it.

Nobody in aerospace and defense disputes the rules. Export-controlled technical data under ITAR and EAR, and Controlled Unclassified Information, may only be seen by authorized people who genuinely need it for their work. The difficulty is showing it is true — that access really is restricted, that no one kept a set of credentials they should not have, and that you can account for every time controlled data was touched.

When most of that lives in shared drives and databases that were never built to answer those questions, the evidence is stitched together by hand at audit time. Lakekeeper moves the control and the record into the data layer itself, so the answer to who could reach this and who did is always the system, not a spreadsheet describing it.

FrameworkWhat it requiresStatus
Export-controlled data (ITAR / EAR)Technical data on defense articles may only be accessed by authorized persons on a strict need-to-know basis. Every access to that data has to be controlled and provable — not assumed because a folder had the right permissions last year.Need-to-know required
Controlled Unclassified Information (CUI)CUI has to be protected from anyone without a legitimate need to see it, and access has to be recorded. When a program is audited, you are asked to show who could reach the data and who actually did.Access must be traceable
CMMC / NIST 800-171Prime and sub-tier suppliers must demonstrate that access to controlled data is restricted, that there are no shared or standing credentials, and that access is logged. The evidence you show an assessor is your live system, not a policy document describing it.Assessment-blocking
Lakekeeper — deployable today

Control and traceability built into the catalog.

Lakekeeper does not sit beside your data adding paperwork. It governs the catalog where controlled data lives — Apache Iceberg-native and open standard — so need-to-know access and a full access record are properties of the system. It helps you enforce the need-to-know access and audit trails that export-control and CMMC programs require.

What it doesWhat it helps you meet
Catalog-level access control
Access is decided table by table and view by view, right at the catalog. Deny by default: no one reaches controlled data unless they have been explicitly granted a need to know. Access is part of the data operation itself, not a folder permission bolted on beside it.
ITAR / EAR — enforce need-to-know on technical data
CUI — restrict access to authorized people only
Declarative data security
Access policy is written down as state and versioned like code, so you can always show exactly who can reach what and when it changed. No standing privileges left open, no shared keys handed around — every access is granted for a single request with short-lived credentials that expire on their own.
CMMC / NIST 800-171 — no shared or standing credentials
ITAR / EAR — eliminate standing access to controlled data
Audit trail at the metadata layer
Every read, write and transformation is captured as a system event. When an export-control officer or CMMC assessor asks who accessed a controlled dataset, the answer is a complete, durably recorded, append-only record produced by the system — not a log reconstructed after the fact.
CUI — access to controlled data is fully recorded
CMMC / NIST 800-171 — access is logged and auditable
Lineage & traceability
Every dataset carries its provenance — where it came from and how it was derived. For certification and safety programs that have to show where engineering and test data originated, that trace is available directly from the catalog.
Certification & safety programs — provable data provenance
Export control — trace where controlled data flowed
Apache Iceberg-native, open standard
Governance is enforced at the open catalog where your data already lives. No proprietary format, no vendor lock-in — the same open standard your engineering and analytics teams are already building on.
Program continuity — no vendor lock-in on controlled data
Portability across primes, subs and program partners

Lakekeeper helps enforce the need-to-know access and audit trails that export-control and CMMC programs require. It does not by itself make an organization ITAR- or CMMC-certified, and it is not a guarantee of export-control compliance.

Controlled data stays controlled —
and every access stays on the record.

Book a 30-minute walkthrough

Bring your specific export-control, CUI or CMMC / NIST 800-171 evidence challenge — we show you how Lakekeeper enforces need-to-know access and produces the access record against your data, not a demo dataset. Right team: your security or compliance lead, export-control officer or head of data, plus whoever owns your catalog.

← Back to all solutions