Export and Deployment Policy
Export and Deployment Policy
Section titled “Export and Deployment Policy”How ARROW hardware, virtual appliances, and cloud images may be delivered, and where.
| Policy number | VTEM-EXP-2026-0002 |
| Version | 2.0 |
| Effective | August 18, 2026 |
| Supersedes | Version 1.1, April 2026 |
| Applies to | ARROW physical devices, virtual appliances, and cloud images |
1. Overview
Section titled “1. Overview”VTEM Labs, Inc. is a U.S.-based provider of advanced cybersecurity and penetration testing technology. Our ARROW platform is a purpose-built solution for remote red team operations, ethical hacking engagements, and secure infrastructure assessments. The ARROW platform is available in two formats.
- Physical Device. A custom Linux appliance with full-disk encryption and multi-carrier cellular connectivity, managed through an automated encrypted VPN tunnel to the ARROW platform.
- Virtual Appliance or Cloud Image. A hardened, pre-built image the customer imports into its own hypervisor or cloud account. Seven deployment targets are supported, listed at clause 7.2.
This policy governs the export, distribution, and use of ARROW products globally and reflects compliance with U.S. export control laws, including the Export Administration Regulations (EAR, 15 CFR Parts 730 to 774), the sanctions programs administered by the Office of Foreign Assets Control (OFAC), and the Wassenaar Arrangement as implemented in the Commerce Control List. ARROW is a commercial product and is not a defense article on the United States Munitions List, so the International Traffic in Arms Regulations do not apply to it.
The policy applies to every VTEM Labs employee, contractor, reseller, and distributor, and to every customer, evaluator, and trial user who receives ARROW in any form. It applies equally to hardware shipped in a case and to an image downloaded over the internet. A download is an export.
2. Export classifications
Section titled “2. Export classifications”ARROW devices and virtual machines are dual-use technologies and are subject to the EAR based on their capability for cybersecurity testing and their inclusion of encryption and VPN components. Two families of control apply, and VTEM Labs applies the more restrictive outcome to every transaction.
- Cybersecurity items. The EAR controls intrusion software tooling and IP network communications surveillance items under ECCNs 4A005, 4D001.a, 4D004, 4E001.a, 4E001.c, 5A001.j, and the related 5B, 5D, and 5E entries. These are subject to License Exception ACE at 15 CFR 740.22.
- Encryption items. ARROW uses full-disk encryption and an encrypted management tunnel, which brings the Category 5 Part 2 encryption controls and License Exception ENC at 15 CFR 740.17 into scope, together with the associated classification and annual self-classification reporting obligations.
Customers who need classification information for their own filings should request it in writing.
2.1 License Exception ACE does not cover everything
Section titled “2.1 License Exception ACE does not cover everything”This is the single most important thing for a customer to understand about deploying a U.S.-origin penetration testing platform abroad. License Exception ACE authorizes many exports of cybersecurity items, but it is expressly unavailable in the situations that matter most. VTEM Labs will not release ARROW where any of the following is true.
- The destination is in Country Group E:1 or E:2, currently Iran, North Korea, Syria, and Cuba.
- The recipient is a government end user in any Country Group D destination. The definition is broad, and it includes state-owned or partially state-owned utilities, telecommunications and internet service providers, transport operators, and government research institutions. Partial ownership means 25 percent or more of the voting securities, or the ability to appoint a majority of the board.
- The recipient is a non-government end user in a Country Group D:1 or D:5 destination, outside the narrow carve-outs for vulnerability disclosure and cyber incident response.
These are destination and end-user tests. They turn on where the item is going and who the recipient is, which are facts VTEM Labs establishes at the point of supply. They do not turn on the content of any engagement, and VTEM Labs does not evaluate its customers’ work. See clause 7.6.1.
3. General policy summary
Section titled “3. General policy summary”| Classification | Physical Device | Virtual Machine |
|---|---|---|
| Prohibited Countries | Not Permitted | Not Permitted |
| Restricted Countries | Reviewed Case-by-Case | Reviewed Case-by-Case |
| Permitted Countries | Allowed (with compliance) | Allowed (with compliance) |
Table 1. Policy summary by destination classification.
The classification follows the deployment, not the invoice. A customer headquartered in a permitted country cannot order ARROW for deployment in a restricted or prohibited one, and cannot grant access to personnel located there. Where the ordering entity, the billing address, the shipping address, and the deployment site are not all in the same country, the most restrictive of them governs.
4. Prohibited countries
Section titled “4. Prohibited countries”VTEM Labs does not ship devices, release images, grant download access, or provision cloud instances to the following destinations under any circumstance. There is no review process for these and no fee will be quoted, because the answer will not change.
| Destination | Basis |
|---|---|
| Cuba | Country Group E:2 |
| Iran | Country Group E:1 |
| North Korea | Country Group E:1 |
| Syria | Country Group E:1 |
| Crimea, and the Donetsk, Luhansk, Kherson, and Zaporizhzhia regions of Ukraine | Comprehensive sanctions |
Table 2. Prohibited destinations.
These are the destinations in Country Group E:1 and E:2 of the EAR, together with the regions of Ukraine subject to comprehensive sanctions. This prohibition applies to both physical shipments and virtual machine access, and it applies to a customer located elsewhere who intends to deploy or operate ARROW in one of these destinations.
Syria warrants a specific note, because U.S. policy toward Syria changed substantially during 2025 and is still moving. A number of Syria sanctions were revoked and the OFAC country program was restructured. Export controls did not follow at the same pace, so a license is still required for effectively all items subject to the EAR, Syria remains in Country Group E:1, and License Exception ACE is therefore not available. VTEM Labs will revisit this determination if and when the country group listing changes.
5. Restricted countries
Section titled “5. Restricted countries”The following destinations are subject to U.S. export licensing requirements or regulatory review. VTEM Labs will not export physical devices or permit virtual machine downloads to these destinations without explicit authorization.
| Destination | Basis |
|---|---|
| Afghanistan | D:5 arms embargo |
| Armenia | D:1 national security |
| Azerbaijan | D:1 national security |
| Belarus | D:1 and D:5; Russia-related controls |
| Burma (Myanmar) | D:1 and D:5; military end user rule |
| Cambodia | D:1; military end user rule |
| Central African Republic | D:5 arms embargo |
| China | D:1 and D:5; military end user rule |
| Congo (Democratic Republic of) | D:5 arms embargo |
| Eritrea | D:5 arms embargo |
| Georgia | D:1 national security |
| Haiti | D:5 arms embargo |
| Hong Kong | Not a separate destination; treated as China |
| Iraq | D:1 and D:5; EAR 746.3 |
| Kazakhstan | D:1 national security |
| Kyrgyzstan | D:1 national security |
| Laos | D:1 national security |
| Lebanon | D:5 arms embargo |
| Libya | D:1 and D:5 arms embargo |
| Macau | D:1; treated with China |
| Moldova | D:1 national security |
| Mongolia | D:1 national security |
| Nicaragua | D:1 and D:5; military end user rule |
| Russia | D:1 and D:5; EAR 746.8, policy of denial |
| Somalia | D:5 arms embargo |
| South Sudan | D:5 arms embargo |
| Sudan | D:5 arms embargo |
| Tajikistan | D:1 national security |
| Turkmenistan | D:1 national security |
| Uzbekistan | D:1 national security |
| Venezuela | D:1 and D:5; military end user rule |
| Vietnam | D:1 national security |
| Yemen | D:1 national security |
| Zimbabwe | D:5 arms embargo |
Table 3. Restricted destinations. The basis for each is in Annex A.
This list is the union of Country Group D:1 (national security) and Country Group D:5 (U.S. arms embargoed), less the destinations already prohibited above. The reason the list is drawn this way is specific to this product. License Exception ACE is unavailable for cybersecurity items to government end users anywhere in Country Group D, and to non-government end users in D:1 or D:5. For ARROW, a D:1 or D:5 listing is a hard licensing bar rather than a matter of enhanced diligence.
Requests will be evaluated on a case-by-case basis and may ultimately be denied. Please note that VTEM Labs will assess and invoice legal review fees for any formal request involving these countries, regardless of outcome. The fee is quoted and agreed in writing before the review begins.
6. Permitted countries
Section titled “6. Permitted countries”All other countries, including U.S. allies and most of the world, may receive ARROW shipments and download virtual machines, provided that:
- the requesting entity is not listed on any U.S. denied, debarred, or restricted party list;
- the use case is authorized, legal, and involves client-approved penetration testing or internal red team operations; and
- the device or software is not re-exported to a prohibited or restricted destination.
A number of permitted destinations sit in Country Group D:2, D:3, or D:4 without being in D:1 or D:5. Commercial customers in those destinations are reachable, but a government end user is not, because License Exception ACE excludes government end users throughout Country Group D. These destinations are marked in the reference table at Annex A.
Separately, some permitted destinations are recognized transshipment routes to restricted markets. Orders routed through them receive additional scrutiny of the end user and the deployment site. This is diligence, not a restriction, and the order proceeds once the end use is verified.
7. Virtual machine deployment in place of physical shipment
Section titled “7. Virtual machine deployment in place of physical shipment”Some destinations cannot receive a physical device even though the customer, the engagement, and the destination are entirely lawful. The obstacle is logistics and customs, not sanctions. In those cases VTEM Labs deploys ARROW as a virtual appliance or cloud image instead, and the engagement proceeds without hardware.
7.1 When VTEM Labs requires a virtual deployment
Section titled “7.1 When VTEM Labs requires a virtual deployment”VTEM Labs may require virtual deployment, at its discretion, where any of the following applies.
- Customs formalities cannot be completed. Some destinations require import documentation, licensing, or local registration that can only be produced by an entity established in that country. Where no such filing can be made from the United States, the hardware cannot lawfully enter and the shipment will not be attempted.
- Encryption import controls apply. A number of countries restrict the import or domestic use of encryption hardware and require prior authorization or registration held by a local party. ARROW devices use full-disk encryption and an encrypted management tunnel, so these controls are engaged.
- Radio approval cannot be obtained. ARROW devices contain cellular transmitters. Many countries require type approval or homologation of radio equipment before it may be imported or operated, and that approval is normally held by a locally established entity. Where it cannot be obtained for a short engagement, the hardware cannot lawfully be used even if it clears customs.
- No compliant carrier service is available. Carrier coverage changes with regulatory, geopolitical, and operational conditions, and some lanes are suspended or unsupported for equipment of this type.
- Return shipment cannot be assured. Where VTEM Labs cannot generate a compliant return label and the customer cannot commit to a lawful return, the device does not go out in the first place.
- Duty, tariff, or seizure exposure is unreasonable. Where duties, tariffs, or the risk of hold or seizure make physical delivery commercially or operationally unsound for either party.
- The customer prefers it. Virtual deployment is available on request in any permitted destination. It is often faster, because there is no transit time and no customs clearance.
7.2 Supported deployment targets
Section titled “7.2 Supported deployment targets”VTEM Labs builds and supports the following targets.
| Deployment Target | Image Format | Typical Host |
|---|---|---|
| VMware (OVA) | OVA / OVF / VMX | Workstation, Fusion, ESXi and vSphere 6.7 and later |
| VirtualBox (OVA) | OVA | Desktop and laboratory hosts on Windows, macOS and Linux |
| QEMU/KVM (QCOW2) | QCOW2 / IMG | Linux virtualization hosts and libvirt-managed infrastructure |
| Hyper-V (VHDX) | VHDX | Windows Server and Windows desktop hypervisor hosts |
| Azure (VHD) | Fixed-size VHD in ZIP | Microsoft Azure, imported as a managed image then launched |
| AWS (AMI) | VMDK in ZIP | Amazon Web Services, imported as a snapshot then registered |
| GCP (raw.tar.gz) | disk.raw.tar.gz in ZIP | Google Cloud, imported as a Compute Engine custom image |
Table 4. ARROW virtual and cloud deployment targets.
Setup guides for each target are under VM Deployment.
7.3 What virtual deployment changes, and what it does not
Section titled “7.3 What virtual deployment changes, and what it does not”Virtual deployment removes the shipping problem. It does not remove the export control problem, and customers should not read it as a way around a restricted destination.
| Consideration | Physical Device | Virtual or Cloud Image |
|---|---|---|
| Customs entry | Required | None |
| Duties and tariffs | Payable by recipient | None |
| Carrier availability | Can block delivery | Not applicable |
| Transit time | Days to weeks | Download time |
| Return obligation | Device must be returned | Image destroyed or deactivated |
| Export license rules | Apply in full | Apply in full |
| Screening and end use | Required | Required |
| Re-export restrictions | Apply | Apply |
Table 5. Physical delivery compared with virtual deployment.
7.4 Deployment region and access control
Section titled “7.4 Deployment region and access control”For cloud deployments, the customer selects the account, project, and region into which the image is imported. The customer is responsible for ensuring that the chosen region, and the location of every person granted access to the running instance, are permitted under this policy. Provisioning an ARROW instance in a permitted region and then operating it from, or granting access to it from, a prohibited destination is a violation of this policy and of the customer’s agreement.
Images are supplied to the contracted customer only. They must not be passed on, republished, mirrored, or redistributed in any form, and any credentials supplied with an image should be changed on first login.
7.5 When the management tunnel cannot call out
Section titled “7.5 When the management tunnel cannot call out”ARROW is managed through an encrypted tunnel that the deployed instance opens outbound to the ARROW platform. In some countries that tunnel will not establish. The traffic may be blocked, throttled, or inspected at the national or carrier level; VPN use may be permitted only over a locally licensed provider; or the encryption itself may be restricted. The image deploys and runs, but it cannot phone home.
This is a connectivity and local-law problem, not a product defect, and it is foreseeable in a number of otherwise permitted destinations. Clients should assume it may happen and plan for it before the engagement window opens.
7.5.1 The client provides the access path
Section titled “7.5.1 The client provides the access path”Where the ARROW tunnel cannot establish, the client is responsible for providing a lawful means of reaching the virtual machine so the engagement can proceed. Acceptable arrangements are ones the client already operates and controls, for example:
- access through the client’s own corporate remote access or VPN infrastructure, where that infrastructure is lawfully operated in the destination;
- a client-provided bastion or jump host that the operator can reach from a permitted location;
- console or out-of-band access through the client’s hypervisor management interface or cloud provider console;
- a client-nominated network path, address range, or egress allowance that permits the instance to reach the platform; or
- operation of the instance by the client’s own personnel, with output exchanged through an agreed channel.
The client is responsible for the lawfulness, security, and availability of whatever path it provides, and for any consent or registration that path requires in the destination. VTEM Labs will support the integration but cannot warrant performance over a network it does not control, and engagement timelines should allow for it.
7.5.2 Where the technology itself is barred
Section titled “7.5.2 Where the technology itself is barred”A blocked tunnel and a barred technology are different problems with different answers. If VPN use, the encryption in the product, or tooling of this class is prohibited or requires a license in the destination, that is a legal restriction and it is the client’s responsibility to resolve it lawfully before deployment, whether by using a licensed local provider, obtaining regulator approval, or narrowing the engagement. Clause 10 already places local law compliance on the client, and this is the most common place it bites.
7.6 The limits of the VTEM Labs role
Section titled “7.6 The limits of the VTEM Labs role”VTEM Labs provisions the device or image, prepares the shipping documentation, and delivers it to the client. What this policy adds to that is a single question, asked before supply. Is the destination one this policy permits, and is the recipient a party VTEM Labs is permitted to supply. That question is about geography and identity. It is not about the client’s work.
- VTEM Labs does not request, receive, review, audit, or retain any client statement of work, scope document, engagement letter, testing authorization, assessment methodology, finding, report, or any record of the work a client performs.
- VTEM Labs is not a party to the client’s engagements, has no visibility into them, and holds no contractual right of access to that documentation.
- VTEM Labs does not assess, approve, or second-guess the work its clients undertake. Clients are professional penetration testing and cybersecurity firms operating under their own commercial agreements, and the lawfulness and scoping of their engagements are matters for their own legal counsel.
ARROW is supplied to contracted professional customers under a commercial subscription. It is not available to the general public, is not sold over the counter, and is not provided on an unvetted or casual basis.
7.7 Deemed exports
Section titled “7.7 Deemed exports”Releasing controlled technology or source code to a foreign person inside the United States is an export to that person’s most recent country of citizenship or permanent residency. VTEM Labs applies this rule to its own personnel and contractors, and customers must apply it to theirs. Giving a foreign national access to a controlled ARROW build, or to its controlled technology, may require a license even though nothing crosses a border, and no license exception is available for nationals of Country Group E:1 or E:2 destinations.
8. Client-arranged delivery and onward transit
Section titled “8. Client-arranged delivery and onward transit”There is a middle case between a straightforward shipment and a virtual deployment. A client may have a legitimate operational need to put physical hardware somewhere that VTEM Labs will not ship to directly, because the customs, carrier, tariff, or seizure risk of that lane is one VTEM Labs is not willing to carry. Where the destination is otherwise lawful, that engagement does not have to be abandoned. It can proceed on the client’s own account.
8.1 How it works
Section titled “8.1 How it works”VTEM Labs delivers the device to a permitted location the client nominates, typically a client office, freight forwarder, or agent in the United States or another permitted country. From the moment of delivery at that location, the client arranges, controls, and is responsible for all onward movement, to its own premises, to the engagement site, and back to VTEM Labs at the end of the term.
- The client becomes the exporter. Any movement of the device out of the delivery country is the client’s export, made on the client’s own account and under the client’s own export authorizations. The client is the exporter of record and is responsible for classification, licensing, filing, and customs formalities for every leg it arranges.
- The client carries the legal risk in full. The client assumes complete legal, regulatory, financial, and operational responsibility for the onward transit, including duty, tariff, penalty, delay, damage, loss, seizure, and forfeiture, and indemnifies VTEM Labs against any claim arising from it.
- Written risk acceptance is required, not implied. This arrangement is available only where the client’s own legal counsel has reviewed it and confirmed in writing that the client accepts the risk, and where an authorized business representative of the client has done the same. VTEM Labs will not proceed on a verbal assurance or on an assurance from someone without authority to give it.
- Custody and return are unchanged. The device remains the property of VTEM Labs throughout. The client remains fully responsible for it from delivery until confirmed return, and the return obligations in clause 11 apply in full. Choosing this route does not convert a rental into a sale and does not relieve the client of returning the device.
- VTEM Labs may still decline. This is a concession, not an entitlement. VTEM Labs may refuse any request under this clause for any reason, and will refuse where the facts suggest the real destination is one this policy prohibits.
8.2 The limit, which does not move
Section titled “8.2 The limit, which does not move”This clause exists so that lawful engagements in operationally difficult places can go ahead. It is not a mechanism for reaching places this policy closes, and it will never be treated as one.
Accordingly, the client must identify every country the device will enter before delivery is arranged, and must obtain written approval from VTEM Labs before moving it to any country not named in that request. Where a client cannot lawfully move a device to the place it needs to work, the answer is a virtual deployment under clause 7, not a quiet routing.
9. Customs, tariffs, and international shipping
Section titled “9. Customs, tariffs, and international shipping”Due to evolving global trade regulations, tariffs, and carrier restrictions, international shipment and return of ARROW devices may be impacted by factors outside of the control of VTEM Labs. Because devices are rented and must come back, every engagement involves two customs movements, not one, and the return leg is usually the harder of the two.
- Customs compliance. All shipments must comply with applicable U.S. export laws and destination country import regulations. VTEM Labs will not alter, misrepresent, or falsify customs declarations, product classifications, country of origin, or declared values under any circumstances or at any customer’s request.
- Tariffs and duties. All import duties, VAT, tariffs, brokerage fees, and related charges are the sole responsibility of the receiving party unless otherwise explicitly agreed in writing. Both the rates and the basis on which they are assessed have changed materially during 2025 and 2026 and may change again during a subscription term. Landed cost should be confirmed with a customs broker in the destination before an engagement is scheduled.
- Low-value shipments are no longer simple. The U.S. duty-free exemption for low-value commercial shipments has been suspended for all countries and is being withdrawn permanently. A returned device or a single spare part now requires a customs entry with full classification, and attracts brokerage and processing fees that can exceed the duty itself.
- Temporary export documentation. Because ARROW devices are rented and returned, an ATA Carnet or equivalent temporary admission document is often the cleanest route for a short engagement. Where a Carnet is used, the customer is responsible for presenting the equipment for re-exportation within its validity period. A Carnet is a customs document only, so it does not authorize an export that export control law prohibits, and it does not make a restricted destination reachable.
- Carrier limitations. Certain regions may be restricted or unsupported by carriers due to regulatory, geopolitical, or operational constraints. Shipping availability may change without notice.
- Return shipping limitations. VTEM Labs will make commercially reasonable efforts to provide return shipping labels. However, due to international regulations, carrier restrictions, and tariff policies, this may not be possible in all regions.
- Client-assisted returns. Where VTEM Labs is unable to generate compliant return shipping labels, the client is responsible for coordinating return shipment in accordance with applicable export laws, including carrier selection, customs documentation, and export declarations.
- Use a broker or express carrier for returns, not the mail. The postal channel now carries the heaviest documentation burden for shipments returning to the United States and is not suitable for an ARROW device.
- Export filing. Electronic export information must be filed for any shipment that requires an export license, regardless of its value. Value-based filing exemptions do not apply to licensed exports.
- Refusal or inability to ship. If a client or end customer is unable or unwilling to comply with shipping, customs, or return requirements, VTEM Labs may require the use of a virtual appliance in place of physical device deployment.
- Delays, holds, and seizures. VTEM Labs is not responsible for delays, customs holds, inspections, tariffs, or seizure of devices once transferred to a shipping carrier. Where a shipment is held or lost, VTEM Labs will offer a virtual deployment so the engagement can continue.
For the day-to-day mechanics of tracking, receiving, and returning a device, see Device Shipments.
10. Client responsibilities
Section titled “10. Client responsibilities”The obligations below relate to export control, custody, and the movement of the device and image. They are deliberately confined to those subjects. Nothing in this policy governs how a client conducts its own engagements, and VTEM Labs does not require clients to account to it for that work.
- No unauthorized resale or re-export. The device or VM may not be sold, sublicensed, transferred, or re-exported to any third party, and never to a party or destination in a restricted or embargoed jurisdiction. Devices are rented and remain VTEM Labs property, so a transfer to a third party is both a breach of contract and potentially an unlicensed re-export.
- Compliance with local laws. The client is responsible for complying with all local laws regarding encryption, VPN use, import and export, wireless transmissions, computer misuse, and data protection at the deployment location.
- Accurate destination information. The recipient entity, delivery location, and country of deployment given to VTEM Labs must be accurate and kept current, because those are the facts on which the export determination rests. Any change is reported before it takes effect.
- Access control. Access is limited to identified individuals whose location and nationality are permitted under this policy.
- No movement across borders. A device may not be carried or shipped to a country other than the one it was released to without prior written approval. Moving a device across a border is a re-export and requires its own analysis.
11. Device custody and return requirements
Section titled “11. Device custody and return requirements”ARROW devices are rented for the duration of an engagement. The obligations below are the core of the commercial relationship, not boilerplate.
- Custodial responsibility. ARROW physical devices remain the property of VTEM Labs at all times. The client assumes full responsibility for the device from the time of delivery until confirmed return, including physical security and protection against loss, theft, and unauthorized access.
- Return timing. Physical devices must be returned upon expiration or termination of the applicable subscription term, or earlier upon request by VTEM Labs.
- Return shipping. VTEM Labs will make commercially reasonable efforts to provide return shipping labels. However, due to international shipping restrictions, this may not be possible in all regions.
- Client-managed returns. Where VTEM Labs cannot provide return shipping, the client is responsible for coordinating compliant return shipment, including carrier selection, customs documentation, and export declarations from the originating country.
- Returned goods treatment. ARROW devices are U.S.-origin goods, so a device returned unaltered may normally re-enter the United States free of duty as American goods returned. That relief is fragile and the client must protect it. Do not open, service, repair, upgrade, reflash, or otherwise advance the device in value while it is abroad, and do not substitute a different unit. The exact device that was exported, by serial number, must be the device that returns. Work performed abroad or a substituted unit makes the return dutiable.
- Return records. The client must keep, and provide on request, the shipping and export documentation for the outbound movement. Proof of export is required to claim returned-goods treatment, and the burden of proof sits with the importer of record.
- Failure to return. Devices not returned within the agreed timeframe may be subject to replacement or recovery fees as defined in the commercial agreement, and platform access may be suspended.
- Virtual deployments. On expiration or termination, the client must destroy or decommission all copies of the image and all instances derived from it, and confirm in writing on request.
12. Compliance and legal boundaries
Section titled “12. Compliance and legal boundaries”VTEM Labs operates in strict compliance with U.S. export control laws and international trade regulations. The following actions are strictly prohibited.
- Misrepresentation of shipment contents, value, origin, or classification.
- Falsification or manipulation of customs, export, or import documentation.
- Routing shipments, downloads, or cloud access through intermediaries to circumvent export restrictions.
- Exporting, re-exporting, or transferring products to denied parties or restricted jurisdictions.
- Splitting an order, or understating a value or quantity, to avoid a licensing or reporting threshold.
- Use of ARROW in violation of applicable local, national, or international law.
VTEM Labs will not support or participate in any activity intended to bypass legal, regulatory, or customs requirements under any circumstances.
12.1 Suspension and termination
Section titled “12.1 Suspension and termination”VTEM Labs may suspend platform access, halt a shipment, revoke a download, deactivate a deployed instance, and recall a device immediately, without prior notice and without liability, where it identifies a violation of this policy or a change in law or listing status that makes continued supply unlawful. Suspected violations are reported to the relevant U.S. authority where the law requires it.
12.2 Policy changes
Section titled “12.2 Policy changes”Countries may be added to or removed from any list in this policy at any time, with or without notice, based on changes to U.S. export control laws or at the sole discretion of VTEM Labs in response to geopolitical events, compliance concerns, or risk assessments. The controlling version is the one published at vtemlabs.com.
13. Questions and licensing requests
Section titled “13. Questions and licensing requests”If your organization is located in a country listed under the restricted category, if you are unsure of your compliance status, or if you need classification information for your own filings, contact VTEM Labs before scheduling an engagement. Requests should identify the legal entity, the recipient, and the country and site of deployment.
Annex A: General reference table
Section titled “Annex A: General reference table”| Destination | Physical Device | Virtual Machine | Basis |
|---|---|---|---|
| Cuba | Not Permitted | Not Permitted | Country Group E:2 |
| Iran | Not Permitted | Not Permitted | Country Group E:1 |
| North Korea | Not Permitted | Not Permitted | Country Group E:1 |
| Syria | Not Permitted | Not Permitted | Country Group E:1 |
| Crimea, and the Donetsk, Luhansk, Kherson, and Zaporizhzhia regions of Ukraine | Not Permitted | Not Permitted | Comprehensive sanctions |
| Afghanistan | License Required | License Required | D:5 arms embargo |
| Armenia | License Required | License Required | D:1 national security |
| Azerbaijan | License Required | License Required | D:1 national security |
| Belarus | License Required | License Required | D:1 and D:5; Russia-related controls |
| Burma (Myanmar) | License Required | License Required | D:1 and D:5; military end user rule |
| Cambodia | License Required | License Required | D:1; military end user rule |
| Central African Republic | License Required | License Required | D:5 arms embargo |
| China | License Required | License Required | D:1 and D:5; military end user rule |
| Congo (Democratic Republic of) | License Required | License Required | D:5 arms embargo |
| Eritrea | License Required | License Required | D:5 arms embargo |
| Georgia | License Required | License Required | D:1 national security |
| Haiti | License Required | License Required | D:5 arms embargo |
| Hong Kong | License Required | License Required | Not a separate destination; treated as China |
| Iraq | License Required | License Required | D:1 and D:5; EAR 746.3 |
| Kazakhstan | License Required | License Required | D:1 national security |
| Kyrgyzstan | License Required | License Required | D:1 national security |
| Laos | License Required | License Required | D:1 national security |
| Lebanon | License Required | License Required | D:5 arms embargo |
| Libya | License Required | License Required | D:1 and D:5 arms embargo |
| Macau | License Required | License Required | D:1; treated with China |
| Moldova | License Required | License Required | D:1 national security |
| Mongolia | License Required | License Required | D:1 national security |
| Nicaragua | License Required | License Required | D:1 and D:5; military end user rule |
| Russia | License Required | License Required | D:1 and D:5; EAR 746.8, policy of denial |
| Somalia | License Required | License Required | D:5 arms embargo |
| South Sudan | License Required | License Required | D:5 arms embargo |
| Sudan | License Required | License Required | D:5 arms embargo |
| Tajikistan | License Required | License Required | D:1 national security |
| Turkmenistan | License Required | License Required | D:1 national security |
| Uzbekistan | License Required | License Required | D:1 national security |
| Venezuela | License Required | License Required | D:1 and D:5; military end user rule |
| Vietnam | License Required | License Required | D:1 national security |
| Yemen | License Required | License Required | D:1 national security |
| Zimbabwe | License Required | License Required | D:5 arms embargo |
| Bahrain | Permitted | Permitted | Country Group D; government end users need a license |
| Egypt | Permitted | Permitted | Country Group D; government end users need a license |
| Israel | Permitted | Permitted | Country Group D; government end users need a license |
| Jordan | Permitted | Permitted | Country Group D; government end users need a license |
| Kuwait | Permitted | Permitted | Country Group D; government end users need a license |
| Oman | Permitted | Permitted | Country Group D; government end users need a license |
| Pakistan | Permitted | Permitted | Country Group D; government end users need a license |
| Qatar | Permitted | Permitted | Country Group D; government end users need a license |
| Saudi Arabia | Permitted | Permitted | Country Group D; government end users need a license |
| Taiwan | Permitted | Permitted | Country Group D; government end users need a license |
| Singapore | Permitted | Permitted | Country Group A:6; transshipment diligence applies |
| Turkiye | Permitted | Permitted | Country Group A:5; transshipment diligence applies |
| United Arab Emirates | Permitted | Permitted | Moved to Country Group A:5 in July 2026 |
| Australia, Canada, Japan, New Zealand, South Korea | Permitted | Permitted | Country Group A:5; permitted with compliance |
| European Union member states | Permitted | Permitted | Country Group A:5; permitted with compliance |
| Switzerland, United Kingdom | Permitted | Permitted | Country Group A:5; permitted with compliance |
| Ukraine (government controlled) | Permitted | Permitted | Permitted; occupied regions are prohibited |
| United States | Permitted | Permitted | Deemed export rules apply to foreign persons |
| All other destinations | Permitted | Permitted | Permitted with compliance |
Annex A. Destination determinations as of August 18, 2026.