S32TECHNOLOGIES
Trust · Eligibility

Who we will supply, and how we decide

Capability is not the same as permission. Every prospective engagement for a restricted capability goes through the same review, and that review has six possible outcomes.

Eligibility is per capability, not per customer.

A customer approved for one S32 Technologies capability is not automatically eligible for every other one. Lawful interception, computer network operations and restricted intelligence modules each carry their own threshold, and a hosting or training relationship does not carry across to them.

That is deliberate. It means a long-standing relationship never becomes the reason something sensitive gets approved, and it means the question is asked again each time the capability changes.

Baseline

Who restricted capability is available to

Lawful interception and computer network operations are supplied only to vetted government agencies, licensed communications service providers, and qualified critical-infrastructure operators, and only where lawful in the customer’s jurisdiction and ours.

No demonstration, training, technical assistance, software transfer, hardware transfer or operational support proceeds to any foreign person or destination without documented authorization. That applies to a conference-room demo as much as to a deployment.

The review

What we establish before proceeding

Legal authority and oversight

Does the organization hold the legal authority to operate the capability, and is it subject to oversight that can act on misuse?

Mission and end use

What the capability is for, who it will be used against, and whether that use is within the authority claimed.

Institutional diligence

Country, institution, named officials, intermediaries and beneficial ownership. Who is behind the buyer.

Sanctions and restricted parties

Screening against applicable sanctions regimes and restricted-party lists, refreshed through the life of the relationship.

Export control

EAR and, where applicable, ITAR jurisdiction, classification, licensing, nationality of personnel, and technical-data review.

Anti-corruption

FCPA and equivalent controls, including how the engagement is being funded and by whom.

Human rights and misuse risk

Foreseeable misuse, spillover onto people outside the mandate, and the record of the institution asking.

Data and incident obligations

Retention, audit, privacy and breach-notification duties that will attach to the deployment.

The gate

Two of the outcomes are refusals

A review that can only produce a yes is not a review. These are the outcomes ours can reach, and they are the same six we use internally.

01

Approved

The engagement proceeds under standard terms.

02

Approved with conditions

It proceeds with specific contractual, technical or operational conditions attached, and those conditions are enforceable, not advisory.

03

Enhanced diligence

The review does not have enough to decide. It pauses while we get more, and the burden sits with us to obtain it, not with the customer to assert it.

04

Counsel or license required

Outside legal opinion or a government license has to be in hand before anything further happens, including a demonstration.

05

Deferred

Not now. Circumstances may change, and the file stays open, but nothing proceeds in the meantime.

06

Declined

We do not proceed. We are not obliged to give a reason, and declining is a real outcome, and it happens.

What happens after approval.

Approval is not permanent. End use, retransfer, access, audit, suspension and termination terms go into the contract, which means a change in how a capability is used is a contractual matter. Screening is refreshed, not filed.

Where misuse is discovered or credibly alleged, S32 Technologies can suspend or withdraw its own participation. What we do not do is take covert control of a lawful customer’s operations. We decide whom we serve and what we supply; the authorized customer governs its own operations inside the boundary that was agreed.