Last updated: 2026-08-27. Governing law: Israel.
Export-Control Self-Classification Memo & Trademark Notes
This memo records the good-faith internal self-classification, for export-control purposes, of the EyalSec / es2 Service and of every EyalSec agent: es-python, es-chromium, es-c, es-cpp, es-rust, es-node and es-solidity, es-bash and es-php. It also records trademark clearance items. It is reviewed periodically and updated as the Service evolves.
Published by Eyal Gabay, trading as "EyalSec", sole proprietor (osek murshe) no. 211868450, of Yehoshua Stampfer 39, Petah Tikva, Israel.
Scope. This memo covers the es2 server and every agent. An earlier version classified es-python only and expressly excluded es-chromium; that exclusion is withdrawn and replaced by the analysis below.
1. Products described (for classification)
| Item | What it is | What it does | |------|------------|--------------| | es2 server | A hosted web service | Receives, stores and displays security events reported by the agents | | es-python | A Python runtime, derived from CPython 3.9 through 3.14, that customers install on their own authorized machines | Marks untrusted data, reports when it reaches a dangerous operation, and can exercise its own process inputs | | es-chromium | A web browser, derived from the Chromium open-source project, that customers install on their own managed machines | Reports when untrusted data reaches a dangerous operation inside a web page, and reports installed extensions | | es-c / es-cpp | Compiler plugins, runtime libraries and driver scripts that load into the compiler already installed on the customer's own machine | Programs built with them report the same class of flows at runtime | | es-rust | A Rust language distribution, derived from the Rust open-source toolchain | Programs built with it report the same class of flows at runtime | | es-node | A JavaScript runtime, derived from the Node.js open-source project. Not currently distributed. | Services run under it report the same class of flows | | es-solidity | A Solidity compiler, derived from the Solidity open-source compiler. Not currently distributed. Development builds only, never for a public network. | Contracts compiled with it report the same class of flows in test | | es-bash | A command shell, derived from GNU Bash. No binary is distributed at all: what is delivered is source, which the customer's own machine compiles. A delivery surface now exists and the product is grantable; the first-export re-check required below has not yet been performed. | Shell scripts run under it report the same class of flows | | es-php | A PHP runtime, derived from the PHP open-source project, that customers install on their own authorized servers. Not currently distributed. | Web applications served by it report the same class of flows |
All of them are defensive security-monitoring tools. They run inside the customer's own authorized environment, observe that environment, and report to the customer's own dashboard. They do not attack, command, exploit, or deliver payloads to third-party systems.
Distribution status matters to this memo. es-python, es-chromium, es-c, es-cpp and es-rust are published and delivered to customers. es-node, es-solidity and es-php exist as products in the dashboard but no artifact for them is served to customers at the date of this memo; each must be re-checked against this memo before it is first exported.
es-php is a customer-visible product whose artifact is not yet served, and the two facts are separable: an account can hold the es-php entitlement and see es-php findings without any artifact having crossed a border. The first export is the publication of a build, not the sale of the entitlement, and that is the event this memo must be re-checked against.
es-bash changed status on 2026-08-27 and its re-check is OUTSTANDING. It is now a grantable product with a working delivery surface (a per-host install script and a secret-gated download of the source bundle), deployed to the internal test environment. No customer has received it yet, because the production environment has not been updated. The re-check this memo requires before a first export has not been performed, and nothing in this update performs it: this paragraph records that the trigger condition has arrived, so that the re-check happens before the production deploy rather than after it.
es-bash is a distinct case and is called out because the distinction matters to this memo. For every other agent, what would cross a border is a compiled binary. For es-bash it is source code, compiled by the recipient on the recipient's own machine. Publicly available source, and source that is already public, are treated differently from object code under several of the regimes below, so the analysis for es-bash must not be inherited wholesale from the other rows.
2. Cryptography classification
This applies to every agent listed in Section 1 and to the server.
- Cryptography is provided by standard, published implementations (OpenSSL and
BoringSSL for TLS, hashing and related primitives; the Go standard library's
cryptopackages). The products use published, standard cryptographic algorithms and protocols (AES, RSA, ECDH/ECDSA, SHA-2, TLS 1.2/1.3) and do not implement proprietary or "non-standard" cryptography. - Encryption functionality is ancillary to the products' primary function (security monitoring and reporting) and the products are aimed at a broad commercial market. Accordingly they are likely classifiable as mass-market items under US ECCN 5D992.c, per Note 3 to Category 5, Part 2 of the US Commerce Control List. The same reasoning applies to es-chromium, whose cryptography is the ordinary TLS and web-platform cryptography of a general web browser.
- Because the products use standard cryptography, the BIS/NSA email notification requirement that applies to "non-standard cryptography", and the associated classification and review obligations for non-standard crypto, should not apply.
- Any applicable mass-market self-classification report and annual self-classification reporting obligations to BIS are to be assessed and met for each agent separately.
- es-chromium ships the open codec set and no digital rights management module. It does
not include a licensed decryption module for protected media. See
/legal/licenses. - es-c and es-cpp ship no cryptographic library of their own. Their published artifacts are instrumentation plugins, runtime libraries and headers that build against the customer's own compiler; any cryptography in a resulting program is the customer's.
- es-solidity performs no encryption. A compiler for smart contracts has no transport security function of its own.
3. "Intrusion software" and cyber-tools axis
3.1 US EAR (ECCNs 4A005 / 4D004 / 4E001)
These control items for the generation, command-and-control, or delivery of "intrusion software" to a third party's system, and for the extraction of data by it.
- es-python, es-c, es-cpp, es-rust, es-node, es-solidity, es-bash and es-php instrument and monitor the customer's own program on the customer's own authorized machine, and exercise their own inputs. They do not generate, command, deliver or extract data from "intrusion software".
- es-chromium observes the behavior of web pages inside the browser the customer runs on the customer's own managed machine. It does not install anything on, send anything to, or execute anything on a remote system, and it does not defeat protective countermeasures on a third party's device.
Accordingly these ECCNs should not apply, absent misuse contrary to the AUP.
3.2 EU Regulation (EU) 2021/821, Article 5 cyber-surveillance catch-all
Article 5 targets items that could be used for covert surveillance of natural persons by monitoring, extracting, collecting or analysing data from information and telecommunications systems.
- The analysis for es-python, es-c, es-cpp, es-rust, es-node, es-solidity, es-bash and es-php is straightforward: they observe the customer's own server-side programs and contracts, not natural persons.
- es-chromium requires a closer look, and this memo records that it has been given one. A browser that reports the pages visited and the values present in them is, on its face, capable of monitoring the activity of natural persons. Three things distinguish it from a controlled cyber-surveillance item: it is installed openly, by the operator of the machine, on the operator's own managed device, not covertly on a target's device; it reports only to the operator's own dashboard, with no third-party collection capability; and it is sold for, and contractually restricted to, the operator's own authorized systems.
- Those distinctions are contractual as well as factual. Section 7 of the Terms
(
/legal/terms) requires authorized deployments, notice and consent, and forbids covert and consumer deployment; Section 2 of the AUP (/legal/aup) repeats those as use restrictions; and Section 4 of the AUP expressly forbids use of the Service, and es-chromium in particular, as part of any programme of covert surveillance of natural persons. - Operational commitment: because the Article 5 catch-all is end-user and end-use dependent rather than item dependent, an es-chromium sale is assessed case by case where the prospective customer is a government, law-enforcement, intelligence or defence body, or where there is any indication the product would be used against individuals rather than to secure the customer's own systems. Where a licence would be required, no supply is made until it is held.
3.3 Wassenaar and other regimes
The same "intrusion software" definitions appear in the Wassenaar Arrangement lists as implemented by Israel, the EU and the UK; the analysis above applies equally. The products' instrumentation and fuzzing are constrained by design and by the AUP to the customer's own authorized environment.
4. Israel export-control position
- Israel's Order of Control of Commodities and Services (Engagement in Encryption Items), 5734-1974 ("the 1974 Encryption Order") was revoked. The revocation was signed on 18 November 2025 and took effect on 21 March 2026, and is therefore now in force.
- The practical consequence is not blanket decontrol. Domestic engagement (development and sale) in most commercial encryption is decontrolled, but the export of many commercial (B2B) encryption products now falls to be assessed under the dual-use export-control regime administered by DECA (Defense Export Controls Agency, Ministry of Defense) or the Export Control Agency (ECA) at the Ministry of Economy and Industry, principally in respect of Wassenaar Category 5, Part 2 items. EyalSec sells B2B, so this is the operative regime, not the decontrol.
- Licences previously granted under the 1974 Encryption Order for non-Wassenaar items, and licences for engagement other than export, were revoked on 21 March 2026. DECA published implementation and training material on 19 March 2026.
- Action required and tracked: confirm the classification of each agent under the current regime with DECA/ECA, and confirm reliance on the mass-market and decontrol notes in Category 5 Part 2, before or alongside export activity. This memo is a self-assessment and is not a substitute for that confirmation.
- A draft "Law for the Regulation of Foreign Trade: Control of Civil Dual-Use and CBRN Exports, 5786-2026" was published on 26 March 2026 for public comment. If enacted it would add a catch-all for non-controlled items, extend licensing to brokering, transshipment and technical assistance, and introduce administrative and criminal sanctions including personal liability for officers. It is monitored; it is not yet law.
5. Compliance commitments
EyalSec commits to:
- Denied-party and sanctions screening of customers against the applicable lists (US SDN / Entity / Denied Persons, EU and UK consolidated lists, and Israeli equivalents) before and during the customer relationship.
- Blocking comprehensively embargoed destinations (currently Iran, North Korea, Cuba,
Syria, and the sanctioned regions of Ukraine) at signup and in the AUP (
/legal/aup). - Case-by-case end-use and end-user review for es-chromium as described in Section 3.2.
- Including export and sanctions representations in the Terms (Section 19) and the AUP.
- Re-classifying each agent separately if its functionality materially changes, in particular if any agent gains the ability to act against, or collect from, a system other than the customer's own.
- Keeping a record of classifications, screening results and any licence determinations.
6. Trademark notes
- "Python" and the Python logos are trademarks of the Python Software Foundation
(PSF). Used nominatively to identify the underlying interpreter; no endorsement or
affiliation is implied. The product name "es-python" should be cleared with the
PSF (
psf-trademarks@python.org). - "Chromium", "Chrome", "Google" and the associated logos are trademarks of Google LLC. The Chromium open-source project's code is BSD-licensed, but Google's marks are not. Used here nominatively to identify the underlying open-source project; no endorsement or affiliation is implied. es-chromium must never be presented, named or branded as Google Chrome or as a Google product, and it carries EyalSec branding rather than Chromium's. Clearance of the product name "es-chromium" should be confirmed.
- "LLVM" and "Clang" are trademarks of the LLVM Foundation; "Rust" and "Cargo" of the Rust Foundation; "Node.js" of the OpenJS Foundation. Each is used nominatively to identify the underlying project; no endorsement or affiliation is implied. Clearance of the product names "es-c", "es-cpp", "es-rust", "es-node" and "es-solidity" should be confirmed, in the Rust Foundation's case against its published trademark policy.
- "OpenSSL" is a trademark of the OpenSSL Software Foundation / OpenSSL project; used descriptively, no endorsement implied.
- "EyalSec", "es2" and the es- agent names: availability and registration in target markets (Israel, EU/EUIPO, US/USPTO, UK) should be searched and, if desired, registered. Until registered, the marks are unregistered and protection is limited.
This is EyalSec's good-faith export-control self-classification, reviewed periodically. It is informational, is not legal advice, and is not a government determination. Customers remain responsible for their own compliance under Section 19 of the Terms.