legal

Export & Trademark Notice

Last updated: 2026-08-27. Governing law: Israel.

Export-Control Self-Classification Memo & Trademark Notes

This memo records the good-faith internal self-classification, for export-control purposes, of the EyalSec / es2 Service and of every EyalSec agent: es-python, es-chromium, es-c, es-cpp, es-rust, es-node and es-solidity, es-bash and es-php. It also records trademark clearance items. It is reviewed periodically and updated as the Service evolves.

Published by Eyal Gabay, trading as "EyalSec", sole proprietor (osek murshe) no. 211868450, of Yehoshua Stampfer 39, Petah Tikva, Israel.

Scope. This memo covers the es2 server and every agent. An earlier version classified es-python only and expressly excluded es-chromium; that exclusion is withdrawn and replaced by the analysis below.

1. Products described (for classification)

| Item | What it is | What it does | |------|------------|--------------| | es2 server | A hosted web service | Receives, stores and displays security events reported by the agents | | es-python | A Python runtime, derived from CPython 3.9 through 3.14, that customers install on their own authorized machines | Marks untrusted data, reports when it reaches a dangerous operation, and can exercise its own process inputs | | es-chromium | A web browser, derived from the Chromium open-source project, that customers install on their own managed machines | Reports when untrusted data reaches a dangerous operation inside a web page, and reports installed extensions | | es-c / es-cpp | Compiler plugins, runtime libraries and driver scripts that load into the compiler already installed on the customer's own machine | Programs built with them report the same class of flows at runtime | | es-rust | A Rust language distribution, derived from the Rust open-source toolchain | Programs built with it report the same class of flows at runtime | | es-node | A JavaScript runtime, derived from the Node.js open-source project. Not currently distributed. | Services run under it report the same class of flows | | es-solidity | A Solidity compiler, derived from the Solidity open-source compiler. Not currently distributed. Development builds only, never for a public network. | Contracts compiled with it report the same class of flows in test | | es-bash | A command shell, derived from GNU Bash. No binary is distributed at all: what is delivered is source, which the customer's own machine compiles. A delivery surface now exists and the product is grantable; the first-export re-check required below has not yet been performed. | Shell scripts run under it report the same class of flows | | es-php | A PHP runtime, derived from the PHP open-source project, that customers install on their own authorized servers. Not currently distributed. | Web applications served by it report the same class of flows |

All of them are defensive security-monitoring tools. They run inside the customer's own authorized environment, observe that environment, and report to the customer's own dashboard. They do not attack, command, exploit, or deliver payloads to third-party systems.

Distribution status matters to this memo. es-python, es-chromium, es-c, es-cpp and es-rust are published and delivered to customers. es-node, es-solidity and es-php exist as products in the dashboard but no artifact for them is served to customers at the date of this memo; each must be re-checked against this memo before it is first exported.

es-php is a customer-visible product whose artifact is not yet served, and the two facts are separable: an account can hold the es-php entitlement and see es-php findings without any artifact having crossed a border. The first export is the publication of a build, not the sale of the entitlement, and that is the event this memo must be re-checked against.

es-bash changed status on 2026-08-27 and its re-check is OUTSTANDING. It is now a grantable product with a working delivery surface (a per-host install script and a secret-gated download of the source bundle), deployed to the internal test environment. No customer has received it yet, because the production environment has not been updated. The re-check this memo requires before a first export has not been performed, and nothing in this update performs it: this paragraph records that the trigger condition has arrived, so that the re-check happens before the production deploy rather than after it.

es-bash is a distinct case and is called out because the distinction matters to this memo. For every other agent, what would cross a border is a compiled binary. For es-bash it is source code, compiled by the recipient on the recipient's own machine. Publicly available source, and source that is already public, are treated differently from object code under several of the regimes below, so the analysis for es-bash must not be inherited wholesale from the other rows.

2. Cryptography classification

This applies to every agent listed in Section 1 and to the server.

3. "Intrusion software" and cyber-tools axis

3.1 US EAR (ECCNs 4A005 / 4D004 / 4E001)

These control items for the generation, command-and-control, or delivery of "intrusion software" to a third party's system, and for the extraction of data by it.

Accordingly these ECCNs should not apply, absent misuse contrary to the AUP.

3.2 EU Regulation (EU) 2021/821, Article 5 cyber-surveillance catch-all

Article 5 targets items that could be used for covert surveillance of natural persons by monitoring, extracting, collecting or analysing data from information and telecommunications systems.

3.3 Wassenaar and other regimes

The same "intrusion software" definitions appear in the Wassenaar Arrangement lists as implemented by Israel, the EU and the UK; the analysis above applies equally. The products' instrumentation and fuzzing are constrained by design and by the AUP to the customer's own authorized environment.

4. Israel export-control position

5. Compliance commitments

EyalSec commits to:

6. Trademark notes


This is EyalSec's good-faith export-control self-classification, reviewed periodically. It is informational, is not legal advice, and is not a government determination. Customers remain responsible for their own compliance under Section 19 of the Terms.

EyalSec Pricing Docs Security Login Book a live demo