Sanctions Policy
Compliance with U.S. and international sanctions regimes.
DOCUMENT
CS-06
OWNER
Chief Compliance Officer
EFFECTIVE
January 1, 2026
REVIEWED
April 1, 2026
Purpose
Alexa Cybersecurity, as a U.S. legal entity, is bound by U.S. economic sanctions administered by the Office of Foreign Assets Control (OFAC) of the U.S. Department of the Treasury, as well as the export controls of the U.S. Department of Commerce (BIS) and U.S. Department of State (DDTC).
This Policy establishes the screening, blocking, and reporting controls that ensure compliance.
Prohibited activities
- 01Providing services or technology to any individual or entity on the OFAC Specially Designated Nationals (SDN) list.
- 02Providing services to comprehensively sanctioned jurisdictions including (but not limited to) Cuba, Iran, North Korea, Syria, the Crimea region of Ukraine, the so-called DNR/LNR regions, and any other jurisdiction designated by OFAC.
- 03Facilitating transactions that would be prohibited if conducted directly by a U.S. person.
- 04Re-exporting controlled cybersecurity items, including intrusion software (per EAR §740.22), to restricted destinations or end-uses without proper authorization.
Screening controls
All counterparties — clients, vendors, distributors, subcontractors, and individual users — are screened against consolidated sanctions lists at onboarding and on an ongoing basis. The screening covers SDN, OFAC sectoral sanctions, EU consolidated lists, UK HMT, UN Security Council, and the U.S. Entity List.
Positive matches trigger immediate hold of the transaction, escalation to the Chief Compliance Officer, and (where applicable) a blocked-property report to OFAC within 10 business days.
Cybersecurity-specific controls
- 01Export-controlled cybersecurity items are not licensed, sold, or remotely operated by users in restricted jurisdictions.
- 02Telemetry pipelines reject ingestion from IPs geo-located in comprehensively sanctioned jurisdictions.
- 03Software updates and license renewals are gated by re-screening at the point of delivery.
Training and audit
All sales, customer-success, and procurement personnel complete sanctions training annually. The control environment is audited annually by an independent third party and the results are presented to the Board.
/CONTROLLED_DOCUMENT
This document is the official, controlled version of CS-06 — Sanctions Policy. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.
VERSION
2026.1
REVIEWED
April 1, 2026
NEXT REVIEW
Quarterly


