Back to Corporate Standards
CS-06 · Corporate Standards

Sanctions Policy

Compliance with U.S. and international sanctions regimes.

DOCUMENT

CS-06

OWNER

Chief Compliance Officer

EFFECTIVE

January 1, 2026

REVIEWED

April 1, 2026

Class · PUBLIC·Review cycle · Quarterly

Purpose

Alexa Cybersecurity, as a U.S. legal entity, is bound by U.S. economic sanctions administered by the Office of Foreign Assets Control (OFAC) of the U.S. Department of the Treasury, as well as the export controls of the U.S. Department of Commerce (BIS) and U.S. Department of State (DDTC).

This Policy establishes the screening, blocking, and reporting controls that ensure compliance.

Prohibited activities

  • 01Providing services or technology to any individual or entity on the OFAC Specially Designated Nationals (SDN) list.
  • 02Providing services to comprehensively sanctioned jurisdictions including (but not limited to) Cuba, Iran, North Korea, Syria, the Crimea region of Ukraine, the so-called DNR/LNR regions, and any other jurisdiction designated by OFAC.
  • 03Facilitating transactions that would be prohibited if conducted directly by a U.S. person.
  • 04Re-exporting controlled cybersecurity items, including intrusion software (per EAR §740.22), to restricted destinations or end-uses without proper authorization.

Screening controls

All counterparties — clients, vendors, distributors, subcontractors, and individual users — are screened against consolidated sanctions lists at onboarding and on an ongoing basis. The screening covers SDN, OFAC sectoral sanctions, EU consolidated lists, UK HMT, UN Security Council, and the U.S. Entity List.

Positive matches trigger immediate hold of the transaction, escalation to the Chief Compliance Officer, and (where applicable) a blocked-property report to OFAC within 10 business days.

Cybersecurity-specific controls

  • 01Export-controlled cybersecurity items are not licensed, sold, or remotely operated by users in restricted jurisdictions.
  • 02Telemetry pipelines reject ingestion from IPs geo-located in comprehensively sanctioned jurisdictions.
  • 03Software updates and license renewals are gated by re-screening at the point of delivery.

Training and audit

All sales, customer-success, and procurement personnel complete sanctions training annually. The control environment is audited annually by an independent third party and the results are presented to the Board.

/CONTROLLED_DOCUMENT

This document is the official, controlled version of CS-06 — Sanctions Policy. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

April 1, 2026

NEXT REVIEW

Quarterly