Ethical Export Policy

Software from Netresec is not subject to national export control. However, we acknowledge that our software could potentially be used by repressive regimes to spy on their own citizens. We have therefore created this Ethical Export Policy, which aims at preventing repressive regimes from obtaining our software. In short, we practice “know your customer” (as recommended by EFF) and strictly deny sales to the countries on the “Export BlackList” below.

Export BlackList

Country EU UN Reporters
Without
Borders
Freedom
House
WGI Netresec's Shit List
Afghanistan EU UN
Angola -1.10
Azerbaijan FH 26 -1.56
Bahrain RWB FH 34 -1.39
Bangladesh FH 25
Belarus EU RWB FH 29 -1.36
Burundi -1.57
Cambodia FH 26 -1.16
Cameroon -1.05
Central African Republic EU UN -1.11
Chad -1.37
China [1] EU RWB FH 40 -1.50 MITM of GitHub, Google, Yahoo, iCloud and outlook.com
Democratic Republic of the Congo EU UN -1.44
Republic of the Congo -1.12
Cuba RWB FH 33 -1.55
Djibouti -1.41
Egypt EU FH 35 -1.25
Equatorial Guinea -1.97
Eritrea EU UN -2.17
Ethiopia FH 31 -1.44
Gabon -1.05
Gambia FH 25
Iran EU UN RWB FH 36 -1.30
Iraq EU UN -1.05
Kazakhstan FH 26 -1.23 Nationwide SSL MITM
Laos / Lao DPR -1.75
Lebanon EU UN
Libya EU UN -1.44
Myanmar / Burma EU RWB FH 30
North Korea EU UN RWB -2.20
Oman -1.06
Pakistan FH 33
Qatar -1.18
Russia EU FH 31 -1.09
Rwanda -1.12
Saudi Arabia RWB FH 34 -1.68
Somalia EU UN -1.78
South Sudan EU UN -1.82
Sudan EU UN FH 29 -1.83
Swaziland -1.43
Syria EU RWB FH 37 -1.97
Tajikistan -1.72
Thailand FH 32 -1.05
Turkey FH 30
Turkmenistan RWB -2.16
United Arab Emirates FH 33 -1.10
Uzbekistan RWB FH 31 -1.80
Venezuela EU FH 27 -1.21
Vietnam RWB FH 35 -1.40
West Bank and Gaza -1.03
Yemen EU UN -1.69
Zimbabwe EU FH 25 -1.20

[1] Excluding Special Administrative Regions Hong Kong and Macau

Sources

We rely on several different sources in our assessment regarding what countries to put on our Export Blacklist.

European Union (EU)
The European Union’s Restrictive measures (sanctions) in force presents a list of countries for which EU require restrictive measures in economic or financial relations. All countries with an arms embargo or "ban on exports of equipment for internal repression" are put on our Export BlackList.
(EU list updated November 2018 based on ISP)

United Nations Security Council (UN)
The UN Security Council impose sanctions and/or more targeted measures such as arms embargoes, travel bans, financial or diplomatic restrictions. All countries with UN arms embargoes are put on our Export BlackList.
(UN list updated November 2018 based on ISP)

Reporters Without Borders
Reporters Without Borders is a non-profit organisation, with consultant status at the United Nations and UNESCO, that continuously monitor attacks on freedom of information worldwide. Reporters Without Borders compile a data set called "Enemies of the Internet" (2012), which is a list of countries whose governments are using technology that monitors online activity and intercepts electronic communication in order to arrest journalists, citizen-journalists and dissidents. All countries on this list are added to our Export BlackList.

Freedom House
Freedom House is an independent watchdog organization that speaks out against the main threats to democracy and empowers citizens to exercise their fundamental rights. Freedom House produces a yearly report called Freedom on the Net (November 2018), which evaluates the degree of internet freedom around the world based on barriers to access, limits on content, and violations of user rights. All countries with a score of at least 25 (out of 40) in the “Violations of User Rights” category in this study are added to our Export Blacklist. The numbers appearing in the Freedom House column of our BlackList is the “Violations of User Rights” score for each respective country.

The Worldwide Governance Indicators (WGI)
The Worldwide Governance Indicators (WGI) is a research dataset summarizing the views on the quality of governance provided by a large number of enterprise, citizen and expert survey respondents in industrial and developing countries. These data are gathered from a number of survey institutes, think tanks, non-governmental organizations, international organizations, and private sector firms. Countries with a governance estimate below -1.00 in the “Voice and Accountability” category of the most recent WGI (September 2018) are added to our Export Blacklist. The “Voice and Accountability” value reflects perceptions of the extent to which a country's citizens are able to participate in selecting their government, as well as freedom of expression, freedom of association, and a free media.

Netresec's Shit List
We at netresec maintain an additional list of countries that we for various reasons do not sell our software to.