Legal
Trade Compliance Policy
iFrame Corporation · 101 Jefferson Dr, Menlo Park, CA 94025 · www.iframe.ai. This Trade Compliance Policy (Export Controls, Sanctions, and End-Use / End-User Screening) is an external-facing, public document. It is binding on all iFrame personnel and, through the flow-down and contractual provisions in Sections 20–21, on iFrame’s customers, resellers, agents, brokers, and suppliers. Sections 6–19 govern internal operations; Sections 20–21 state the obligations iFrame imposes on its counterparties.
Last updated · Version 1.0 · Prepared July 2, 2026
Document control
| Document title | Trade Compliance Policy (Export Controls, Sanctions, and End-Use / End-User Screening) |
| Version | 1.0 |
| Prepared | July 2, 2026 |
| Effective date | Date of signature (see Section 24) |
| Document owner | Export Compliance Officer (ECO), iFrame Corporation |
| Classification | Public — External-facing; binding on personnel, customers, resellers, brokers, and suppliers |
| Next scheduled review | Annually, or upon material change in applicable law |
1. Purpose
iFrame Corporation (“iFrame,” “we,” or “the Company”) designs, builds, and operates high-performance GPU and AI compute infrastructure, and delivers access to that infrastructure as a service (“iFrame Services”). iFrame’s platform is built on advanced graphics processing units and AI accelerators (including NVIDIA HGX B300-class GPUs), high-speed interconnect, and associated software and technology, all of which are subject to stringent national and international trade controls.
This Policy establishes iFrame’s binding commitment to conduct all activities in full compliance with applicable export control, economic sanctions, and end-use / end-user control laws. It sets out the rules, roles, and procedures that govern how iFrame acquires, deploys, and provides access to controlled hardware, software, technology, and compute capacity, and the obligations iFrame imposes on those who transact with it.
2. Policy statement
It is the policy of iFrame to comply fully with all export control, sanctions, and trade laws applicable to its business, and to require the same of its customers, resellers, brokers, and suppliers. iFrame will not export, reexport, transfer (in-country), or otherwise provide access to controlled items, technology, software, or compute capacity — whether physically or through remote access to iFrame Services — in violation of applicable law or this Policy.
iFrame will not transact with, or provide iFrame Services to, any party or destination when doing so would violate applicable trade controls, and will not knowingly facilitate any transaction structured to evade such controls. Where any provision of this Policy conflicts with applicable law, the more restrictive requirement governs.
3. Scope and applicability
This Policy applies to:
- All personnel — directors, officers, employees, temporary staff, interns, and individual contractors of iFrame worldwide, regardless of role or location;
- All iFrame operations — procurement, engineering, provisioning, sales, customer onboarding, service delivery, support, logistics, and disposal;
- All items — hardware, components, software, technology, technical data, and compute capacity that iFrame acquires, integrates, operates, or makes available; and
- All counterparties— customers, prospective customers, end users, resellers, distributors, sales agents, brokers, freight forwarders, integrators, and suppliers, to the extent set out in Sections 20–21 and in their agreements with iFrame.
This Policy applies to physical transfers of items and to the provision of Infrastructure-as-a-Service (“IaaS”) and Platform-as-a-Service, including remote access to compute, regardless of the physical location of the user.
4. Definitions
For purposes of this Policy:
- BIS — the U.S. Department of Commerce, Bureau of Industry and Security.
- CCL — the Commerce Control List (Supplement No. 1 to Part 774 of the EAR).
- Controlled Item — any hardware, software, technology, technical data, or service that is subject to the EAR, ITAR, EU Dual-Use Regulation, or other applicable export control law, including advanced computing integrated circuits and systems (see Section 7).
- Deemed Export / Deemed Reexport — the release of controlled technology or source code to a foreign national, which is treated as an export to that person’s country of most recent citizenship or permanent residency.
- EAR — the U.S. Export Administration Regulations, 15 C.F.R. Parts 730–774, as administered by BIS and amended from time to time.
- ECCN — Export Control Classification Number, the classification assigned to an item on the CCL.
- End User — the party that ultimately receives and uses an item or the benefit of iFrame Services.
- End Use — the purpose for which an item or service is ultimately used.
- Entity List — the list of parties subject to specific license requirements (Supplement No. 4 to Part 744 of the EAR).
- EU Dual-Use Regulation — Regulation (EU) 2021/821 setting up an EU regime for the control of exports, brokering, technical assistance, transit, and transfer of dual-use items.
- ITAR — the U.S. International Traffic in Arms Regulations, 22 C.F.R. Parts 120–130, administered by the U.S. Department of State.
- OFAC — the U.S. Department of the Treasury, Office of Foreign Assets Control.
- Reexport — the shipment or transmission of an item subject to the EAR from one foreign country to another, or the release of technology or software to a foreign national outside the United States.
- Restricted Party — any person or entity that appears on a Restricted Party List (Section 9) or is owned or controlled by, or acting on behalf of, such a person or entity.
- SDN List — OFAC’s list of Specially Designated Nationals and Blocked Persons.
- Transfer (in-country) — a change in end use or end user of an item within the same foreign country.
5. Governing legal framework
iFrame’s business is subject to the following bodies of law, each as amended, superseded, or replaced from time to time. This Policy is to be interpreted and applied consistently with the current text of each:
5.1 United States export controls.
- The Export Administration Regulations (EAR), 15 C.F.R. Parts 730–774, administered by BIS, including the Commerce Control List, the end-use and end-user controls of Part 744, the license exceptions of Part 740, the country groups of Supplement No. 1 to Part 740, and the “Know Your Customer” guidance and red flags of Supplement No. 3 to Part 732.
- The advanced computing and semiconductor controls applicable to AI accelerators, GPUs, and the systems, software, and technology that support them (see Section 7).
- The International Traffic in Arms Regulations (ITAR), 22 C.F.R. Parts 120–130, to the extent any defense article, defense service, or technical data is implicated. iFrame’s standard commercial infrastructure is not designed for ITAR-controlled activity, and iFrame does not knowingly provide iFrame Services for ITAR-controlled purposes without prior authorization.
5.2 United States economic sanctions.
- The economic sanctions programs administered by OFAC under 31 C.F.R. Chapter V, including comprehensive country programs, list-based programs, and sectoral sanctions, together with the SDN List, the Consolidated Sanctions List, and OFAC’s 50 Percent Rule (entities owned 50% or more, in the aggregate, by one or more blocked persons are themselves blocked).
5.3 European Union export controls.
- The EU Dual-Use Regulation (EU) 2021/821, including its control lists (Annex I), Union General Export Authorisations (Annex II), the list of items subject to the intra-EU transfer controls (Annex IV), brokering and technical assistance controls, and catch-all provisions, together with the export control laws of any EU Member State from which iFrame or its counterparties operate.
5.4 Other applicable regimes.
- Applicable export control, sanctions, and anti-boycott laws of the United Kingdom, and of any other jurisdiction in which iFrame maintains operations, sources equipment, or delivers iFrame Services.
- The multilateral export control arrangements on which these national regimes are based, including the Wassenaar Arrangement, the Missile Technology Control Regime, the Nuclear Suppliers Group, and the Australia Group.
Because the rules governing advanced computing are subject to frequent amendment, iFrame maintains its compliance program against the current textof each regulation. References in this Policy to specific rules, classifications, and lists are illustrative of iFrame’s obligations and do not limit iFrame’s duty to comply with the law as then in effect.
6. Roles and responsibilities
6.1 Board and executive management. iFrame’s executive management is responsible for setting the tone of compliance, approving this Policy, providing adequate resources for the trade compliance program, and holding the organization accountable for adherence.
6.2 Export Compliance Officer (ECO). iFrame designates an Export Compliance Officer with authority and independence to administer this Policy. The ECO is responsible for: maintaining the compliance program and procedures; overseeing product and technology classification (Section 7); administering restricted-party screening (Section 9) and end-use / end-user review (Sections 10–11); making licensing and hold/release determinations; approving or escalating exceptions; conducting training (Section 17); maintaining records (Section 15); investigating potential violations (Section 16); and interfacing with regulators and outside counsel. The ECO has authority to halt any transaction, onboarding, provisioning action, or shipment pending compliance review.
6.3 Functional owners. Procurement, engineering/operations, sales, customer onboarding, support, and logistics leads are each responsible for implementing this Policy within their function, escalating red flags to the ECO, and not proceeding with any transaction that has not cleared required screening and review.
6.4 All personnel. Every individual within scope is responsible for understanding and complying with this Policy, completing required training, recognizing and reporting red flags, and never circumventing a compliance control. Compliance is a condition of employment or engagement.
7. Classification of items, technology, and services
iFrame classifies all hardware, software, technology, and services it acquires or provides, and records the classification, so that applicable controls can be correctly applied.
7.1 Advanced computing hardware. iFrame’s infrastructure incorporates advanced AI accelerators and the systems that house them. The GPUs, accelerator modules, and integrated systems iFrame deploys — including NVIDIA HGX B300-class GPUs and the 8-GPU compute nodes built around them, associated high-bandwidth memory, and high-speed network adapters and DPUs — fall within the U.S. controls on advanced computing. Depending on their performance characteristics and configuration, these items are classified under ECCNs in the 3A090 / 4A090 families (advanced integrated circuits and computers/systems incorporating them), together with related software and technology classifications (e.g., the 3D090 / 3E090 / 4D090 / 4E090 families) and controls on high-bandwidth memory. The ECO maintains a current classification matrix for iFrame’s hardware, software, and technology, and updates it as products, configurations, and regulations change.
7.2 Compute capacity and remote access. iFrame treats the provision of access to controlled compute — whether by physical delivery or by remote access to iFrame Services — as an activity that may trigger export control and sanctions obligations. The location of the user, the identity of the customer and end user, and the intended end use each factor into iFrame’s compliance determinations under Sections 9–12.
7.3 Encryption. iFrame’s platform and software may incorporate encryption functionality subject to the encryption controls of the EAR (Category 5, Part 2) and analogous regimes. The ECO ensures that any required classification, self-classification reporting, or notification obligations for encryption items are met.
8. Country and destination controls
8.1 Prohibited destinations. iFrame will not export, reexport, transfer, or provide access to iFrame Services in or to any jurisdiction subject to comprehensive U.S. sanctions or embargo, which as of the date of this Policy include Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine, and any other territory that becomes comprehensively sanctioned. Access to iFrame Services from these destinations is prohibited.
8.2 Restricted destinations and licensing. Certain destinations are subject to license requirements for advanced computing items and related technology under the EAR country-group framework (Supplement No. 1 to Part 740), including the national-security-controlled group D:1, the missile-technology group D:4, and the U.S. arms-embargoed group D:5, as well as destinations subject to enhanced controls on advanced computing. iFrame will not export, reexport, transfer, or provide access to Controlled Items to or in such destinations without first confirming that the transaction is authorized by license, license exception, or other applicable authorization, or is otherwise permitted under the current regulations.
8.3 Geolocation and access controls. iFrame implements technical controls to identify the geographic origin of access to iFrame Services and to restrict access from prohibited destinations. Customers must not access, or permit access to, iFrame Services from any prohibited destination, and must not use anonymization, proxy, or other techniques to obscure the location of access in a manner designed to evade these controls (see Section 20).
9. Restricted party screening
9.1 Screening obligation. iFrame screens all counterparties — customers, prospective customers, end users, resellers, distributors, agents, brokers, freight forwarders, and suppliers, and, where appropriate, their principals, beneficial owners, and authorized users — against applicable Restricted Party Lists before onboarding or transacting, and on an ongoing basis thereafter for the duration of the relationship.
9.2 Restricted Party Lists. Screening covers, at minimum:
- OFAC’s SDN List and Consolidated Sanctions List, applying the 50 Percent Rule;
- The BIS Entity List (Supplement No. 4 to Part 744), Denied Persons List, Unverified List (Supplement No. 6 to Part 744), and Military End User (MEU) List (Supplement No. 7 to Part 744);
- The U.S. State Department’s Debarred List (ITAR);
- The EU Consolidated List of persons, groups, and entities subject to EU financial sanctions, and applicable Member-State lists; and
- Analogous lists maintained by other jurisdictions in which iFrame operates (e.g., the UK sanctions list).
9.3 Match handling. Any confirmed or probable match is escalated to the ECO. iFrame will not transact with, provide iFrame Services to, or continue an existing relationship with any Restricted Party absent a determination by the ECO — with outside counsel where appropriate — that the transaction is lawful and authorized. Positive matches identified during an active relationship result in suspension of service pending review.
9.4 Rescreening. iFrame rescreens counterparties periodically and upon any change to the applicable lists, and re-runs screening at appropriate lifecycle events (e.g., contract renewal, change in beneficial ownership, addition of authorized users).
10. End-use and end-user controls
10.1 Prohibited end uses. iFrame will not knowingly provide Controlled Items or iFrame Services, and prohibits their use, for any end use restricted under Part 744 of the EAR or analogous law, including:
- the design, development, production, or use of nuclear, chemical, or biological weapons or missiles capable of delivering such weapons;
- prohibited military, military-intelligence, or weapons-of-mass-destruction end uses in restricted destinations;
- the operation, installation, maintenance, or use of items in support of a restricted “advanced computing” or “supercomputer” end use where prohibited; and
- any other end use that is prohibited, or that requires a license that has not been obtained.
10.2 Prohibited applications. iFrame separately prohibits the use of iFrame Services for unlawful or abusive purposes as set out in its Acceptable Use Policy, including uses that facilitate human rights abuses, unlawful surveillance, or malicious cyber-enabled activity.
10.3 End-user verification. iFrame takes reasonable steps to know its customers and the end users of its services, to verify their identity and legitimacy, and to confirm that the intended end use is lawful, before providing access to Controlled Items or iFrame Services.
11. Know Your Customer (KYC) and customer due diligence
11.1 KYC program. Because iFrame provides advanced compute capacity as a service, it maintains a Know Your Customer program consistent with the BIS “Know Your Customer” guidance and red flags (Supplement No. 3 to Part 732), with the customer-identification expectations applicable to IaaS providers, including those arising under Executive Order 13984 and its implementing rules, and with sound sanctions due-diligence practice.
11.2 Customer identification. Before granting access to iFrame Services, iFrame collects and verifies information sufficient to establish the identity of the customer and, where relevant, its beneficial owners and authorized users, including legal name, address, country of organization and operation, and the nature of the intended use. iFrame retains this information in accordance with Section 15.
11.3 Red flags. iFrame trains personnel to recognize and escalate red flags, including but not limited to: reluctance to provide end-use or end-user information; requests to route access or delivery through unusual intermediaries or jurisdictions; a customer or end use that does not fit the customer’s line of business; requests to disable, evade, or obscure geolocation or logging controls; payment or ownership structures designed to obscure the true party in interest; and indications that a party may be acting on behalf of a Restricted Party or a restricted destination. Unresolved red flags must be escalated to the ECO and may not be “self-cleared” by the transacting function.
11.4 Large compute / training-run awareness. iFrame monitors for, and applies enhanced diligence to, uses of iFrame Services that could implicate reporting or heightened-control obligations for large-scale AI compute (for example, arrangements that could enable a foreign person to conduct a large AI training run of potential concern), and applies the reporting and control measures required by applicable law as then in effect.
12. Remote access, deemed exports, and anti-diversion
12.1 Deemed exports. The release of controlled technology or source code to a foreign national — whether in the United States or abroad, and whether in person or through access to systems — may constitute a deemed export or deemed reexport requiring authorization. iFrame controls access to controlled technology and source code accordingly, and obtains any required authorization before releasing controlled technology to a foreign national.
12.2 Anti-diversion. iFrame prohibits, and contractually requires its counterparties to prohibit, any diversion of Controlled Items or iFrame Services to unauthorized end users, end uses, or destinations. iFrame includes a destination control / anti-diversion statement in relevant documentation and requires the flow-down obligations of Sections 20–21.
12.3 Transshipment and reexport. iFrame does not participate in, and prohibits its counterparties from participating in, transactions structured to transship or reexport Controlled Items in evasion of applicable controls.
13. Licenses, authorizations, and exceptions
13.1 Determination. The ECO determines whether a proposed transaction requires a license or other authorization, or qualifies for a license exception or exception equivalent, based on the item’s classification, the destination, the end user, and the end use.
13.2 No transaction without authorization. Where a license or authorization is required, iFrame will not proceed until the required authorization is obtained and its conditions are satisfied. iFrame complies with all conditions, provisos, and reporting requirements attached to any license or authorization.
13.3 Exceptions to this Policy. Any exception to the procedures of this Policy requires the prior written approval of the ECO, is documented with the supporting rationale, and does not authorize any departure from applicable law.
14. Recordkeeping and audit
14.1 Recordkeeping. iFrame creates and retains records of its export-controlled and sanctions-relevant transactions and compliance activities — including classifications, screening results and resolutions, KYC information, end-use / end-user documentation, licenses and authorizations, and hold/release decisions — for the period required by applicable law (generally at least five years under the EAR from the date of the transaction or expiration of any license, or longer where required), and in a form that is retrievable and auditable.
14.2 Audit and monitoring. iFrame periodically audits and tests its trade compliance controls, tracks metrics, and remediates deficiencies. The ECO reports to executive management on the state of the program and on any significant issues.
15. Reporting violations and non-retaliation
15.1 Duty to report. Any person who becomes aware of an actual or potential violation of this Policy or of applicable trade law must report it promptly to the ECO. External parties may report concerns to compliance@iframe.ai.
15.2 Investigation and disclosure. iFrame investigates reported concerns, takes corrective action, and, where appropriate and in consultation with counsel, makes voluntary self-disclosures to the relevant authorities.
15.3 Non-retaliation. iFrame prohibits retaliation against any person who reports a concern in good faith or who cooperates in an investigation.
16. Training and awareness
iFrame provides trade compliance training to personnel commensurate with their roles — including onboarding training and periodic refresher training for personnel in procurement, engineering/operations, sales, onboarding, support, and logistics — and maintains records of completion. Training covers classification, screening, end-use / end-user controls, KYC, red flags, recordkeeping, and escalation.
17. Enforcement and consequences
17.1 Internal. Violation of this Policy may result in disciplinary action up to and including termination of employment or engagement, in addition to any legal consequences.
17.2 Legal. Violations of export control and sanctions laws can result in severe civil and criminal penalties for both the Company and responsible individuals, including substantial fines, denial of export privileges, and imprisonment. iFrame takes these obligations seriously and enforces this Policy accordingly.
17.3 Counterparties. Breach of the obligations in Sections 20–21 is a material breach of the counterparty’s agreement with iFrame and may result in suspension or termination of service, cancellation of orders, and other remedies available at law or under contract.
18. Suspension and termination of service
iFrame reserves the right to suspend or terminate access to iFrame Services, decline or cancel any order, or refuse any transaction, immediately and without liability, where iFrame determines in good faith that continuing would violate, or create a material risk of violating, applicable trade law or this Policy, or where a counterparty fails to provide information reasonably required for compliance.
19. Interaction with other iFrame policies
This Policy operates together with iFrame’s Acceptable Use Policy, its Security Protocols for As-a-Service Delivery, its data protection and privacy policies, and its customer and supplier agreements. Where trade compliance requirements are more restrictive, they govern. Technical access, logging, and isolation controls that support this Policy are described in iFrame’s Security Protocols for As-a-Service Delivery.
20. Obligations of customers, end users, resellers, and brokers
As a condition of purchasing, reselling, brokering, or accessing iFrame Services or Controlled Items, each customer, end user, reseller, distributor, agent, and broker (“Counterparty”) represents, warrants, and covenants that it will:
20.1 Comply with law. Comply with all applicable export control, sanctions, and trade laws, including the EAR, OFAC-administered sanctions, the EU Dual-Use Regulation, and the laws of all jurisdictions in which it operates or from which it accesses iFrame Services.
20.2 Not be a Restricted Party. Not be, and not be owned or controlled by or acting on behalf of, any Restricted Party or any party located in or ordinarily resident in a prohibited destination; and promptly notify iFrame if this ceases to be true.
20.3 Observe destination restrictions. Not export, reexport, transfer, or provide access to iFrame Services or Controlled Items, and not access iFrame Services, in or to any prohibited destination, or in or to any restricted destination absent required authorization; and not use anonymization, proxy, relocation, or other techniques to evade iFrame’s geolocation or access controls.
20.4 Observe end-use and end-user restrictions. Not use, and not permit the use of, iFrame Services or Controlled Items for any prohibited end use (Section 10), including nuclear, chemical, biological, missile, prohibited military, military-intelligence, weapons-of-mass-destruction, prohibited advanced-computing / supercomputer, or unlawful surveillance or malicious-cyber end uses; and use iFrame Services only for lawful purposes consistent with iFrame’s Acceptable Use Policy.
20.5 Screen and diligence. Screen its own customers, end users, and downstream recipients against applicable Restricted Party Lists, and conduct reasonable due diligence to confirm the identity, legitimacy, and lawful end use of any party to whom it provides access to Controlled Items or iFrame Services.
20.6 No diversion. Not divert, and not permit the diversion of, Controlled Items or iFrame Services to any unauthorized end user, end use, or destination, and not participate in any transshipment or reexport in evasion of applicable controls.
20.7 Provide information and cooperate. Provide, and keep current, the information iFrame reasonably requests to satisfy its compliance obligations (including end-user, end-use, and identity information), and cooperate with iFrame’s screening, KYC, and audit requirements.
20.8 Flow down. Impose these obligations, in substance, on its own resellers, agents, brokers, and end users through binding contractual terms, and remain responsible for their compliance.
20.9 Notify. Promptly notify iFrame of any actual or suspected violation, of any government inquiry relating to Controlled Items or iFrame Services obtained from iFrame, and of any change that would make any representation in this Section untrue.
Breach of this Section is a material breach entitling iFrame to the remedies in Sections 17 and 18.
21. Obligations of suppliers and logistics providers
As a condition of supplying goods, components, software, technology, or logistics services to iFrame, each supplier, integrator, freight forwarder, and logistics provider (“Supplier”) represents, warrants, and covenants that it will:
21.1 Comply with law and provide classifications. Comply with all applicable export control, sanctions, and trade laws, and provide accurate and complete export classification information (including ECCN or equivalent, and country of origin) for all items supplied to iFrame, together with any applicable license conditions.
21.2 Not be a Restricted Party. Not be, and not be owned or controlled by or acting on behalf of, any Restricted Party; and promptly notify iFrame if this ceases to be true.
21.3 Lawful sourcing and integrity. Source items through lawful, authorized channels; not supply counterfeit, diverted, or grey-market items; and maintain the integrity and provenance of items supplied to iFrame, consistent with iFrame’s supply-chain security requirements.
21.4 Observe controls on transfers to iFrame. Ensure that any transfer of Controlled Items, technology, or technical data to iFrame or its personnel (including any deemed export) is authorized under applicable law.
21.5 Cooperate and flow down. Cooperate with iFrame’s screening, diligence, and audit requirements; provide documentation reasonably required for iFrame’s recordkeeping; and impose equivalent obligations on its own subcontractors and suppliers.
21.6 Notify. Promptly notify iFrame of any actual or suspected violation affecting items or services supplied to iFrame, and of any change that would make any representation in this Section untrue.
Breach of this Section is a material breach entitling iFrame to suspend or terminate the supply relationship and to pursue other remedies available at law or under contract.
22. Policy governance
22.1 Ownership and review. The ECO owns this Policy and reviews it at least annually, and upon any material change in applicable law or in iFrame’s business, and updates it as needed. Executive management approves material changes.
22.2 Availability. iFrame makes the current version of this Policy available to personnel and, as appropriate, to customers, resellers, brokers, and suppliers, and publishes an external-facing version at www.iframe.ai.
22.3 Precedence of law. Nothing in this Policy authorizes or requires any act that would violate applicable law. Where this Policy and applicable law conflict, the more restrictive requirement governs.
23. Disclaimer and note on completion
This Policy is a governance instrument stating iFrame’s commitments and requirements. It is not legal advice and does not itself constitute a determination as to the lawfulness of any specific transaction. The regulatory landscape governing advanced computing, and in particular the classification thresholds, country groupings, and licensing rules for AI accelerators, changes frequently; iFrame applies the law as then in effect. Before adoption, iFrame should have this Policy reviewed by qualified export-control counsel and should complete the bracketed items (compliance contact details and the identity of the designated Export Compliance Officer).
24. Approval and signature
Adopted and approved on behalf of iFrame Corporation:
______________________________________
Vladyslav Panin
Chief Executive Officer
iFrame Corporation
Date: ____________________
iFrame Corporation · 101 Jefferson Dr, Menlo Park, CA 94025 · www.iframe.ai
Trade Compliance Policy · Version 1.0 · This document is binding as set out above.
Legal inquiries: compliance@iframe.ai