Export Controls, Research Security & International Collaboration Policy

Collaborate globally. Protect sensitive knowledge responsibly.

The JR Institute intends to support open research while managing legal, security, ethical, and reputational risks involving controlled technology, restricted parties, foreign relationships, international travel, data access, and material transfer.

Developing Framework

This page presents a planned public standard. Final screening systems, licensing procedures, disclosure forms, travel controls, technology-control plans, and review authorities should be established before controlled activities begin.

Policy Purpose

Openness and security must be managed together.

International research can accelerate discovery, strengthen institutions, and connect expertise. It can also create obligations involving export controls, sanctions, restricted entities, intellectual property, data protection, cybersecurity, and disclosure.

The Institute should identify those obligations early and avoid informal arrangements that bypass review, transparency, or security controls.

Core Principles

Disclose relationships, screen risk, control access, and preserve academic integrity.

01

Early Review

Review controlled technology, foreign parties, travel, shipping, funding, and access before commitment or transfer.

02

Complete Disclosure

Disclose appointments, support, affiliations, gifts, funding, facilities, and outside obligations.

03

Least Necessary Access

Limit controlled data, equipment, software, and technical information to authorized persons.

04

Restricted-Party Screening

Screen collaborators, vendors, destinations, recipients, and intermediaries where required.

05

Secure Collaboration

Use approved contracts, systems, storage, communications, and transfer methods.

06

Independent Escalation

Escalate high-risk or conflicted matters to qualified legal, security, compliance, and governance review.

Scope

This policy is intended to apply to research, software, technical data, equipment, prototypes, biological materials, chemicals, encryption, geospatial information, defense-related technology, international travel, foreign funding, and cross-border collaboration.

Technology and Information Classification

Projects should be reviewed to determine whether technology, software, data, equipment, or services are subject to export, sanctions, security, contractual, sponsor, or publication restrictions.

Classification should occur before access, transfer, shipment, disclosure, foreign participation, or international travel.

Restricted Parties, Sanctions, and Destination Screening

Collaborators, vendors, sponsors, recipients, end users, financial institutions, and destinations may require screening against applicable restrictions.

  • Identify all parties and beneficial owners where relevant
  • Confirm destination and end use
  • Escalate ambiguous matches rather than dismissing them informally
  • Document the review and decision
  • Repeat screening when parties or circumstances change

Deemed Exports and Foreign-Person Access

Providing controlled technical information or access to certain technology may be regulated even when no item physically leaves the country.

Access decisions should consider nationality, immigration status where legally relevant, location, project classification, system permissions, laboratory access, and licensing requirements.

Physical presence on campus does not automatically authorize access to controlled technology, systems, equipment, or technical data.

Shipping, Hand-Carrying, and Material Transfers

Equipment, samples, prototypes, software, data, and technical documents should be shipped or carried internationally only through approved processes.

Review should address classification, license needs, customs, end use, destination, recipient, temporary export, return, insurance, and chain of custody.

International Travel and Remote Access

International travel may require device preparation, clean systems, reduced data, secure communications, travel registration, country review, briefing, and post-travel reporting.

Remote access from foreign locations should be treated as a potential transfer and evaluated according to data sensitivity, project restrictions, local law, and cybersecurity risk.

Foreign Affiliations, Support, Appointments, and Gifts

Covered persons should disclose foreign appointments, institutional affiliations, talent-program participation, laboratories, financial support, gifts, sponsored travel, in-kind resources, and outside commitments when relevant to institutional or sponsor requirements.

Disclosure supports conflict management, sponsor accuracy, security review, and protection of research independence.

Technology-Control Plans and Cybersecurity

High-risk projects may require a written technology-control plan defining authorized persons, physical areas, data systems, device controls, marking, storage, communication, monitoring, and incident response.

Controlled information should not be placed in personal email, consumer file-sharing, unapproved cloud systems, or unmanaged devices.

Publication, Fundamental Research, and Academic Openness

The Institute should preserve open inquiry wherever possible and review proposed restrictions on publication, participation, access, and dissemination before accepting them.

A project should not be described as unrestricted merely because publication is eventually expected. Access controls, sponsor rights, proprietary data, or security obligations may still apply.

Potential Violations, Holds, and Corrective Action

Suspected unauthorized transfers, undisclosed relationships, restricted-party contact, security breaches, export violations, or inaccurate sponsor disclosures should be reported promptly.

The Institute may pause shipments, access, travel, payments, publication, system use, or collaboration while qualified personnel review the matter.

Framework date: July 2026

Research Security Lifecycle

Disclose, classify, screen, control, monitor, and close.

  • Disclose the relationship. Identify parties, support, appointments, access, destinations, and outside obligations.
  • Classify the activity. Determine whether technology, data, software, or equipment is controlled.
  • Screen the parties. Review collaborators, vendors, recipients, end users, and destinations.
  • Control access and transfer. Use approved systems, contracts, licenses, storage, and travel procedures.
  • Monitor and close. Review changes, preserve records, terminate access, and confirm return or disposition.
Research Security Questions

Report controlled technology, restricted-party, foreign relationship, or transfer concerns.

Inquiries may concern international collaboration, foreign funding, travel, shipping, software, equipment, data access, sanctions, disclosures, or technology-control plans.

Submit a Research Security Inquiry

Identify the project, party, country, technology, proposed transfer, deadline, and available supporting information.

Contact the Institute