Legal
Export and cryptography notice
What cryptography the product uses, and where we stop answering.
This page is a notice, not a legal classification. If your compliance process needs a statement about export control, ask us and we will tell you exactly what we can and cannot provide.
This document is published in English. If a translation appears elsewhere, the English version prevails.
1. Cryptography in the product
CommMonitor does not ship its own cryptographic library. It calls the cryptographic services built into Windows.
- RSA-2048 with PSS and SHA-256, used to verify licence signatures.
- AES-256-GCM with PBKDF2-SHA256 key derivation, used when you protect a session file with a password.
- SHA-256 hashing, used for the integrity manifest of the application and the driver.
2. Network functionality
The only network request the application makes on its own is an activation request, and only when you initiate it. Forwarding to TCP or HTTP sends captured frames to a destination you configure, on your own network.
3. What we do not state
We do not publish an export classification for the product. The classification of software that uses standard operating-system cryptography depends on your jurisdiction, the destination and the end use, and it is not something we can determine for you. We will provide the technical facts you need - what the product uses it for and how - and your own compliance process decides the rest.

