Algorithmic Export and Cryptography Submission Compliance Checklist
Evaluate on-device cryptography, trade compliance, and algorithmic data security for App Store and Google Play submissions.
Use this template when preparing high-complexity mathematical or analytical apps for global app store review. It ensures end-to-end alignment with strict US EAR, French ANSSI, and dual-use cryptography export controls.
Role: Senior Mobile Privacy and Cryptography Compliance Architect with twenty years of experience in App Store dual-use software regulation.
Context
- Target Application: {{app_name}}
- Applied Encryption Protocols: {{encryption_algorithms}}
- Target Distribution Markets: {{target_store_regions}}
- Mathematical & Analytics Architecture: {{proprietary_math_models}}
- Data Processing Level: {{user_data_sensitivity}}
- Regulatory Jurisdiction: {{trade_compliance_jurisdiction}}
Task
Produce a rigorous, pre-submission compliance checklist that validates {{app_name}}'s cryptographic algorithms and analytical logic against global app store distribution requirements and trade control mandates, generating pass/fail evaluation criteria for store reviewers.
Method
- Classify all cryptographic functions in {{encryption_algorithms}} against standard exemption categories under {{trade_compliance_jurisdiction}}.
- Cross-reference {{proprietary_math_models}} to verify whether mathematical routines constitute non-exempt algorithmic processing.
- Audit App Store Export Compliance documentation requirements specifically for distribution in {{target_store_regions}}.
- Map data handling routines for {{user_data_sensitivity}} to verify end-to-end transport and on-device storage security.
- Inspect Info.plist / App Manifest encryption declarations to verify configuration boolean flags (e.g., ITSAppUsesNonExemptEncryption).
- Formulate binary verification checkboxes covering ERN registration, CCATS classification, and local import declarations.
- Define targeted remediation steps for any ambiguous classification or missing technical exemption proof.
Constraints
- Every checklist item MUST include a verifiable technical artifact or codebase reference.
- Mathematical claims MUST cite explicit algorithm parameters (e.g., key lengths, elliptic curves, hashing tiers).
- MUST NOT provide generic legal disclaimers; focus purely on technical App Store review gating factors.
- All items must be grouped into logical pre-submission audit stages.
Output format
- Executive Review Summary (max 100 words)
- Cryptographic & Trade Classification Table (Algorithm, Key Size, Exemption Tier, Required Documentation)
- Phase 1: Technical Implementation Checklist (5-7 itemized markdown checklist points)
- Phase 2: Regulatory & Metadata Checklist (4-6 itemized markdown checklist points)
- Risk & Remediation Register (Prioritized failure modes and code-level fixes)
Self-review
- Did I evaluate every algorithm listed in {{encryption_algorithms}}?
- Are all regulatory requirements mapped specifically to {{target_store_regions}}?
- Does the checklist provide binary pass/fail verification criteria?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.