iOS App出口合规咨询:HTTPS与Keychain场景下的豁免资格判定
Hey there! This is a super common question when navigating Apple's export compliance forms, and I’ve walked plenty of developers through this exact scenario. Let’s break this down clearly:
核心结论
In almost all cases, your iOS app using only HTTPS and Keychain will qualify for the exemption under U.S. Export Administration Regulations (EAR) Category 5, Part 2.
具体拆解
Why HTTPS is exempt
HTTPS relies on TLS/SSL, which falls squarely into the "widely deployed, publicly standardized encryption" category covered by EAR 740.17(b). As long as you’re using iOS’s native HTTPS stack (likeURLSession) without modifying the underlying encryption logic or adding custom, non-standard crypto on top, this is explicitly exempt from needing a separate export license. The rule here is that if the encryption is a standard, widely used tool for general web/data communication, it’s covered.Why Keychain is exempt
Keychain is Apple’s built-in system-level credential storage, and its encryption is managed entirely by the iOS platform. EAR exempts encryption that’s part of a standard operating system’s core security features—since you’re not developing custom crypto for Keychain, just using the system-provided tool to store passwords/tokens, this doesn’t trigger the need for additional licensing.
少数需要留意的例外情况
There are a couple edge cases where you might need to dig deeper:
- If your app is specifically targeted at users in sanctioned countries/regions (like Cuba, Iran, North Korea, etc.), even standard HTTPS/Keychain use might require extra compliance checks, as EAR has strict restrictions for these areas.
- If you’ve added custom encryption on top of HTTPS (e.g., encrypting data again before sending it over an HTTPS connection), that custom crypto layer might not be exempt and would need further evaluation.
回到Apple的合规表单
You were right to select "Yes" when asked if your app uses encryption—HTTPS does count! When filling out the follow-up details, just note that you’re using system-provided HTTPS and Keychain, which fall under EAR exemptions. This should clear things up without needing additional licensing.
内容的提问来源于stack exchange,提问作者dariaa

