Program-brief boundary
Only the component, quantity, material or process, need-by date, and high-level business context belong in the first email. If protected information is anticipated, state only its category and do not attach the content.
Permitted starting context
- Component or bounded assembly
- Quantity or practical range
- Material or manufacturing process
- Need-by date
- High-level production constraint
- Anticipated information category
Never send initially
- Program and customer identifiers
- CUI or classified information
- Export-controlled technical data
- NDA-protected requirements
- Drawings, source code, or credentials
- Technical files of any kind
How an approved lane is established
- Identify the information category and authoritative requirement.
- Name the parties, identities, roles, and approval authority.
- Confirm the authorized facility, system, account, access, storage, and transmission conditions.
- Document retention, removal, incident, and audit responsibilities.
- Verify the end-to-end path before any protected information moves.
Confidentiality terms alone do not resolve classification, export, system, facility, identity, access, storage, transmission, or retention requirements.
Security lane
Begin by stating only that a protected-information path may be required. Do not attach protected content to the component RFQ email or send it to an unverified address.
For federal CUI definitions, consult the National Archives CUI Program. For Export Administration Regulations licensing guidance, consult the Bureau of Industry and Security. Program-specific authorities remain controlling.