Skip to content

ITAR-friendly visitor management

ITAR Visitor Management System for Defense & Aerospace Sites

  • Free plan available
  • No credit card required
  • Set up in minutes

How a similar industrial-software customer runs visitor check-in

We do not publish a named defense or aerospace customer testimonial on this page. Command Alkon is the closest analog among our public references — an industrial-software company managing multi-site visitor sign-in with NDA capture at check-in.

InstaCheckin was the easiest implementation we have ever been through, with great results! We are able to check in guests as well as get a signed NDA! We have been pleased with all that it can do!

Dianne Rogers, PHR People Business Manager · Command Alkon

Frequently asked questions

Does InstaCheckin work for ITAR-restricted facilities?
InstaCheckin is used by defense and aerospace customers as part of their visitor-management program for ITAR-controlled sites. The product captures a citizenship attestation, binds every visit to a US-person host of record, prints a badge with an escort-required overlay, and exports the visitor log on demand. It does not make an export-control decision, classify technology, or run automated denied-party screening — ITAR compliance is broader than visitor logs alone, and your export-control officer owns the program.
Is InstaCheckin itself "ITAR compliant"?
No visitor system is "ITAR compliant" on its own, and InstaCheckin does not claim to be. ITAR compliance is a facility program — DDTC registration, a technology-control plan, USML classification, license determinations, denied-party screening, and training. InstaCheckin provides visitor logging that supports that program: a structured, timestamped, photographed record attributed to a US-person host, exportable for audit. It is one honest artifact in a larger program, not the program itself.
Can the iPad app flag foreign nationals at check-in?
Yes. The iPad welcome flow can require a citizenship attestation field before sign-in completes (for example, "Are you a US person as defined by 22 CFR §120.62?"). When the visitor selects a non-US citizenship, the workflow can route them to a stricter NDA, a different badge template with an "ESCORT REQUIRED" overlay, or an additional host-approval step. The attestation is the visitor's own timestamped statement — it is a record, not an identity verification; InstaCheckin does not scan passports.
Does InstaCheckin screen visitors against OFAC or the BIS Entity List?
No. InstaCheckin does not run automated screening against government denied-party or restricted-party lists (OFAC, BIS Entity List, the Consolidated Screening List). It offers a manual blocklist your security team maintains by hand: when a name you have added attempts to sign in, InstaCheckin silently alerts your designated security contact at the kiosk. If your program requires automated denied-party screening, run it in a dedicated tool and record the result — that is a separate control from visitor logging.
Does InstaCheckin enforce continuous escort of foreign nationals?
No — it makes the escort requirement visible and binds a US-person host of record; it does not physically gate a door or enforce continuous escort. The badge carries a high-contrast "ESCORT REQUIRED" overlay and a color band, and the host of record is named on the record and notified at sign-in. Physical enforcement on the floor stays with your facility. What InstaCheckin contributes is legibility and an auditable record of who accepted escort responsibility.
How does InstaCheckin's audit log help with ITAR record-keeping?
Every check-in is stored as a structured record with the same fields each time: visitor name, company, photo, citizenship attestation, purpose of visit, host of record, badge ID, NDA signature, sign-in and sign-out timestamps, and facility location. The log exports to CSV, Excel, or PDF with date-range and citizenship filters. Records are retained server-side for as long as your data-retention policy specifies, which is how customers keep records available across ITAR's five-year recordkeeping window (22 CFR §122.5). InstaCheckin does not enforce the retention clock — you configure it to your policy.
Can we require a US-person host on every visitor record?
Yes. Every visit in the admin portal binds to a specific host employee, and the host receives an email, SMS, Slack, or Teams notification when their visitor signs in. The host name, email, and phone are stored on the visit record so the export-control officer can later pull every visit a given host escorted — without joining the visitor log to a separate badge system.
Can we pre-register visitors and capture an NDA before they arrive?
Yes. A host or program manager can pre-register a visit from the admin portal and send the visitor a pre-arrival email with a unique check-in link. The visitor confirms citizenship, work authorization, and any program-specific NDA or technology-control acknowledgment in the pre-arrival flow. By the time they scan their QR code at the iPad, the workflow already knows whether to apply the escort-required template. Electronic-record and e-signature law varies by jurisdiction; verify enforceability with counsel.
Does InstaCheckin support multiple controlled facilities under one account?
Yes. The admin portal supports a multi-site dashboard where corporate facility-security or export-control teams can see check-ins across every location, run a unified audit export, and push a consistent badge template, NDA, and pre-registration flow to every site. Each site can override the welcome screen, badge color, host directory, and NDA wording locally. The same pattern is described on the manufacturing visitor management page.

Related verticals: manufacturing visitor management and office visitor management.

Ready when you are

Start 14-Day Free Trial