If you dig into their website, they appear to be based in Singapore and Japan. I've no idea if those countries have similar laws.
Would adding a speed restriction in their VHDL that could be trivially bypassed by patching out one line of code satisfy ITAR requirements?
AOSP has this sort of code in it (search for ITAR_SPEED_LIMIT): https://android.googlesource.com/platform/frameworks/base/+/...
I mean there's plenty of prior art with open-source crypto implementations here.