Am I right in assuming that an applet that performs non-exportable encryption is considered to have been exported when the page is accessed by someone offshore? Mike