Rules are the prerequisite. Not the paperwork.
Varn builds autonomous machines for European defence. That work is regulated, watched, and licensed — as it should be. This page is the public version of how we run inside those lines, what we will not do, and who to write to when something needs attention.
Where we sit, on the map of who is watching.
One country, one legal address, one set of regulators in front of us. The lines below are the ones we actually report to — not a list of agencies we hope to impress.
- Licensing authorityJ-01Justitsministeriet
All controlled exports and intangible technology transfers are licensed by the Danish Ministry of Justice under EU Regulation 2021/821.
- Multilateral seatJ-02Wassenaar · MTCR · AG
Denmark is a member-state of the Wassenaar Arrangement, the Missile Technology Control Regime, and the Australia Group. Varn declares against all three.
- Operational reviewJ-03Forsvarsministeriet
New autonomous systems are reviewed by the Danish Ministry of Defence — and, where relevant, by FE — before any field use.
The rules we read before we ship.
The frameworks below are not aspirational. They govern what we are allowed to build, who we are allowed to sell to, what we are required to disclose, and what we have to be reviewed for.
- 01EU Regulation 2021/821
Recast dual-use export control
Every export of a controlled item or intangible technology transfer requires a Justitsministeriet licence before it leaves Denmark. No after-the-fact approvals.
- 02Council Common Position 2008/944/CFSP
Eight criteria on arms exports
The criteria the EU agreed to apply to every arms export decision — human rights, regional stability, internal repression, end-use, diversion risk.
- 03Wassenaar Arrangement
Conventional arms & dual-use controls
Multilateral lists of conventional military items and dual-use goods. Denmark reports annually; Varn supplies the underlying numbers for any line that touches us.
- 04MTCR · Category I & II
Missile-relevant technology
We submit qualifying items for licensing review under the missile technology control regime regardless of whether export is intended.
- 05Article 36, Additional Protocol I
Legal review of new weapons
Geneva Conventions review of new weapons, means, and methods of warfare. Commissioned before any autonomous system reaches operational use.
- 06AQAP 2110 · STANAG 4107
Quality assurance · NATO
Quality management for design, development, production. Implementation in progress; certification target 2027.
- 07GDPR · Databeskyttelsesloven
Data protection
Personal data is processed in Denmark by default. Varn is registered with Datatilsynet; DPO contact is published below.
- 08NIS2 · Cybersikkerhedsloven
Cybersecurity directive
In scope as an essential entity in the defence supply chain. Incident reporting, supply-chain risk register, and management accountability are written into the operating model from day one.
Inside the democratic circle. Only.
The categories below are the ones we will sell to and the ones we will not. Specific contracts inside them still require licences and end-use review on a case-by-case basis. The categories never move.
If a customer crosses the line during the life of a contract, the contract ends. That clause is in every contract we sign. No exceptions, no renegotiation.
- EU member states
- NATO member states
- EU candidate countries in active accession
- Ukraine · Moldova
- United Kingdom
- Australia · New Zealand
- Japan · Republic of Korea
- Russia and any intermediary acting on its behalf
- Belarus
- The People’s Republic of China
- The Islamic Republic of Iran
- The Democratic People’s Republic of Korea
- Any party under EU restrictive measures
- Any state that crosses into an EU restrictive measures listing while a contract with Varn is open
A weapon does not decide who dies.
Varn systems can act faster than a human. The choice to act remains human.
We build autonomous machines because autonomy is the only way certain missions get done at all. The autonomy is in the hard things — navigation under jamming, target classification, swarm coordination, contested-link survival. The decision to apply lethal force is a separate question, and the answer is the same on every Varn platform.
The position is not a marketing claim. It is in the architecture of the system, in the contracts we sign with operating states, and in the Article 36 review every Varn system undergoes before it reaches the field.
- RuleA-01
The system proposes. The operator decides.
Any application of force is initiated by a human acting on the recommendation of the system, not by the system acting on the human’s standing approval.
- RuleA-02
The system holds fire until told.
Loss of link does not authorise lethal action. The default state of a Varn system that has lost its operator is to hold, return, or self-deactivate — never to escalate.
- RuleA-03
The system is reviewable, after the fact.
Every decision the system proposes and every command the operator gives is logged in tamper-evident form. The log is available to the operating state and to the Article 36 reviewer.
How we behave when no one is in the room.
Six operating commitments. Concrete, narrow, written so a new hire can read them and know what to do next Tuesday morning.
- Trade controlsTC-01
Licence before shipment.
Every transfer of a controlled item — physical, digital, or in someone’s head — clears Justitsministeriet before it happens. We have no “after the fact” lane. Demos abroad are pre-cleared the same way.
- Catch-allTC-02
Stop, license or no licence.
Per Article 4 of EU 2021/821: if we have reason to suspect end-use in WMD programmes, internal repression, or breach of an EU embargo, we do not ship. The licence is not the last check; it is one of several.
- Data protectionDP-01
Personal data lives in Denmark.
Default residency is DK. Cross-border transfers run on Standard Contractual Clauses with a documented Transfer Impact Assessment. Datatilsynet is the supervisory authority; the DPO contact is in §08.
- Coordinated disclosureVD-01
Safe harbour for good-faith research.
Security researchers acting in good faith can report findings to security@varnindustries.com. We acknowledge within 72 hours, do not threaten legal action against researchers who follow the policy, and publish what was fixed once it is fixed.
- Anti-briberyAB-01
No facilitation, no intermediaries we cannot name.
Zero facilitation payments. No third-party agent on a public-sector deal without beneficial-ownership review on file. Aligned to Danish Penal Code §144, UK Bribery Act, and the FCPA where the deal touches the United States.
- Supply chainSC-01
Country-of-origin, recorded at receipt.
Critical components are sourced inside the democratic circle wherever the part exists there. Single-source dependencies in adversarial jurisdictions are tracked and replaced on a published timeline — no quiet acceptance of supply-chain risk.
Where we are. And where we aren't yet.
Varn was founded in May 2026. Several of the regimes listed in §03 apply to us in principle today and in practice as soon as we ship the first item. This is the honest version.
- In effect
- In progress
- Not yet
- S-01
Danish ApS · CVR public listing
Registered as Varn Industries ApS. CVR number will be published on the about page when it appears in the public CVR register.
In progressIn progress - S-02
Datatilsynet registration
Registered with the Danish Data Protection Agency. DPO appointment is the responsibility of the founder pending the first dedicated hire.
In effectIn effect - S-03
Justitsministeriet exporter onboarding
Filings prepared. No shipment of a controlled item will take place before the file is fully open.
In progressIn progress - S-04
Article 36 weapons review · process
Process drafted, reviewer identified. No Varn system has reached operational-threshold yet; the first review is scoped to the first platform that does.
In effectIn effect - S-05
AQAP 2110 · NATO quality assurance
Implementation in flight. Target certification window: 2027. We will not claim NATO QA conformity before the certificate is issued.
Not yetNot yet - S-06
ISO/IEC 27001 · information security
ISMS scope drafted. Target certification window: 2027. Internal controls are being built to the standard meanwhile.
Not yetNot yet - S-07
FMI · Danish defence vendor onboarding
Engaged with Forsvarsministeriets Materiel- og Indkøbsstyrelse. No Varn product is on a programme of record yet.
In progressIn progress - S-08
NIS2 · Cybersikkerhedsloven readiness
Acting as if we are an essential entity from day one — incident reporting playbook, supplier risk register, and management accountability are in place.
In progressIn progress
If we got something wrong, write to us.
Compliance questions, export-control queries, and reasoned disagreements with anything written on this page go to the compliance desk. We read every one. Replies come from a named human, with the relevant authority cited where there is one.
Security findings — anything you would call a vulnerability — go to the security inbox under coordinated disclosure. Personal data requests go to the DPO. We do not use intermediaries on any of these.
- Compliance deskcompliance@varnindustries.com
Export control · trade · ethics · this page
- Security disclosuresecurity@varnindustries.com
Coordinated vulnerability disclosure · 72 h acknowledgement
- Data protection officerdpo@varnindustries.com
GDPR · Databeskyttelsesloven · access and erasure requests