How does governing MCP server access satisfy ITAR requirements?

Kastra enforces governing MCP server access at the moment of execution and writes a signed evidence record for every MCP request. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to ITAR, CMMC 2.0, NIST 800-171 control families.