Industry
AI is reaching into the plant floor through the IT side, where the OT controls do not apply
Production data, supplier terms and process knowledge are now inside AI systems that were never scoped as operational technology.
The crown jewels are process knowledge, and they are text
Specifications, tolerances, yields and supplier pricing are exactly the material an agent is most useful summarizing — and exactly what a competitor or an export-control regime cares about.
- Segmentation does not cover the copyAir-gapping the line does nothing about the process document an assistant just read and forwarded.
- Supplier obligations are unreadQuality, indemnity and notification terms sit in agreements nobody reviews until a dispute.
- Defense supply chains inherit requirementsA tier-two supplier picks up the prime's security obligations through the flow-down, AI included.
With Odingard, you can
Keep process knowledge inside the boundary
Cerberus judges the outbound action, so an agent can read the specification without being able to send it onward.
Prove the control to a customer audit
TraceLock records evidence write-once and crosswalks it to the frameworks your primes ask about.
What buyers and regulators ask about
- IEC 62443
- The reference standard for industrial automation and control system security, increasingly cited in customer requirements.
- CMMC and NIST SP 800-171
- Defense suppliers handling controlled unclassified information inherit these through contract flow-down.
- Export control (ITAR / EAR)
- Technical data leaving the boundary can be a violation regardless of whether it was intentional.
Warden · By Odingard
Bring in Warden
Warden assesses where AI already touches production data and constrains the boundaries before an incident defines them for you.
Use AI on production data without exporting it
The constraint belongs at the action, not at the door. Start with a boundary review.