Indiana buyer guide

Outsourcing software development from Indiana

An Indiana buyer guide to international software and AI outsourcing: current CDPA processor evidence, manufacturing and OT access, incidents, time zones, cost, and exit.

For: Indiana founders, product and engineering leaders, manufacturers, industrial and connected-product teams, privacy and security owners, counsel, procurement teams, and buyers evaluating software, automation, analytics, support, or AI delivery outside the United StatesBy Outsourcing.ai Editorial Team
The decisionAn Indiana buyer should classify each work package before international access, keep consumer-data processing separate from manufacturing and operational-technology authority, use a buyer-owned maintenance interlock for staging and production sessions, name the actual Eastern or Central buyer location, and require processor, incident, recovery, and exit evidence that can be tested before scale.Evidence references: [1][2][3][4][5][6][7][8][9][10][11][12][13][14][15]
An enterprise-data lane and a manufacturing-system lane passing through separate privacy, evidence, staging, monitored-access, safety, and return gates, all controlled by a central buyer-owned switch linked to two operating clocks and a distinct urgent incident relay
Indiana consumer-data processing and manufacturing maintenance need separate permissions: the buyer-owned interlock routes ordinary engineering, privacy-controlled data, digital-twin testing, expiring supervised sessions, incident evidence, and final release without turning supplier capability into standing production authority. Original Outsourcing.ai editorial illustration, generated with AI and reviewed for relevance and accuracy.
No local-office claim. Outsourcing.ai is an online research and delivery platform. This guide is for Indiana buyers; it does not represent an Indiana office, Indiana staff, completed Indiana client work, a manufacturer, critical-infrastructure operator, State vendor, government authorization, certification, or legal, privacy, cybersecurity, safety, engineering, procurement, employment, tax, export, sanctions, or intellectual-property advice.
Direct answerAn Indiana company can use software and AI teams outside the United States, including for manufacturing-adjacent work, but it should not give one standing “vendor VPN” permission to a whole supplier. Classify each operation first. Consumer-data work may activate Indiana's current CDPA processor instructions, contract, rights, security, assessment, and return-or-delete evidence. Manufacturing or operational-technology work needs a separate safety and production-authority path even when the privacy statute does not apply. State work activates a third contract-and-policy lane only when the actual agency procurement and system facts require it. Route ordinary code through isolated engineering, test changes in a digital twin or staging system, and issue an expiring supervised session only when a named plant owner approves the exact asset, command set, time, and rollback.

Indiana outsourcing at a glance

Proposed workFirst buyer decisionEvidence required before access
Ordinary web, mobile, data, or AI engineering with no regulated or production dataProve the boundary instead of assuming a repository is harmlessWork package, identities, cities, accounts, data classification, dependencies, test plan, release authority, accepted evidence, and exit
Personal-data operation within Indiana’s current CDPA perimeterDecide controller/processor role and applicability for the operationThreshold and exemption analysis, data inventory, purpose, instructions, consumer-rights support, assessment decision, contract, subprocessors, security, deletion or return, compliance evidence
Connected product, manufacturing application, historian, MES, SCADA, PLC, HMI, engineering workstation, or other OT-adjacent workDecide whether the supplier needs source access, synthetic data, a digital twin, staging, read-only production evidence, or a supervised production sessionAsset and dependency inventory, safety boundary, approved commands, maintenance order, named operator, monitored access path, session evidence, rollback, recovery test, revocation
State of Indiana agency or covered State-system workRead the actual procurement, contract, data classification, Indiana RAMP, and vendor policy requirements; do not apply them to every private buyerSolicitation and executed clause register, system boundary, data classification, approved cloud and vendor path, exceptions, incident ownership, acceptance, exit
Supplier discovers a possible event involving Indiana personal informationSend decision-ready facts to the owner immediately; do not wait for perfect attributionDiscovery time, affected systems, owner/licensee, data elements, acquisition facts, resident scope, containment, preserved evidence, update cadence, notice-decision owner
Buyer spans Indiana’s two time zonesName the site or county before promising overlap or incident coverageBuyer location, IANA zone, contributor cities and zones, dated overlap, daylight-saving transitions, authority windows, backup owner, handoff standard

These are operating lanes, not conclusions that a particular organization, system, record, facility, person, contract, or event is covered. The current code, executed contracts, sector rules, federal obligations, other states, and destination-country law may change the result. Qualified owners should decide the perimeter from the actual facts.

The distinct Indiana model: a maintenance-authority interlock

Indiana is useful for a buyer decision that generic “offshore development” pages often miss: software delivery authority and production maintenance authority are not the same permission.

A distributed team may be excellent at application code, test automation, analytics, computer vision, predictive-maintenance models, integration adapters, dashboards, or documentation. That capability does not automatically authorize the team to reach a production line, issue a control command, change a recipe, update firmware, modify a safety-related configuration, view unrestricted plant telemetry, or decide when a facility returns to service.

Use one buyer-owned interlock with four outputs:

  1. Ordinary engineering: approved repositories, synthetic or minimized data, isolated build systems, and no route to production OT.
  2. Privacy-controlled data: exact controller instruction, covered fields, purpose, rights support, subprocessor path, evidence, and deletion or return.
  3. Staging or digital twin: representative configuration and behavior without uncontrolled physical effect, followed by acceptance and rollback testing.
  4. Time-boxed maintenance: a named asset, approved order, named operator, supervised session, limited commands, active logging, safe-stop condition, rollback, and immediate revocation.

The interlock is not a diagram that lives in a policy folder. It should be reflected in identity groups, network routes, environment credentials, approval records, deployment controls, maintenance tickets, session monitoring, and the definition of done. If a person can bypass it with a shared account or a permanent tunnel, it is not an interlock.

Start with an operation and asset record

Do not classify the supplier once and reuse the label for every task. Create a row for each collection, query, transformation, model call, code change, build, test, deployment, maintenance action, support view, export, incident action, and deletion. Record:

  • business process, product, facility, line, cell, asset, system, environment, and accountable owner;
  • whether the item is enterprise IT, product software, engineering data, consumer personal data, production telemetry, OT configuration, command data, safety-related information, regulated data, or an ordinary artifact;
  • exact data fields, source, subject, sensitivity, purpose, retention, replica, log, backup, and every technically possible access route;
  • buyer entity, supplier entity, subprocessor or subcontractor, role for this operation, contributor name, employer, city, country, account, device, and network path;
  • source repository, build runner, package registry, artifact store, signing process, staging target, release target, and final deployment authority;
  • asset protocol, firmware or software version, configuration baseline, dependencies, operating state, safety constraints, recovery point, and rollback owner where manufacturing systems are involved;
  • requested command, allowed command set, prohibited actions, session start and expiry, supervisor, observation path, record source, and automatic termination condition;
  • consumer-rights, assessment, incident, continuity, recovery, deletion, return, and exit responsibilities; and
  • source, qualified interpretation, approval, exception, expiration, and re-review trigger.

“The supplier works only in the cloud” is not enough. Cloud observability may receive production telemetry. Ticket attachments may contain screenshots or identifiers. A model-evaluation set may contain real failure traces. A remote desktop gateway may bridge a corporate account into an engineering workstation. Trace the actual operation and the actual route.

Keep the current CDPA lane operational

Indiana’s Consumer Data Protection Act is current as of January 1, 2026. The Attorney General’s current guide summarizes applicability through two paths: controlling or processing personal data of at least 100,000 Indiana residents, or at least 25,000 residents while deriving more than half of gross revenue from personal-data sales, subject to the law’s definitions and exemptions. A buyer should preserve the calculation and exemption decision instead of placing “Indiana privacy: yes/no” in a spreadsheet without evidence.

For each covered operation, distinguish the controller that determines purpose and means from a processor acting on instructions. Current Article 15 makes that relationship useful to outsourcing procurement. The operating packet should identify:

  • processing instructions, nature and purpose, data types, duration, and party obligations;
  • the individuals permitted to process the data and their confidentiality duty;
  • technical and organizational support for authenticated consumer requests;
  • security and breach assistance based on the nature of processing and information available;
  • information needed for the controller’s impact assessment;
  • the subprocessor approval and equivalent-obligation path;
  • evidence available to demonstrate compliance; and
  • deletion or return at the controller’s direction when services end, subject to an applicable legal retention requirement.

Do not ask a supplier to “be CDPA compliant” and treat that phrase as an instruction. A processor needs machine-readable and human-usable limits: allowed tables and fields, permitted transformations, approved environments, supported rights operations, blocked purposes, geographic and account boundaries, retention, evidence, and escalation.

Consumer rights must survive the delivery architecture

A deletion, correction, access, portability, opt-out, or appeal process can fail even when the public form works. The hidden failure is usually downstream: a cache, search index, analytics store, fine-tuning dataset, evaluation set, support export, log archive, ticket, backup, or subprocessor has no subject linkage or no tested action.

For a representative request, test the complete path:

  1. authenticate and record the request without over-collecting identity evidence;
  2. find the subject in each approved system and supplier-held copy;
  3. distinguish deletion from a justified restriction or retained record;
  4. execute the action through the processor and every relevant subprocessor;
  5. prevent the deleted material from silently returning through a restore, replay, or derived dataset;
  6. return evidence to the controller without placing unnecessary personal data in the evidence packet; and
  7. preserve the appeal and accountable-human route.

The buyer owns the consumer response. The international team can implement and exercise the workflow, but it should not invent the legal scope or communicate as the controller without explicit authority.

Treat assessment evidence as a release dependency

Current Article 15 requires impact assessments for specified higher-risk processing and applies its own effective-date boundary. The engineering decision is simple even when the legal analysis is not: if a new or materially changed feature may involve targeted advertising, personal-data sale, significant-effect profiling, sensitive data, or another assessed operation, the release should stop until the responsible owner records the applicability and assessment decision.

An assessment-ready change packet should include:

  • feature and decision description, affected people, data, purpose, model, outputs, recipients, and systems;
  • benefits, reasonably foreseeable risks, safeguards, alternatives, and data-minimizing option;
  • profiling logic and human-review path where relevant;
  • quality, bias, security, privacy, misuse, and failure-mode evidence appropriate to the system;
  • supplier facts separated from controller conclusions;
  • approval, conditions, residual risk, prohibited state, and expiry; and
  • triggers for re-review when purpose, data, model, threshold, recipient, country, subprocessor, or behavior changes.

This makes the assessment a live production control. It also prevents a vendor from treating a prior assessment as permission for a substantially different model or dataset.

Separate the manufacturing and OT lane

Indiana’s Department of Homeland Security identifies critical manufacturing as an interconnected sector and emphasizes that critical infrastructure depends on cyber technology. NIST’s manufacturing and OT publications provide a voluntary technical method for turning that concern into supplier controls. They do not make every Indiana manufacturer a critical-infrastructure operator, and they do not replace the facility’s safety program, engineering standards, vendor instructions, or applicable regulation.

The key distinction is consequence. An error in a brochure site may cause a bad page. An error in an industrial environment may interrupt production, corrupt engineering state, damage equipment, defeat a quality control, or contribute to physical harm. Therefore, do not copy ordinary SaaS permissions into the plant environment.

Build an asset-to-authority matrix

For every affected asset or logical group, record:

Asset or environmentSupplier may seeSupplier may changeBuyer approvalLive observationRollback and safe state
Source and build systemApproved code, issues, synthetic fixturesFeature branch and controlled pipelineCode owner and release ownerRepository and CI logsRevert, known-good artifact, dependency lock
Digital twin or representative labApproved configuration and simulated telemetryTest configuration and candidate behaviorTest ownerTest recording and comparisonReset image and baseline fixture
Staging or pre-productionMinimized representative stateSigned candidate within change windowSystem owner and change ownerDeployment and application logsPrior signed release and rollback test
Production enterprise ITMinimum diagnostic evidenceOnly explicitly approved changeService ownerActive monitoring and incident channelTested recovery plan
Production OT or manufacturing systemNamed signals or screens needed for the orderExact approved commands on exact assetsPlant or operations owner plus required safety authorityNamed on-site or accountable observer and session recording appropriate to policyDefined safe stop, known-good configuration, recovery sequence, revocation

If the supplier cannot describe why it needs a production command instead of a staging test, the request is not ready. If the buyer cannot identify who has authority to stop the session, the session is not ready.

Issue expiring maintenance capsules

NIST’s manufacturing example treats remote vendor access as registered, approved, monitored, selected-system access that is disabled after the work. Convert that pattern into a one-session capsule:

  • supplier legal entity, named engineer, verified account, managed device, and approved location;
  • maintenance order, business reason, affected asset, version, operating state, and prerequisites;
  • allowed gateway, protocol, destination, system, privilege, command, file, and transfer direction;
  • start time, hard expiry, idle timeout, and automatic credential and route revocation;
  • buyer supervisor, plant contact, safety owner, security observer, and incident channel;
  • active-session indication, logging, recording where authorized, integrity checks, and clock synchronization;
  • pre-change backup, comparison baseline, safe-stop criteria, rollback steps, recovery objective, and post-change validation; and
  • evidence packet, exceptions, unresolved observations, acceptance, credential closure, and route closure.

A permanent vendor tunnel, shared account, unrecorded emergency password, or unrestricted engineering workstation defeats the model. Emergency support may require a faster route, but it still needs a named incident authority, constrained access, contemporaneous logging, and retrospective reconciliation.

Keep code acceptance separate from plant release

The international team may prepare a correct change while the plant is not ready to receive it. Use two approvals:

  1. Technical acceptance: the code or configuration meets the work package, review, test, security, dependency, provenance, and documentation requirements.
  2. Operational release: the named facility owner confirms the window, state, safety prerequisites, production dependencies, people, communications, rollback, and recovery readiness.

Store signed or otherwise integrity-protected artifacts between those decisions. The supplier should not rebuild a different artifact during the release window. The buyer should be able to connect source commit, dependency set, build evidence, test results, artifact identity, approval, deployed identity, and observed result.

For AI or analytics in manufacturing, add model and data lineage, evaluation population, operating envelope, drift thresholds, fail-safe behavior, human override, and rollback. A model that only recommends maintenance is not automatically harmless if operators rely on it. A model that writes a control parameter needs a materially stronger boundary than one producing a separate advisory report.

Use an immediate incident fork

Indiana’s breach page explains current owner-facing notification obligations for covered computerized personal information and the Attorney General reporting path. The supplier should not decide whether an event is legally reportable, but it must not delay the owner while trying to reach final attribution.

Create an immediate relay for facts that may involve covered data, credentials, a production system, an integrity change, an unsafe state, or loss of availability. The first packet should say what is known and unknown:

  • discovery time, reporter, system, asset, account, region, and current operating state;
  • observed behavior and acquisition, access, alteration, execution, outage, or safety facts;
  • data elements and Indiana-resident question where personal information may be involved;
  • plant, product, customer, quality, safety, and continuity impact indicators;
  • containment taken, authority used, records preserved, and actions intentionally not taken;
  • supplier systems, subprocessors, credentials, sessions, files, builds, commands, and logs involved;
  • buyer decision owner, plant or service owner, privacy owner, security owner, counsel route, and communications owner; and
  • next update time even when there is no new conclusion.

Then split the response. The privacy owner determines the Article 4.9 path from the facts. The plant or service owner decides safe operation and recovery. Security preserves and analyzes evidence. Counsel and communications owners control notices. The supplier keeps the technical record current and follows authorized containment. One track may close while another remains active.

Name the Indiana location before calculating overlap

Most of Indiana uses Eastern time, while twelve northwest and southwest counties use Central time. The State’s current page lists Jasper, Lake, LaPorte, Newton, Porter, and Starke in northwest Indiana and Gibson, Perry, Posey, Spencer, Vanderburgh, and Warrick in southwest Indiana. Indiana observes daylight saving time.

Do not write “Indiana time” in a statement of work. Record the buyer site, county, maintained IANA identifier, and dated offset. America/Indiana/Indianapolis may be appropriate for an Indianapolis-centered team; a site in Lake County or Vanderburgh County needs its actual Central-time identity. Confirm with maintained time-zone data rather than relying on a static offset.

For each contributor city, calculate four dates: a normal working week, both sides of the March transition, both sides of the November transition, and any destination-specific transition date. Record:

  • sustainable shared hours rather than the widest theoretical overlap;
  • meeting window, maintenance window, release window, and incident authority window separately;
  • who can approve, observe, stop, and recover work outside buyer business hours;
  • written handoff cutoff, evidence standard, unanswered-question route, and acceptance time; and
  • backup owner for absence, local disruption, connectivity loss, or an expired maintenance capsule.

Nearshore can improve live overlap for many Indiana sites, but overlap is not a substitute for clear authority. Offshore follow-the-sun work can be valuable when the work packet is small, testable, and reversible. Compare cities and named people, not region stereotypes.

Compare destinations after the workload is split

Do not choose one country for every lane. Separate at least these work packages:

  • ordinary application engineering using synthetic or minimized data;
  • consumer-data processing under controller instructions;
  • manufacturing analytics with delayed, filtered, or aggregated telemetry;
  • digital-twin and lab work;
  • production support without command authority;
  • supervised maintenance requiring an expiring session; and
  • incident, recovery, and continuity support.

Then compare actual provider entities and contributor cities on:

  • relevant product, data, industrial, and recovery experience supported by inspectable evidence;
  • employer or contractor identity, assignment chain, confidentiality, and destination-country IP research;
  • screening, device control, secure workspace, identity, network, logging, and administrator practices;
  • ability to work through the buyer’s staging, artifact, maintenance, and evidence controls;
  • overlap with the actual Indiana site and credible after-hours escalation;
  • subprocessor and subcontractor transparency;
  • continuity when the contributor, city, provider system, or network is unavailable; and
  • complete cost, including buyer supervision, lab or twin infrastructure, security, travel, rework, recovery, and exit.

Country pages are starting points, not rankings. Use the Colombia guide or Mexico guide to examine closer overlap patterns, the India guide for a deep engineering and follow-the-sun pattern, and the Poland guide for European delivery. Recheck the exact legal entity, people, tools, locations, and current rules before a decision.

Build a complete cost model

The lowest hourly rate can be the most expensive operating model when the buyer adds uncontrolled access, coordination, rework, downtime, or a failed exit. Calculate:

complete monthly cost = supplier fees + buyer ownership + security and privacy controls + environments and lab + coordination + travel + rework + expected disruption + transition and exit

Use ranges and name assumptions. For an OT-adjacent project, estimate separately:

  • environment discovery and asset inventory;
  • representative lab, digital twin, simulator, fixtures, and test-data preparation;
  • gateway, identity, monitoring, logging, and session-control work;
  • plant-owner, engineer, security, privacy, quality, and safety review time;
  • planned downtime or controlled window cost;
  • rollback and recovery exercise;
  • on-site or specialist support when actually needed; and
  • credential closure, documentation, knowledge transfer, and replacement-provider handover.

A bidder that refuses to price evidence, rollback, or transition is not necessarily cheaper. It may be moving cost and risk back to the buyer.

Run a paid 30-day interlock pilot

Choose one meaningful but reversible work package. A good pilot might implement a diagnostic view, an analytics adapter using minimized telemetry, a digital-twin change, a consumer-rights workflow, or a production-adjacent fix that can be validated before any live command.

Week 1: perimeter and evidence

  • record the operation, data, asset, environment, identities, locations, accounts, tools, dependencies, and roles;
  • decide CDPA, breach, manufacturing/OT, State-work, contractual, and other applicable lanes with qualified owners;
  • create the source-to-artifact and asset-to-authority matrices;
  • calculate dated overlap for the actual Indiana site and contributor cities; and
  • agree acceptance, incident, rollback, recovery, and exit evidence.

Week 2: isolated delivery

  • provision least-privilege repositories and systems;
  • use synthetic, minimized, delayed, or representative data where possible;
  • build through the approved pipeline with dependency and provenance evidence;
  • demonstrate rights support or data handling if personal data is involved; and
  • exercise the incident relay with one ambiguous signal.

Week 3: twin or staging acceptance

  • deploy the exact candidate to the representative environment;
  • test expected behavior, failure, misuse, security, performance, and rollback;
  • compare baseline and result using buyer-observable evidence;
  • reject undocumented manual steps and rebuilds; and
  • close or condition every exception before release authority is considered.

Week 4: controlled release and exit

  • issue an expiring maintenance capsule only if the work needs it;
  • require named buyer observation and hard-stop authority;
  • verify artifact identity, pre-change state, commands, logs, result, rollback readiness, and credential closure;
  • export the complete evidence packet and restore it in a clean buyer-controlled location; and
  • rehearse supplier replacement by having another authorized person use the runbook without private supplier knowledge.

Score the pilot on accepted output, evidence completeness, rework, incident behavior, control adherence, recovery, exit, and complete cost. Do not scale merely because the supplier was responsive or the demo looked polished.

Contract controls that match the operating model

The executed agreement and work orders should map to technical controls. Consider qualified review of:

  • entities, services, roles, instructions, data, assets, systems, facilities, locations, and permitted people;
  • purpose, confidentiality, security, personal-data assistance, assessments, subprocessors, incident support, deletion or return, and compliance evidence;
  • source, background materials, dependencies, generated assets, model and dataset rights, inventions, assignment, waivers where available, and third-party restrictions;
  • production and OT access as a separately approved privilege, not an implied part of support;
  • maintenance-order content, named approver, session expiry, monitoring, prohibited commands, emergency route, rollback, and safe-stop authority;
  • acceptance tests, artifact identity, documentation, operational evidence, defect handling, service levels, and recovery objectives;
  • notification triggers that are faster and broader than the final legal notice decision when operationally necessary;
  • insurance and allocation language based on the real service and risk rather than a generic template;
  • audit or assessment mechanics that protect legitimate security and confidentiality interests while providing useful evidence; and
  • suspension, credential revocation, transition assistance, repository and account transfer, data disposition, subcontractor closure, and survivals.

The outsourcing contract checklist and source-code and IP guide provide broader procurement context. They do not replace Indiana, federal, sector, destination-country, or fact-specific review.

Red flags for an Indiana buyer

  • “We are CDPA compliant” without operation-level instructions, rights evidence, subprocessor facts, or deletion/return proof.
  • “We only need read access” when the account can export, execute, alter a view, invoke an API, or bridge into another system.
  • One supplier group has ordinary development, staging, production IT, and production OT permissions.
  • A permanent remote tunnel or shared emergency account exists without a named session owner and automatic expiry.
  • The provider tests directly in production because a twin or representative environment is “too expensive.”
  • A maintenance change is rebuilt during the window instead of deploying the accepted artifact.
  • “Indiana time” appears without a site, county, IANA zone, date, or daylight-saving transition test.
  • State of Indiana vendor policies are presented as universal private-sector law—or ignored when the actual State contract activates them.
  • The supplier promises final breach determination before notifying the buyer of credible facts.
  • Recovery means restoring a server but does not cover configuration, engineering state, device logic, credentials, data integrity, or safe operation.
  • The exit export omits scripts, dependency sources, model/data lineage, configuration, runbooks, maintenance history, credentials, or accepted evidence.
  • A provider is described as a partner, certified specialist, local team, or prior client provider without evidence and permission.

Frequently asked questions

International delivery is not categorically prohibited. The answer depends on the buyer, work, data, system, contract, sector, destination, people, and current law. Classify each operation before access and obtain qualified advice where the facts require it.

Does Indiana’s CDPA apply to every Indiana business?

No. The current law uses defined applicability paths and exemptions. Preserve the actual calculation and analysis. Even when Article 15 does not apply, contracts, security duties, other laws, customer requirements, and sound engineering controls may still matter.

Can an overseas processor handle Indiana consumer data?

Do not answer from location alone. Determine applicability and roles, define instructions and purpose, evaluate security and subprocessors, support rights and assessments, confirm contractual and other transfer restrictions, and test deletion, return, incident, and exit. The buyer remains responsible for its own decisions.

Can an international engineer remotely maintain an Indiana factory system?

Capability is not authority. Use the facility’s applicable safety, engineering, security, vendor, contract, and regulatory requirements. Prefer isolated engineering and representative testing. If live access is justified, issue a named, limited, monitored, expiring session with buyer observation, hard-stop authority, rollback, and recovery evidence.

Should Indiana manufacturers choose nearshore teams?

Nearshore cities can provide useful overlap, while other regions may provide deeper specialist pools or follow-the-sun capacity. Split the workload first and compare named teams, cities, evidence, complete cost, and authority coverage. Do not select a region by label alone.

Which time zone should an Indiana company use?

Use the actual buyer site. Most counties are Eastern; twelve listed northwest and southwest counties are Central. Store the applicable IANA identifier and calculate dated overlap for each contributor city.

Does this page imply Outsourcing.ai has an Indiana office or Indiana clients?

No. This is a state-specific buyer guide, not a local-presence, customer, certification, government-approval, or prior-work claim.

Decision

The best Indiana outsourcing arrangement is not the one offering the broadest technical access. It is the one that makes each permission explainable and reversible.

First classify the operation. Keep consumer-data processing, ordinary software engineering, digital-twin work, production IT, production OT, and State-contract duties in their own lanes. Then connect each lane to a named instruction, environment, person, location, account, approval, evidence packet, incident route, rollback, recovery test, and exit. A buyer-owned maintenance-authority interlock lets an international team contribute deeply without converting expertise into standing production authority.

Use the project brief generator to structure the first work package, the provider scorecard to compare evidence, and the provider evaluation guide to test the actual team before a larger commitment.

For a neighboring two-zone decision where operation-specific controller or processor status, insurance-licensee evidence, and Commonwealth-system access need separate treatment, use the Kentucky outsourcing buyer guide.

Evidence ledger

Sources used on this page

  1. 2026 Indiana Code, Title 24 — Trade Regulation — Indiana General Assembly. Supports: Current official code source for Article 15 consumer-data duties, controller and processor roles, impact assessments, enforcement, and Article 4.9 security-breach provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  2. Consumer Data Bill of Rights — Office of the Indiana Attorney General. Supports: Current January 1, 2026 CDPA effective date, applicability summary, consumer rights, controller and processor explanation, privacy-notice expectations, and Attorney General complaint path. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  3. Privacy Toolkit 2026 — Indiana Cybersecurity Hub. Supports: Current Indiana privacy-by-design, data-processing-agreement, vendor breach-notification, access-control, encryption, patching, training, and incident-response guidance. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  4. Security Breach FAQs and Notification Form for Businesses — Office of the Indiana Attorney General. Supports: Current official explanation of covered computerized-data breaches, owner notification, consumer and Attorney General notification, consumer-reporting-agency path, and notification form. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  5. Indiana Time Zone Information — State of Indiana. Supports: Official list of the twelve northwest and southwest Indiana counties on Central time and confirmation that the remainder of Indiana uses Eastern time with daylight saving time. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  6. Get Prepared: Critical Infrastructure — Indiana Department of Homeland Security. Supports: State treatment of critical manufacturing as an interconnected cyber-dependent infrastructure sector where disruption can affect other sectors. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  7. Indiana Office of Technology Policies, Procedures and Standards — Indiana Office of Technology. Supports: Current state-agency and vendor policy index, including Indiana RAMP, data classification, remote access, software development, third-party risk, incident, resilience, and maintenance policies; used only for the separately activated State-work lane. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  8. Cybersecurity Framework Version 1.1 Manufacturing Profile — National Institute of Standards and Technology. Supports: Voluntary risk-based manufacturing cybersecurity profile covering industrial control systems, remote access, authorization, monitoring, recovery, and manufacturing-system priorities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  9. Manufacturing Profile Low Impact Example Guide, Volume 2 — National Institute of Standards and Technology. Supports: Manufacturing example for registered vendors, approved maintenance orders, managed VPN access, selected-system access, monitoring, disabling access after work, and restoration checks. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  10. Protecting Information and System Integrity in Industrial Control System Environments — National Cybersecurity Center of Excellence. Supports: Manufacturing IT and OT integration, remote-access risk, integrity protection, authentication, authorization, monitoring, allowlisting, and anomaly-detection design. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  11. Operational Technology Security Publications — National Institute of Standards and Technology. Supports: Maintained official index for current OT security, remote-access, backup, manufacturing integrity, response, and recovery publications. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  12. Secure by Demand for Operational Technology Owners and Operators — Cybersecurity and Infrastructure Security Agency. Supports: Current procurement considerations for OT products, including authentication, vulnerability, logging, default-setting, legacy-protocol, ownership, and lifecycle questions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  13. IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained identifiers and transition rules for calculating dated overlap between the actual Indiana buyer location and each proposed contributor city. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  14. Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained methodology for secure-development requirements, protected environments, provenance, release integrity, vulnerability response, and buyer-supplier evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  15. Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for investigating contributor and assignment questions rather than assuming one Indiana contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.

Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.