Kentucky buyer guide
Outsourcing software development from Kentucky
A Kentucky buyer guide to international software and AI outsourcing: current processor roles, insurance and State-system boundaries, two-zone operations, incidents, cost, and exit.

Kentucky outsourcing at a glance
| Proposed work | First buyer decision | Evidence required before access |
|---|---|---|
| Ordinary application, automation, data, or AI engineering without covered personal or sector data | Prove the clean boundary rather than assuming a repository is harmless | Work package, identities, cities, accounts, data classification, synthetic test set, dependencies, build path, acceptance, release owner, and exit |
| Personal-data processing within the current Kentucky Consumer Data Protection Act perimeter | Decide applicability and the role for each operation, not for the supplier in general | Threshold and exemption record, data-purpose map, controller instruction, rights support, assessment decision, binding contract, subprocessors, safeguards, evidence, return or deletion |
| System or data of a covered Kentucky insurance licensee | Decide whether the insurer’s distinct information-security and event program applies | Licensee and exemption decision, nonpublic-information inventory, supplier due diligence, application test evidence, access control, audit trail, incident plan, notice route, annual oversight inputs |
| Commonwealth agency or State-system work | Read the actual solicitation, executed contract, system boundary, COT policy, KITS requirement, and approved exception | Clause register, data and system classification, need-to-know role, approved endpoint and remote path, session monitoring, privileged-command rationale, incident owner, acceptance, revocation, closeout |
| Supplier discovers a possible event involving Kentucky information | Relay preserved facts to the correct buyer owner immediately; do not let a supplier declare the legal outcome | Discovery time, system, owner or licensee, data elements, acquisition and harm facts, containment, evidence location, resident or licensee scope, known recipients, update cadence, decision owner |
| Kentucky buyer operates across the federal Eastern-Central boundary | Name the actual site or city before promising overlap, support, or incident coverage | Buyer location, IANA zone, contributor cities and zones, dated overlap, daylight-saving transitions, authority window, backup owner, handoff packet, escalation route |
These lanes are classification prompts, not legal conclusions. A statute may not apply because an organization, record, processing operation, or threshold is outside its perimeter. A different federal, state, sector, contractual, or destination-country rule may still apply. Qualified owners should determine the actual perimeter and preserve the reasoning.
The distinct Kentucky model: a context-to-authority control plane
The Kentucky-specific lesson is operational: a supplier’s role follows what it does with a specific operation, while its authority should follow an even narrower approved work order.
KRS 367.3619 says role is a fact-based determination that depends on the context in which personal data is processed. A processor remains a processor while it continues to adhere to the controller’s instructions for that operation. That is more useful to an engineering buyer than a one-time vendor label. It implies a live control plane with four separate lanes:
- Ordinary delivery: bounded engineering artifacts, synthetic or minimized data, isolated build systems, and buyer-owned acceptance and release.
- Consumer-data processing: exact instructions, purpose, fields, rights support, assessment inputs, subprocessor path, safeguards, evidence, and deletion or return.
- Insurance work: the licensee’s own risk, nonpublic-information, third-party, application-testing, audit, continuity, incident, and oversight program.
- Commonwealth work: only the controls activated by the real agency, procurement, contract, system, and approved State policy perimeter.
The control plane should exist in identity groups, repository permissions, data views, prompt and model configuration, network routes, service accounts, deployment workflows, remote sessions, approval records, logs, retention jobs, incident playbooks, and closeout. A policy slide is not enough. If one permanent account can cross all four lanes, the design has collapsed.
At the center, keep a buyer-owned context switch. It may route a proposed operation forward, restrict it, require assessment, move it to a sector lane, or stop it. The supplier can provide evidence and advice. The buyer retains applicability, role, risk acceptance, privileged access, notification, release, and return-to-service decisions.
Build the operation-and-authority ledger first
Do not begin with country rankings or hourly rates. Begin with a ledger row for every collection, access, transformation, model call, code change, support view, export, deployment, privileged command, incident action, deletion, and return. At minimum, record:
- business process, product, system, environment, repository, dataset, model, interface, and accountable buyer owner;
- exact data fields, data subjects, source, purpose, sensitivity, retention, replicas, logs, backups, training or retrieval use, and prohibited reuse;
- buyer entity, supplier entity, subprocessor, contributor name, employer, city, country, account, managed device, network path, and approved hours;
- applicable lane, threshold or exemption reasoning, controller or processor role for this operation, instruction version, assessment decision, and qualified reviewer;
- permitted reads, writes, transformations, model calls, exports, commands, deployments, and administrative actions, plus actions that remain prohibited;
- source repository, branch policy, build runner, dependency source, artifact store, signing or provenance step, staging target, production target, and release owner;
- access start, expiry, approver, supervisor where needed, monitoring source, revocation trigger, exception, and evidence location;
- rights-request, audit, incident, recovery, continuity, return, deletion, and legal-hold responsibilities; and
- change triggers: new purpose, field, data source, consumer group, model, tool, recipient, subprocessor, environment, city, country, privilege, retention period, or release path.
A spreadsheet can prototype the ledger, but enforcement belongs in systems. Translate approved rows into groups, scoped tokens, column or row filters, environment boundaries, policy-as-code, CI checks, deployment approvals, expiring remote access, and deletion jobs. Compare logs and configuration back to the ledger. A contract cannot compensate for an architecture that makes unauthorized combinations or exports easy.
Lane one: ordinary delivery is still controlled delivery
An operation outside a particular privacy or sector statute is not an uncontrolled operation. Ordinary work can still expose credentials, proprietary code, customer configuration, unreleased strategy, vulnerabilities, or production power.
Create a clean engineering lane:
- synthetic, masked, minimized, or deliberately constructed test data;
- separate development and production identities;
- no production secrets in repositories, tickets, chat, screenshots, prompts, or sample payloads;
- allowlisted dependency sources and automated software-composition checks;
- protected branches, peer review, reproducible builds, and buyer-controlled signing or release;
- isolated test environments with representative failure and rollback cases;
- an evidence packet for every accepted increment; and
- immediate account and token revocation at role change or exit.
The supplier may implement, test, document, and recommend. The buyer should retain product priority, architecture exceptions, risk acceptance, secrets, production deployment, incident notification, and final acceptance. If the supplier needs temporary production evidence, create a new approved operation instead of silently widening the ordinary lane.
Use the project brief generator to define outcome, systems, boundaries, constraints, evidence, and acceptance before asking providers for estimates. Then use the provider scorecard to compare how each proposal handles the control plane, not merely its résumé and rate.
Lane two: make the current Kentucky privacy role executable
Kentucky’s Consumer Data Protection Act took effect January 1, 2026. Its application, exclusions, data exemptions, consumer rights, controller duties, processor contract, assessments, deidentified-data controls, permitted processing, and enforcement should be read from the current codified chapter. Do not reduce that review to “Kentucky resident data.” Determine the covered entity, threshold, operation, person, record, exemption, and role.
For an operation treated as controller-to-processor work, KRS 367.3619 supplies a useful implementation checklist. The processor follows controller instructions and assists with consumer-rights requests, security and breach obligations, and assessment information. The binding contract sets the nature and purpose, type of data, duration, and party rights and obligations. It also addresses confidentiality, deletion or return, compliance information, reasonable assessment or qualifying independent assessment, and written subprocessor obligations.
Convert those requirements into artifacts:
| Contract or role concept | Executable supplier evidence |
|---|---|
| Processing instruction | Versioned operation ID, approved fields, purpose, input, output, tool, model, recipient, retention, and prohibited actions |
| Rights assistance | Tested locate, export, correct, delete, restrict, and appeal-support path across primary stores, derived data, logs, queues, caches, and subprocessors |
| Security assistance | Data-flow diagram, identities, least privilege, encryption, logging, vulnerability handling, incident relay, recovery, and evidence preservation |
| Assessment support | System and model behavior, benefit, risk, safeguards, consumer expectation, data minimization, alternatives, testing, residual risk, and change history |
| Confidentiality | Contributor roster, employer or contractor relationship, training, signed obligation, managed account and device, and termination control |
| Return or deletion | Inventory-based return, deletion execution, replica and backup treatment, subprocessor confirmation, exception or legal hold, and buyer acceptance |
| Compliance information or assessment | Current evidence mapped to the operation, named gaps, remediation owner and date, report scope, assessor independence where used, and accessible underlying records |
| Subprocessor flow-down | Exact legal entity, service, location, data, purpose, terms, technical controls, incident route, evidence, change notice, and offboarding |
The most important runtime control is a role-drift stop. Stop the operation when a supplier proposes a purpose not in the instruction, combines buyer data with another dataset, selects a new recipient, retains output for its own use, changes model or location, decides how consumer data will be used, or moves from implementation into independent product decisions. The buyer then reclassifies the operation, updates contracts and assessments where needed, and changes access before work resumes.
KRS 367.3621 makes assessment evidence relevant for targeted advertising, sale, certain profiling risks, sensitive data, and other heightened-risk processing. An outsourced AI feature therefore needs more than a model card. Preserve the exact use case, affected people, input and derived fields, benefit, foreseeable risk, alternatives, safeguards, validation population, error handling, human authority, monitoring, appeal or correction path where relevant, and the delta from the last approved version. A supplier can supply technical facts; the controller retains the assessment and acceptance decision.
Lane three: do not collapse insurance work into the general privacy lane
A Kentucky insurance licensee may sit outside or differently within a general consumer-privacy analysis while still having a distinct information-security program under KRS Chapter 304. KRS 304.3-756 addresses nonpublic information, information systems, risk assessment, authorized access, secure development, evaluation of externally developed applications, authentication, monitoring, audit trails, environmental and technology failures, third-party service providers, incident response, executive or board reporting, and changing outsourcing arrangements.
Treat this as its own lane. The buyer first establishes whether it is a licensee, whether an exemption or deemed-compliance provision applies, what system and nonpublic information are in scope, and which obligations remain. The outsourcing work order then maps into the licensee’s actual program.
Before access, request evidence that answers:
- What nonpublic information and systems can the provider or subprovider technically reach?
- Which individuals are necessary and appropriate, and who screened and authorized them?
- How does the provider test an externally developed application before the licensee uses it?
- Which logs reconstruct access, change, material transactions, deployment, and incident response?
- How are remote sessions authenticated, encrypted, restricted, monitored, and revoked?
- How do the provider’s controls address identified threats and the sensitivity of the information?
- How do continuity, backup, restoration, and environmental-failure plans interact with the service?
- What provider evidence feeds the licensee’s annual review, executive oversight, remediation record, or certification process?
- How will the provider notify the licensee early enough for the licensee to investigate and meet its own decisions and deadlines?
- How are records returned, deleted, retained, or preserved when the relationship or system changes?
KRS 304.3-760 treats a cybersecurity event at a third-party service provider as part of the licensee’s event path and ties timing to provider notice or the licensee’s actual knowledge, depending on the provision. The contract should therefore require an operational alert well before anyone has a perfect legal conclusion. The first message should identify discovery time, system, current scope, possible nonpublic information, containment, evidence, provider and subprovider involvement, known recipients, and the next update. It should not delay because the supplier is still debating labels.
Do not advertise a provider as “Kentucky insurance compliant” from a generic certificate. Ask which precise controls, operation, environment, people, data, and evidence were within an assessment, what was excluded, when the evidence was collected, and whether the buyer can inspect the underlying artifacts needed for its own program.
Lane four: State policies apply only when the real State-work perimeter activates them
The Commonwealth Office of Technology publishes enterprise policies, security standards, incident materials, and architecture guidance for appropriate agencies. Those documents do not automatically govern every private Kentucky company. Conversely, a private supplier should not assume its ordinary commercial controls satisfy a Commonwealth solicitation or contract.
For actual State work, build a clause-and-control activation record from:
- the procuring entity and its authority;
- the solicitation, questions and answers, amendments, proposal commitments, award, and executed contract;
- data ownership and classification;
- system authorization and hosting boundary;
- applicable COT policy and KITS version;
- approved products, endpoints, network paths, and exceptions;
- subcontractor and location disclosures;
- testing, acceptance, incident, audit, retention, records, and closeout clauses; and
- named agency owners for security, privacy, procurement, release, incident, and records decisions.
Current CIO-072 frames State access around need-to-know and least privilege and includes consultants, contractors, vendors, and other workers. The current enterprise security-controls document describes authorization before remote connection, virtual endpoints, monitored remote access, protected sessions, managed access points, and documented rationale for privileged remote commands. Translate only the controls actually applicable to the work into a session record.
A State-system supplier should receive an expiring role for the named system and work order, through the approved endpoint and route, during the approved window. Log session creation, authentication, system reached, commands or changes, files moved, alerts, supervisor or owner where required, termination, and access removal. Keep the agency’s incident and release decisions with named State owners. Do not reuse State-system credentials for commercial work or claim that public-sector authorization proves general provider quality.
Design the incident relay before an event
Kentucky has more than one potential incident path. KRS 365.732 addresses an information holder that owns or licenses certain information and a holder that maintains information it does not own. The insurance provisions add a distinct licensee and third-party-service-provider path. State systems have their own policy, contract, and agency response boundary. Other laws, contracts, and jurisdictions may add more.
Use one technical intake and separate decision branches:
- Supplier signal: any suspected unauthorized access, acquisition, disclosure, change, loss, misuse, or material availability event is reported immediately under the contract’s operational threshold.
- Evidence preservation: preserve cloud, identity, endpoint, application, database, model, network, ticket, communication, and subprovider records under buyer direction.
- Ownership and lane classification: identify the system owner, data owner or licensee, applicable private, insurance, State, contractual, and other-jurisdiction lanes, without treating one as a substitute for another.
- Scope and harm facts: identify affected systems, records, fields, people, transactions, acquisition indicators, misuse indicators, availability impact, and current uncertainty.
- Containment and continuity: restrict access, rotate secrets, isolate affected components, maintain safe service, recover from known-good artifacts, and record every material action.
- Buyer decisions: named qualified owners decide legal characterization, law-enforcement coordination, regulator, resident, producer, customer, partner, insurer, or public communication.
- Updates and reconciliation: provide a fixed update cadence, correct preliminary statements, reconcile recovered systems and records, test remediation, and retain the approved evidence package.
“Without unreasonable delay,” “as soon as reasonably practicable,” a sector deadline, and a contract’s faster signal are not interchangeable. The supplier should meet the earliest operational relay promised while the buyer determines which legal branches and clocks apply. A contract that starts notification only after the supplier confirms a statutory breach is too late for resilient decision-making.
Name the Kentucky clock, site, and authority window
Kentucky spans Eastern and Central time. The current federal boundary in 49 CFR 71.5 follows county lines and other described boundaries; municipalities on the boundary are placed in Central time. Do not ask a provider to “cover Kentucky hours.” Name the buyer’s actual location and maintained IANA zone, such as the relevant America/* identifier chosen from the location facts, then calculate dated overlap with every contributor city.
For each recurring operation, publish:
- buyer site or city and maintained zone identifier;
- contributor city, country, and maintained zone identifier;
- UTC meeting time and each local display time;
- applicable daylight-saving transition dates;
- sustainable normal overlap, not a temporary sales-calendar maximum;
- decision authority during and outside overlap;
- backup owner and escalation method;
- handoff cutoff and evidence packet; and
- holiday, leave, outage, and clock-change test cases.
Split calendars by work type. Product discovery may need live overlap. Implementation can use an evidence-rich relay. Release and privileged access may be restricted to a narrower buyer-controlled window. Incident intake may be continuous while notification and risk decisions remain with named buyer owners. If a company has sites on both sides of the Kentucky boundary, name the site for each system instead of choosing a corporate default.
Select the engagement model before the destination
The best country depends on the work and control lane. Choose the commercial and operating model first:
- Managed project: useful for a bounded outcome with acceptance milestones and a clear handover, provided the buyer can see the real contributors and subprocessors.
- Staff augmentation: useful when the buyer has mature product, architecture, security, privacy, review, and release ownership. Direct task control increases the need for clear employer, classification, confidentiality, IP, and destination-country review.
- Specialist engagement: useful for a narrow assessment, integration, model evaluation, security review, or recovery task. Prevent the specialist’s advice from becoming unreviewed production authority.
- Build-operate-transfer or dedicated team: useful only with explicit hiring, knowledge, account, repository, asset, data, contract, and continuity milestones. A future transfer promise is not present buyer control.
Then compare named countries and cities against the actual role and authority ledger: skills, overlap, language, employment model, contributor identity, IP path, privacy and transfer constraints, sanctions and export review, infrastructure, continuity, subprocessor transparency, commercial stability, and exit. Use the nearshore-versus-offshore comparison as an operating-model input, not a country verdict.
No state page can determine whether every destination is suitable. Verify the employer and contributor chain, destination-country law, IP assignment, government-access and transfer questions, tax and employment exposure, sanctions, export controls, sector restrictions, and the buyer’s own contracts. WIPO’s directory is a starting point for official IP institutions, not proof of assignment or enforceability.
Normalize complete cost around buyer-retained work
An hourly rate is not a complete-cost comparison. Normalize every proposal over the same period and output:
complete cost = supplier fees
+ buyer product and architecture time
+ privacy, security, insurance, legal, and procurement review
+ environment, tooling, identity, logging, and connectivity
+ assessment, testing, assurance, and release evidence
+ travel, overlap, handoff, and coordination
+ incident, continuity, recovery, and exit readiness
+ expected rework and uncertainty reserve
- buyer-accepted credits
Do not monetize an unsupported “quality multiplier.” Compare observable scenarios. For each provider, show expected supplier fees, retained buyer hours by role, one-time setup, recurring control work, expected rework, risk reserve, and assumptions. Keep optional scope separate. State currency, taxes, payment timing, rate validity, inflation or index treatment, and who absorbs tool or cloud changes.
Low price may reflect excluded assessment support, thin logs, shared credentials, undisclosed subprocessors, untested applications, no two-zone coverage, or a handover that exists only as a promise. High price may simply reflect overhead. The winning proposal is the one that provides the best risk-adjusted evidence for the required outcome and control lane.
Run a paid Kentucky role-drift pilot
A representative six-to-eight-week pilot should test the relationship under real boundaries without exposing the highest-risk system first.
Week 0 — baseline. Select one useful increment. Record entities, contributors, cities, zones, systems, data, roles, instructions, subprocessors, environments, access, contract terms, evidence, incident owners, and exit conditions. If insurance or State lanes may apply, have the appropriate buyer owner decide that perimeter before access.
Week 1 — clean room. Provision named accounts, managed access, synthetic or minimized data, repository and dependency controls, isolated build and test, logging, secrets handling, and buyer-controlled release. Test revocation immediately.
Weeks 2–3 — delivery and evidence. Produce a thin vertical slice. Require reviews, tests, provenance, known limitations, security results, data-flow updates, assessment inputs, and a handoff packet. Compare actual contributors, tools, fields, recipients, and locations to the ledger.
Week 4 — role-drift exercise. Propose a realistic change: new model, field, purpose, recipient, subprocessor, production view, privileged command, or destination. The correct behavior is to stop, record the delta, reclassify, approve or reject, update contracts and controls, and only then continue.
Week 5 — incident and clock exercise. Inject an ambiguous supplier signal outside primary overlap. Measure discovery-to-relay time, preserved facts, correct lane routing, owner response, updates, containment, safe continuity, and whether the team uses the actual Kentucky site zone.
Week 6 — release and exit. Rebuild from controlled sources, verify acceptance, revoke accounts and tokens, export evidence and buyer-owned artifacts, execute return or deletion, handle replicas and backups, reconcile subprocessors, and have someone other than the original implementer operate the result.
Score outcomes, not presentation: accepted functionality, escaped defects, review latency, reproducibility, role-drift stops, access exceptions, incident relay, recovery, documentation freshness, knowledge concentration, and exit completion. Scale only the lanes that pass.
Put authority and evidence in the contract
The agreement, statement of work, data-processing terms, security schedule, sector addendum where needed, and exit plan should align. Address:
- exact buyer and supplier entities and authorized signers;
- engagement model, outcome, exclusions, acceptance, change control, fees, and payment;
- contributor and subprocessor transparency, locations, employer chain, screening where justified, and change notice;
- operation-specific roles, controller instructions, purpose, data types, duration, rights support, assessment inputs, confidentiality, safeguards, evidence, audit, and return or deletion;
- supplier prohibition on independent purpose, undisclosed combination, unapproved model use, sale, unrelated training, or recipient change;
- accounts, devices, endpoints, network paths, secrets, environments, privileged access, monitoring, expiry, revocation, and exceptions;
- secure development, dependency control, testing, provenance, vulnerability handling, release, rollback, and recovery;
- insurance-licensee or Commonwealth requirements only when the verified perimeter activates them;
- early operational incident signal, preserved evidence, update cadence, buyer-controlled notifications, cooperation, and cost allocation;
- IP ownership, present assignment where appropriate, contributor flow-down, background materials, open-source and model/data licensing, and destination-country review;
- continuity, key-person replacement, records, knowledge transfer, transition assistance, return, deletion, and deletion exceptions; and
- precedence among documents so a generic supplier policy cannot silently override the work order or required control.
Avoid a promise that the supplier “complies with all laws.” It is too broad to operate and too vague to test. Map obligations to artifacts, owners, systems, triggers, and review dates. Do not publish customer names, platform names, partnerships, certification claims, or prior-work implications without current evidence and written naming permission.
Kentucky outsourcing red flags
Pause or reject a proposal when:
- it declares the supplier a processor for all work without operation-level facts;
- it cannot show the instruction that limits purpose, data, tool, model, recipient, retention, and location;
- a new model, subprocessor, or data combination does not trigger reclassification;
- “HIPAA,” “GLBA,” “insurance,” or another exclusion is used as proof that no control program applies;
- an insurance technology provider substitutes a generic certificate for application, access, audit, incident, and buyer-program evidence;
- Commonwealth policy is marketed as a private-sector credential or ignored on actual State work;
- vendor remote access is permanent, shared, unmonitored, or able to cross environments;
- the provider promises “Kentucky hours” without a site, zone, dated overlap, and authority owner;
- incident notice waits for the provider to confirm a legal breach;
- subprocessors, contributors, employers, countries, or technical recipients are hidden;
- the buyer cannot reproduce a build, inspect accepted evidence, revoke access, or operate without the supplier;
- intellectual-property language covers the contracting company but not the actual contributor chain;
- deletion ignores logs, derived data, model artifacts, caches, queues, backups, and subprocessors; or
- the price excludes the buyer work needed to make the service safe and acceptable.
Frequently asked questions
Can a Kentucky company outsource software or AI work outside the United States?
Yes, in general, but suitability depends on the buyer, operation, data, system, contract, sector, contributor chain, destination, and applicable law. International location does not remove Kentucky or federal obligations, and Kentucky law is not the only relevant law. Classify each operation and retain buyer authority over risk acceptance, privileged access, release, incident notification, and exit.
Does the Kentucky Consumer Data Protection Act apply to every Kentucky business?
No. The current chapter contains applicability thresholds, entity exclusions, data exemptions, and operation-specific provisions. Determine the actual entity, threshold, record, purpose, and role from current law. Do not treat “Kentucky resident data” as the complete test, and do not treat an exemption as permission to ignore contracts, security, other laws, or consumer expectations.
Is an overseas development company automatically a processor?
No. KRS 367.3619 makes controller-versus-processor status a fact-based determination tied to the context of a specific processing operation. A supplier adhering to the controller’s instructions for that operation remains a processor. Independent purpose, combination, recipient, retention, or product decisions can require a role and control review.
What should a Kentucky processor contract cover?
For covered work, review current KRS 367.3619 with qualified counsel. It addresses instructions and assistance plus a binding contract defining processing nature and purpose, data type, duration, party rights and obligations, confidentiality, return or deletion, compliance evidence, assessments, and written subprocessor obligations. The operational design should make each term testable.
When does a Kentucky data protection assessment matter?
Current KRS 367.3621 identifies several heightened-risk categories, including targeted advertising, sale, certain profiling risks, sensitive data, and other processing presenting heightened risk. Record the exact operation, benefits, risks, safeguards, consumer expectations, alternatives, evidence, owner, approval, and change triggers. Do not reuse an assessment after the relevant facts change without reviewing the delta.
Does an insurance licensee use only the general privacy lane?
Not necessarily. Kentucky’s insurance data-security statutes establish a distinct program for covered licensees, subject to their applicability and exemption provisions. That program includes risk assessment, third-party due diligence, application testing, access, audit trails, incident response, oversight, and changing outsourcing arrangements. Keep it separate from the general consumer-data analysis.
Do Commonwealth security policies apply to every Kentucky company?
No. Use Commonwealth policies for the agency and State-system perimeter to which they actually apply through authority, procurement, contract, policy, and system facts. Do not generalize State remote-access rules to all private buyers, and do not ignore them when the actual State work activates them.
How quickly should an overseas supplier report a possible incident?
The contract should require an immediate operational signal with preserved facts, followed by updates. The buyer then determines which private, insurance, State, contractual, federal, other-state, or destination-country paths and clocks apply. Waiting for the supplier to confirm a statutory breach can deprive the buyer of investigation and notification time.
Which Kentucky time zone should a provider use?
The zone of the actual buyer site or responsible owner, not a generic statewide label. Kentucky crosses the Eastern-Central boundary. Record the site, maintained IANA identifier, contributor cities, dated overlap, daylight-saving transitions, authority windows, backup owner, and handoff standard.
Should Kentucky buyers choose nearshore delivery automatically?
No. Nearshore locations may improve live overlap; other locations may support deep specialist work or relay coverage. Compare named cities, actual contributors, sustainable hours, role boundaries, evidence, continuity, legal and IP facts, cost, and exit. Geography is one input, not the decision.
How long should a first engagement be?
Use a paid six-to-eight-week pilot sized to produce a real accepted increment and test a role change, incident relay, two-zone schedule, revocation, reproducibility, and exit. Avoid both an unpaid artificial exercise and a broad production commitment that makes correction expensive.
How should a Kentucky buyer compare bids?
Normalize the same scope, assumptions, roles, data, environments, evidence, buyer-retained work, setup, recurring controls, rework, continuity, and exit. Score the provider’s demonstrated ability to stay inside instructions and produce buyer-usable evidence. Do not select from hourly rate, country label, certification, or sales references alone.
What should happen at exit?
Revoke accounts, tokens, endpoints, and network routes; transfer repositories, build and deployment configuration, artifacts, documentation, logs, keys under the approved custody model, issue history, model and data records, and operating knowledge; execute return or deletion across subprocessors and replicas; record lawful exceptions; and prove that the buyer or replacement team can build, release, recover, and operate without the departing supplier.
The buyer decision
Kentucky does not need another page that ranks “cheap offshore developers.” It needs an executable decision: classify each operation, bind role to current facts, bind authority to an even narrower work order, keep consumer, insurance, and Commonwealth lanes distinct, run the actual site clock, preserve early incident facts, and make evidence and exit part of delivery.
If a provider can work inside that control plane, survive a role-drift stop, produce the required artifacts, release only through buyer authority, and leave the buyer able to operate, international delivery can be evaluated on its real merits. If it needs permanent trust, vague roles, hidden recipients, generic compliance claims, or an exit that cannot be tested, the low rate is not a saving.
Use the outsourcing RFP guide to request comparable evidence, the contract checklist to convert the chosen lane into obligations, and the source-code and IP guide to trace contributor, repository, dependency, model, and assignment facts before scale.
Evidence ledger
Sources used on this page
- Kentucky Revised Statutes, Chapter 367 — Kentucky Consumer Data Protection Act — Kentucky Legislative Research Commission. Supports: Current codified Kentucky consumer-data sections, including application, rights, controller duties, processor contracts, assessments, deidentified data, permitted processing, enforcement, and separately displayed future-effective text. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- KRS 367.3619 — Data processing responsibilities and controller-processor contracts — Kentucky Legislative Research Commission. Supports: Current processor instruction, rights and security assistance, assessment support, contract content, confidentiality, return or deletion, compliance evidence, assessment, subprocessor, and fact-based role provisions effective January 1, 2026. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- KRS 367.3621 — Data protection impact assessments — Kentucky Legislative Research Commission. Supports: Current assessment triggers and benefit-risk, safeguard, consumer-expectation, confidentiality, comparable-operation, and Attorney General production provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- KRS 365.732 — Notification of a computer security breach — Kentucky Legislative Research Commission. Supports: Current private information-holder breach definition, owner or licensee relay, affected-resident notice, timing, investigation, restoration, and law-enforcement-delay provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- KRS 304.3-756 — Insurance written information security program — Kentucky Legislative Research Commission. Supports: Current insurance-licensee risk assessment, authorized access, externally developed application testing, audit trails, third-party due diligence, safeguards, incident response, annual oversight, and outsourcing-change provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- KRS 304.3-760 — Insurance cybersecurity-event notification — Kentucky Legislative Research Commission. Supports: Current insurer and third-party-service-provider event treatment, deadline-start, agreement, commissioner, ceding-insurer, producer, and consumer-notice paths. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- CIO-072 IT Access Control and User Access Management Policy — Commonwealth Office of Technology. Supports: Current reviewed Commonwealth least-privilege and need-to-know access-policy boundary for employees, consultants, contractors, vendors, and other State-system users. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Enterprise Security Controls and Best Practices — Commonwealth Office of Technology. Supports: Current Commonwealth remote-access authorization, virtual endpoint, monitoring, encryption, managed access point, privileged-command rationale, service-provider, and audit controls; used only in the State-work lane. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 49 CFR 71.5 — Boundary line between eastern and central zones — Electronic Code of Federal Regulations. Supports: Current federal description of Kentucky's Eastern-Central time-zone boundary and the treatment of municipalities located on the boundary. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained identifiers and transition rules for calculating dated overlap between the actual Kentucky buyer location and each proposed contributor city. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained methodology for secure-development requirements, protected environments, provenance, release integrity, vulnerability response, and buyer-supplier evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for investigating contributor and assignment questions rather than assuming one Kentucky contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.
