Skip to content

Manufacturing

Can manufacturing data stay on our own servers during a data license?

By SourceX Editorial · Updated

Short answer

Yes, manufacturing data can stay in storage you control through most of a data license. The fit check uses metadata only, SourceX never hosts multi-terabyte datasets, and the licensed copy is handed over from your own storage, on an encrypted drive or through a managed transfer. The buyer does receive a prepared copy for its permitted use.

Key takeaways

  • The initial fit check needs metadata only, so no files leave the plant at the start.
  • Production systems do not need inbound access; extracts come from replicas or backups your team controls.
  • Delivery has three routes: your own storage, an encrypted drive, or a managed transfer for smaller packages.
  • A license gives the buyer a prepared copy, so a policy that no copy may ever leave rules licensing out.

Short answer: what stays in your environment and what moves#

Almost everything stays in your environment until delivery, and even then the handover can start from your own storage. The table shows each stage of a typical license and what, if anything, leaves.

The row many IT directors miss is the last one. A license gives the buyer a copy of the prepared dataset for the permitted use, so if company policy says no copy may ever leave, raise that at the fit check; it narrows what is possible.

Short answer: what stays in your environment and what moves
StageWhere the records sitWhat leaves your environment
Fit checkYour systems, untouchedMetadata only: system names, years of history, record families, known restrictions
Inventory and scopingYour systemsField lists, date ranges and approximate volumes
Rights reviewYour contracts and noticesContract terms for review, not records
PreparationArranged deal by deal; large extracts stay in storage you controlPrepared samples, only if you approve
ApprovalYour sign-offRelease authorization
DeliveryYour storage, an encrypted drive or a managed transferThe prepared, licensed copy and nothing else

The three delivery options compared#

The three delivery options are seller storage, an encrypted drive and a managed transfer, and the right one depends on size, bandwidth and policy. SourceX never hosts multi-terabyte datasets, so large packages use the first two.

Each option ends the same way: the handover is recorded so both sides can show what was delivered, when and under which authorization.

The three delivery options compared
OptionBest forWhat your IT team controlsWatch-outs
Seller storageLarge packages in your cloud tenant or file serversThe storage location, the buyer's time-limited access and its revocationScope access to the package only and close it after handover
Encrypted driveVery large archives such as historian or image data, or plants with limited upload bandwidthEncryption, the key and the shipping recordSend the key through a separate channel and log chain of custody
Managed transferSmaller, text-heavy packages such as work orders or NCRsWhat is uploaded and whenConfirm the upload matches the approved package exactly

Which plant records are usually small, and which are large?#

Text-heavy plant records such as work orders, NCRs and quotes are usually small, while historian, image and CAD archives are usually large, and size decides the delivery route more than anything else.

Size also shapes preparation. Text needs careful review for names and customer details, while large sensor archives need checks for network and security details and decisions about which tags and time ranges matter. Scoping a narrower slice often removes the need for a drive at all.

  • Usually compact: work orders, NCRs, CAPAs, ECO text, complaint cases, quotes and maintenance notes exported from the ERP, QMS or CMMS
  • Moderate: ERP transaction history with operation-level detail, plus the text of attachments
  • Usually large: process historian archives, machine vision images, inspection scans, CAD vaults and video

What your production network does not need to allow#

A data license does not need inbound access to your production network. No one outside the company needs a VPN into the plant, credentials to the ERP or MES, or a connection to the OT network; your team creates extracts and stages them where policy allows.

OT exports deserve a second look before they leave. Historian tags, PLC exports and network configuration files can reveal IP addresses, controller models and network topology, which are security details rather than training value, and they are removed or excluded.

  • Extract from a reporting replica or restored backup, not the live production database.
  • Use a read-only service account scoped to the tables in the inventory.
  • Stage extracts in a storage location separate from production systems.
  • Encrypt at rest and keep the keys under your own management.
  • Produce a file manifest with record counts and checksums for every delivery.
  • Revoke any buyer access and log the revocation once handover is confirmed.

How a buyer confirms what it received#

A buyer confirms receipt against a manifest, not by looking inside your systems. The manifest lists each file, its record count and its checksum, alongside the data dictionary that explains fields, codes and any values that were masked or banded.

The SourceX Evidence Packet travels with the package. It records provenance, licensing rights, permitted use, the privacy record and release authorization, so the buyer can see what was approved without any access to the source environment.

This also protects the supplier. If a question about scope comes up later, the manifest and the Evidence Packet show exactly which records were released, which makes the license easier to audit and defend.

Illustrative: a foundry that kept everything on site#

Illustrative: a fictional gray and ductile iron foundry runs an on-premises ERP, a QMS and a process historian on its furnaces and molding lines. Its IT director had a firm rule that production data does not go to third-party clouds, and the plant's upload bandwidth is modest.

The fit check covered system names and years of history only. After rights review and preparation, the text-heavy package of maintenance work orders and nonconformance reports was small enough for a managed transfer. The historian archive, far larger, was written to an encrypted drive, shipped with a chain-of-custody record and unlocked with a key sent separately.

At no point did anyone outside the company connect to the plant network. The IT director kept the extraction scripts, the manifest and the revocation log as the company's own record of the license.

How SourceX handles delivery#

Delivery is the last stage of the SourceX five-step transaction, after Supply, Rights, Preparation and Approval. No files move during the initial assessment, the supplier signs off at every step, and large datasets stay in the supplier's own storage or ship on encrypted drives because SourceX never hosts multi-terabyte datasets.

Every delivery records how the handover happened, whether through uploaded files, the supplier's storage or a drive. That record, with the manifest, is what both sides rely on if a question about scope or timing comes up later.

Frequently asked questions

Does our cloud tenant count as our own storage?

Yes. Seller storage means any location your company controls, whether on-premises servers, a private data center or a storage account in your own cloud tenant. What matters is that you set the access, scope it to the approved package and revoke it after handover.

Does the buyer get ongoing access to our systems?

No. The buyer receives the prepared, licensed package and nothing more. There is no live connection to your ERP, MES, CMMS or historian. If future updates are part of a license, each one is prepared, approved and delivered as its own release. Your IT team decides when each release is staged and when access to it closes.

What happens to the data when the license ends?

That depends on the license terms. Agreements commonly address the permitted use, whether trained models may be kept, and what happens to copies of the data at the end of the term, such as deletion or return with certification. These points are negotiated per deal and reviewed with counsel.

Who does the extraction work?

Usually your own IT or operations team, because they know the systems and keep control. The inventory defines exactly which tables, fields and date ranges are in scope, which keeps extraction narrow. Older or heavily customized systems may need a planning conversation before anything is pulled.

Can export-controlled or defense work be part of a license?

No. Export-controlled technical data and defense program records are excluded from scope. ITAR can treat giving a foreign person access information, such as storage credentials, to unencrypted technical data as a release in its own right, which is one more reason controlled material stays out entirely. Plants that do some controlled work separate those records during the inventory, and anything of uncertain status stays out until the classification owner confirms it.

Do we need new storage or software to deliver data this way?

Usually not. Most plants stage extracts on file servers, NAS devices or cloud storage they already run, and use encryption tools their security policy already approves. If an encrypted drive is needed, it is a standard external drive prepared under your own key management and shipped with a custody record.

Sources

  • 22 CFR 120.56(a) provides that technical data is released through visual or other inspection by foreign persons, oral or written exchanges with foreign persons, or the use of access information to cause or enable a foreign person to access, view or possess unencrypted technical data, and 120.56(b) requires authorization before providing such access information to a foreign person. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify