Scoping
Your customers, your contract terms, your shop equipment and any data handling requirements already in play.
Wichita, Kansas
Orca IT supports Wichita businesses remotely from Gilbert, Arizona. Family owned since 2015, never outsourced, and experienced with the drawing control, data security and uptime demands of aircraft manufacturing suppliers.
Overview
Wichita's aircraft manufacturing base and the machine shops, fabricators, tooling houses, coating specialists and engineering firms that feed it make this one of the most concentrated aerospace supply chains in the world. Agriculture, energy and healthcare fill out the rest of the regional economy.
Being a supplier here means three things technically. First, you receive and hold customer engineering data, models, drawings, specifications, that is commercially sensitive and sometimes export-controlled, and your customer expects it kept under access control with a record of who touched it. Second, you must be able to demonstrate quality and traceability, which means the systems holding inspection records, certifications and job history cannot lose data. Third, you get audited, and those audits increasingly include IT security questions that a small shop has no natural way to answer.
We build for exactly those three. Access to engineering data is restricted by group rather than left open on a shared drive, with logging so access is provable and a documented process for granting and revoking it. Quality and traceability systems get immutable backups, tested restores and recorded recovery times. Endpoint detection and response runs on every machine with coverage reporting, multi-factor authentication is enforced, disks are encrypted and verified, patch compliance is measured, and policies exist in writing. That is Pod Guard operating inside Pod Care.
Shop floor technology needs its own handling. CNC controllers, CMM inspection machines and test equipment run software that is tied to specific operating system versions, is often unpatched, and sometimes still moves programs by removable media. We segment those systems onto their own network with explicit firewall rules, replace ad-hoc USB workflows with controlled transfer paths where the machine allows it, image the controller PCs so a failed disk is a swap rather than a rebuild, and log vendor remote access instead of leaving support tunnels permanently open. Nothing gets patched without your equipment vendor's agreement.
On export-controlled data, we are direct: tell us during scoping. Requirements around who may access technical data, where it may be stored and which nationals may view it are real, and they affect design decisions like cloud region, tenant configuration and support access. We would far rather scope that honestly at the start than discover it mid-project. We implement the technical controls and document them; formal determinations belong with your compliance counsel.
Kansas observes daylight saving and Arizona does not, so we sit two hours behind Wichita from March to November and one hour behind from November to March. Your 7:00am first shift is our 5:00am or 6:00am, and our engineers are working through your second shift, which makes maintenance windows straightforward without anyone staying up. Wichita clients often share a pod with our Tulsa and Kansas City accounts; see remote support or the full coverage list.
If your customer contract carries export control or specific data handling terms, raise it on the first call. Any provider who says it makes no difference has not read one.
Included
Six areas that turn an audit question into a document you already have.
Customer models and drawings held under group-based access with logging, plus a documented process for granting and revoking access to each project.
Quality, inspection and certification records backed up immutably, restore-tested on a schedule and documented with real recovery times.
CNC, CMM and test equipment on isolated network segments with explicit firewall rules and controlled program transfer paths.
Machine PCs imaged and documented so a failed drive means a swap and a restore rather than a call to a vendor with a long lead time.
Office systems patched on a schedule with reportable compliance figures, and equipment systems handled only with vendor agreement.
Equipment supplier remote sessions brokered and recorded instead of permanent tunnels nobody remembers opening.
How It Works
Your customers, your contract terms, your shop equipment and any data handling requirements already in play.
Free remote assessment of office and shop systems, identity, network and backups, ranked by audit and operational risk.
Access control, segmentation, backup and endpoint work completed in priority order, with documentation produced alongside.
Flat monthly management with monitoring, patching, help desk and evidence kept current at each Surface Check review.
Two hours from March to November and one hour from November to March, since Arizona does not observe daylight saving time. We cover your first shift from mid-morning onward and are still working during your second shift, which makes scheduled maintenance easy to place without overtime.
Group-based access control rather than open shared drives, logging so access is provable, encryption at rest and in transit, a documented process for granting and revoking project access, and backups that are immutable and tested. The goal is that an audit question about who could see a drawing has a precise answer.
Tell us during scoping and we will design around it, including storage location, tenant configuration and who may provide support access. We implement and document the technical controls. Determinations about what your obligations actually are belong with your compliance counsel, not with an IT vendor.
Not without your equipment vendor's agreement. Those systems are frequently tied to specific operating system versions and unauthorized changes can invalidate support. What we do is isolate them, control access, image them for fast recovery and monitor the infrastructure around them.
We replace uncontrolled personal drives with a defined transfer path: a small number of managed, scanned devices, or a network drop-point where the machine supports it, with the process documented so it survives staff turnover. Uncontrolled USB is one of the more common infection routes in shops.
Both. Pod Care is priced per user per month, so a ten-person shop pays a ten-person price and still gets monitoring, security tooling, backups and a real help desk. Small suppliers often face the same audit questions as large ones with none of the internal resources.
Controls implemented, documented and monitored by a family-owned Arizona team.
Talk to Your Pod
The free Deep Dive shows you exactly what a customer's security reviewer would find. Better to see that list on your own schedule than during an audit week.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.