Beta · available to order

Bridge the gap between your CNC machine and your network.

CodePod and CodeNet are purpose-built appliances that carry program files to your machines over an encrypted connection. Your 20-year-old control never touches the office network, and nobody walks another USB drive across the shop floor.

The problem

Your machines outlive your IT policy.

A CNC machine is bought to run for thirty years. The operating system inside it was not. That gap is where shops lose time — and where auditors start asking questions.

Controls that can’t be patched

The systems inside most controls stopped receiving security updates long ago and can’t be brought up to date. If the machine can read a file share or a USB drive, we can connect it, whatever its age or brand, and it stays on your floor. Replacing a machine that still holds tolerance is an expensive way to fix a file transfer problem.

File sharing that got switched off

The file-sharing methods these controls were built around have been switched off on modern networks. They were never secure, so IT departments removed them. Every year, fewer of the old ways still work.

So the USB drive comes back

Sneakernet is what’s left. A drive in someone’s pocket carries no encryption and leaves no record of where it has been, and somebody walks it out to the machine again every time a program changes. It is also the hardest habit to defend in a CMMC assessment.

How it works

A broker in the middle

The device stands on both sides of the boundary and hands files across. Your network sees a modern, authenticated, encrypted endpoint. The machine sees the same file share or USB drive it has always seen. Neither side can reach the other.

How an Iron Glacier appliance sits between your network and your CNC machine Your shop and office network connects to the Iron Glacier appliance using SFTP or HTTPS over Wi-Fi or Ethernet. The appliance authenticates the user, filters the file, and stores it encrypted. It then presents the file to the CNC machine as a standard network file share or a USB drive. Traffic does not route between the two sides. Shop & office network Engineering, programming, scheduling SFTP / HTTPS Wi-Fi or Ethernet CODEPOD / CODENET Authenticate the user Reject dangerous files Store encrypted at rest Log every connection no traffic routes across File share / USB isolated segment CNC machine Any age, any brand, unchanged

The two sides of the appliance cannot see each other. Only files cross the middle.

Encrypted on the network side

Connect over secure Wi-Fi or plain Ethernet. Every upload is encrypted, and every person gets their own login and their own file space instead of one shared folder the whole building can reach.

Filtered in the middle

Dangerous files are rejected before they can ever reach the machine. Files sit encrypted at rest, and every connection is written to an audit log you can hand to an assessor.

Familiar on the machine side

The control sees a standard network file share or a USB drive, which is exactly what it already knows how to read. Nothing is installed on the machine, and nothing about the way your operators work has to change.

Products

Two ways to solve it. One security model.

Which one fits depends on how your machines connect and how many of them you have. If you’re not sure, tell us what’s on your floor and we’ll tell you straight.

CodePod

One device per machine · Ethernet

The full-capability appliance. Beyond file transfer, CodePod can bridge machine data protocols back to your office network, making it both a file bridge and a monitoring gateway for the same machine.

  • Secure file transfer over SFTP and HTTPS
  • MTConnect and OPC‑UA port forwarding for uptime monitoring
  • Ethernet-type DNC drip feed for programs too large to fit in control memory
  • Remote connection support for authorized service access
  • Multiple named users with per-user file isolation
CodeNet

One server · multiple machines · USB

The cost-effective route for smaller shops, and the answer for machines that have a USB port but no usable Ethernet. One server distributes files to receivers that plug straight into each control.

  • Secure file transfer to multiple machines from one server
  • Receiver plugs into the machine’s USB port and draws power from it
  • Appears to the control as an ordinary USB flash drive
  • Upload once, then send to one machine or push to all of them
  • Files protected by your machine’s own unique fingerprint
  • Nothing for the operator to configure; receivers pair automatically
Beta · available to order

Where the products stand today

CodePod and CodeNet are both in beta and both available to order now, with longer-than-normal lead times. The hardware and software are finished and working. What beta means here is that we are still hardening edge cases and finishing documentation.

Where a beta unit needs swapping for final production hardware, we cover that at no charge. What the swap covers is set out in writing with your quote.

Talk to us about a beta unit →

Why Iron Glacier

Built for the shop floor by someone who worked on one

A purpose-built appliance

No Windows PC to buy, license, patch, or babysit in the corner of the shop. It is one sealed device that does one job.

Works with what you own

Age, brand, and control generation don’t matter. If the machine can read a file share or a USB drive, it can be connected.

Nothing to teach the operator

The device is transparent to the machine. Programs appear where they have always appeared. There is no new screen to learn at the control.

Built by a machinist

Twenty years of hands-on CNC experience is behind these products, from running the machines to fielding the support calls. The design decisions come from that.

Security & Compliance

Built for shops facing CMMC

If you handle Controlled Unclassified Information, the file path to your CNC machine is part of your assessment scope. Full-disk encryption, named user accounts, network isolation, and audit logging are built into these devices rather than bolted on afterwards.

Iron Glacier products help you close a specific gap. They support your compliance program. They do not by themselves certify your organization.

  • Access Control (AC)
    Named accounts, role separation, per-user file isolation
  • Media Protection (MP)
    Removes the loose USB drive from the workflow entirely
  • System & Communications Protection (SC)
    Encrypted transport, default-deny firewall, network isolation
  • Audit & Accountability (AU)
    Connection and configuration logging with user attribution

Tell us what’s on your floor.

Send us your machine list, with makes, models, and how they connect, and we’ll come back with a straight recommendation and a quote. No pressure and no drip campaign.