/ For the CISO

How are access, endpoint posture, custody, evidence and change control handled?

Named accounts, logged access, one hardened setup per role, and a serialized record of every device movement.

/ 01

Administrative access

Surya holds role-based administrative access under named accounts. Access is logged. The tenant stays yours — the customer's Microsoft 365 tenant remains the customer's, and work runs inside it.

/ 02

Endpoint posture

One hardened standard setup per role, built on Windows Autopilot and Microsoft Intune with NIST hardening, versioned and kept current. Access is mapped per person and enforced on the Microsoft security stack.

/ 03

Custody and evidence

Devices in custody are tracked by serial number from intake to disposition, documented at every movement. Erasure is NIST 800-88, with a certificate per device.

/ 04

Compliance posture and diligence

HIPAA-aligned processes — alignment, not certification. A SOC 2 examination is in progress. A BAA is available for healthcare customers. A security overview, subprocessor list, and audit accommodation are available on request under NDA.

/ Proof

The stated posture, in one place

The Trust Center states the controls, the data handling, the erasure certification, the chain of custody, and the compliance posture without addition. Diligence requests route through the conversation form.

Review the posture, then the scope.

The calculator gives you the commercial shape. The working session covers access, evidence and the diligence material you need.

Price My Fleet →Have a conversation →