/ For security leadership
Know what is connected. Control how it is reached.
Evaluate the visibility, segmentation, access controls and operating evidence around your physical environments. Surya operates the supported technology boundary, with Claroty capabilities where they are in scope.
CISOs, security leaders, IT and OT security owners and anyone evaluating access, segmentation and operating controls.
/ Two business outcomes
Site resilience
Be ready when technology fails.
Prepare the devices, configurations, and recovery procedures your sites depend on, so a supported failure has a defined path back to work.
Security and compliance
Protect the operation. Show the controls.
Control equipment custody, user access, and network connections, with records that help demonstrate how the purchased scope is protected.
Four questions this page answers.
/ 01
What is connected, and how does it communicate?
Within the Fabric scope, connected assets are identified and their communication is described. Where operational and cyber-physical systems are present, Surya is a Claroty partner and deploys, integrates and operates Claroty asset visibility and exposure context inside that scope.
/ 02
Which connections and vendor access paths are permitted?
Segmentation and secure access define which paths exist. Third-party and vendor access is granted deliberately, scoped, recorded and revocable.
/ 03
How are changes authorized, recorded and stopped when necessary?
Routine allowlisted operations run under standing policy. Consequential changes require explicit authorization from your named owner, and operations can be stopped.
/ 04
What evidence can our reviewers inspect?
The released standard, the security and trust material and the security documentation request path are available for review, with their stated scope qualifications.
/ Products
Where the security boundary is operated.
The relationship starts with Surya Standby, which is a scoped physical replacement process rather than a change of administrative control. Physical-system security work sits in Fabric and its OT and CPS scope, and endpoint protection is a separate concern.
Surya Fabric
Site networking, segmentation, secure access and tested configuration recovery.
Surya Fabric in detail →OT and CPS security
Claroty asset visibility, exposure context and secure access, deployed, integrated and operated by Surya where that scope applies.
OT and CPS security in detail →Surya Endpoint
Endpoint configuration, protection and protected-data recovery.
Surya Endpoint in detail →Surya Control is included with Endpoint and Fabric and is never a separate purchase; Standby on its own does not include it, so ongoing tenant, endpoint and network administration stays with your organization or its current provider. Surya engineers work three shifts, 365 days a year; response commitments for a scope are set in the written proposal, and Control does not perform unrestricted autonomous remediation.
/ First purchase
Start with a supported scope.
A security-led evaluation still begins with one product and one declared scope.
/ 01
The scope under review
The sites, networks and connected systems in question are named before anything is deployed.
/ 02
Actual prerequisites
Network, identity and system prerequisites are reviewed against the released profile of the product.
/ 03
Authorization model
Your named owner is identified for the changes that require explicit authorization.
/ 04
Acceptance tests
The product is accepted against the acceptance criteria of its released profile.
/ 05
Evidence path
The documentation your reviewers receive, and its stated scope, are agreed during qualification.
Where a material detail is unresolved, compatibility and scope are confirmed during qualification rather than assumed here.
Who owns what.
Surya operates
- The supported technology boundary inside the accepted scope
- Segmentation and secure access configuration
- Claroty deployment, integration and operation where that scope applies
- Recorded authorization of consequential changes
You retain
- Access policy and who is permitted
- Risk decisions and regulatory obligations
- Equipment, clinical and application vendors
- Your own security programme and reviewers
The boundary, stated plainly.
- Not included: Production programming and control logic
- Not included: Machinery safety and process engineering
- Not included: Clinical equipment functionality
- Not included: Guaranteed regulatory compliance or certification of every product
/ Deployment
Your first deployment.
Deployment starts with a defined scope, a single site or a single group of equipment, rather than the whole estate. The relationship starts with Surya Standby, and Endpoint or Fabric is deployed to the released profile when that deeper scope is purchased, at the outset or later. Where Surya Fabric is purchased, Surya provides the network system itself: the equipment, its standard configuration, installation and testing.
/ 01
Choose the scope
The products, the equipment classes, one site or one device group. The scope is written down before anything is installed.
/ 02
Compatibility review
For Standby, the configurations Surya will capture and reproduce, the physical placement and the approvals the replacement workflow needs. For Endpoint, your environment is checked against the released profile, including identity and platform dependencies. For Fabric, the sites, connectivity, cabling and site readiness the Surya-supplied network system needs are checked.
/ 03
Written prerequisites
Anything that must change first is stated in writing, together with the approvals your organization needs to give.
/ 04
Installation
Surya installs the agreed physical arrangement and the prepared replacements, deploys and tests the Surya-supplied network system where Fabric is purchased, and configures any purchased Endpoint scope to the released standard.
/ 05
Acceptance tests
Each product is accepted against its own tests, so the result is inspectable rather than asserted.
/ 06
Ongoing operation
Surya operates the accepted scope, and faults inside it are Surya's to resolve.
What changes in your environment
- Surya Standby reproduces the configurations you already run; it does not require your estate to be rebuilt first, and keeping your existing production setup is not a barrier to it.
- Standby prepares replacements for your existing supported equipment and configurations. Endpoint can retain devices where its released profile permits. Fabric supplies, installs and tests the network system for the agreed sites.
- Where Endpoint is purchased, configurations inside that purchased scope are brought to the released profile, which can change how some settings are managed today, and replacement preparation then follows that baseline. Where Fabric is purchased, the supported site network runs on the Surya-supplied system and its standard configuration. Equipment and identity models outside the purchased scope are unaffected.
- Approvals from an accountable owner are required for consequential changes.
- Providers responsible for adjacent systems, applications or machinery remain responsible for them, and Standby on its own leaves ongoing tenant, endpoint and network administration where it is today.
An illustrative first scope: one site, the agreed equipment classes, the existing configurations captured per role, the prepared replacement positions for them, and the acceptance tests for that scope. Quantities, timing and commercial terms come from the proposal for your environment.
Each product has its own prerequisites. Standby does not require Endpoint or Fabric, and buying Fabric does not automatically require Endpoint. Any dependencies that extend beyond the selected site are identified during qualification.
What reviewers can request.
Security documentation, including the SOC 2 report, is available through the documentation request path with its stated scope qualifications. It does not imply certification of every product or guaranteed regulatory compliance.