/ For security leadership
Know what is connected. Control how it is reached.
Evaluate the visibility, segmentation, access controls and operating evidence around your physical environments. Surya operates the supported technology boundary, with Claroty capabilities where they are in scope.
CISOs, security leaders, IT and OT security owners and anyone evaluating access, segmentation and operating controls.
Four questions this page answers.
/ 01
What is connected, and how does it communicate?
Within the Fabric scope, connected assets are identified and their communication is described. Where operational and cyber-physical systems are present, Surya is a Claroty partner and deploys, integrates and operates Claroty asset visibility and exposure context inside that scope.
/ 02
Which connections and vendor access paths are permitted?
Segmentation and secure access define which paths exist. Third-party and vendor access is granted deliberately, scoped, recorded and revocable.
/ 03
How are changes authorized, recorded and stopped when necessary?
Routine allowlisted operations run under standing policy. Consequential changes require explicit authorization from your named owner, and operations can be stopped.
/ 04
What evidence can our reviewers inspect?
The released standard, the security and trust material and the security documentation request path are available for review, with their stated scope qualifications.
/ Products
Where the security boundary is operated.
Physical-system security work sits in Fabric and its OT and CPS scope. Endpoint protection and AI governance are separate concerns.
Surya Fabric
Site networking, segmentation, secure access and tested configuration recovery.
Surya Fabric in detail →OT and CPS security
Claroty asset visibility, exposure context and secure access, deployed, integrated and operated by Surya where that scope applies.
OT and CPS security in detail →Surya Endpoint
Endpoint configuration, protection and protected-data recovery.
Surya Endpoint in detail →Surya AI Foundation
Access groups, declared data boundaries, usage visibility and audit for AI work.
Surya AI Foundation in detail →Monitoring inside the accepted scope is not a claim of staffed round-the-clock response, and Control does not perform unrestricted autonomous remediation.
/ First purchase
Start with a supported scope.
A security-led evaluation still begins with one product and one declared scope.
/ 01
The scope under review
The sites, networks and connected systems in question are named before anything is deployed.
/ 02
Actual prerequisites
Network, identity and system prerequisites are reviewed against the released profile of the product.
/ 03
Authorization model
Your named owner is identified for the changes that require explicit authorization.
/ 04
Acceptance tests
The product is accepted against the acceptance criteria of its released profile.
/ 05
Evidence path
The documentation your reviewers receive, and its stated scope, are agreed during qualification.
Where a material detail is unresolved, compatibility and scope are confirmed during qualification rather than assumed here.
Who owns what.
Surya operates
- The supported technology boundary inside the accepted scope
- Segmentation and secure access configuration
- Claroty deployment, integration and operation where that scope applies
- Recorded authorization of consequential changes
You retain
- Access policy and who is permitted
- Risk decisions and regulatory obligations
- Equipment, clinical and application vendors
- Your own security programme and reviewers
The boundary, stated plainly.
- Not included: Production programming and control logic
- Not included: Machinery safety and process engineering
- Not included: Clinical equipment functionality
- Not included: Guaranteed regulatory compliance or certification of every product
What reviewers can request.
Security documentation, including the SOC 2 report, is available through the documentation request path with its stated scope qualifications. It does not imply certification of every product or guaranteed regulatory compliance.