# Surya Technologies Keep your sites working. Resilience and security for physical businesses. Surya reduces downtime and security risk across physical locations, with tested recovery, consistent controls and evidence that supports CMMC and HIPAA compliance. Every product answers two questions: how it keeps the site working or restores it after disruption, and how it protects equipment, access, systems and information. ## Compliance reporting and auditor coordination - Surya is a Vanta partner. Every Surya product (Standby, Endpoint and Fabric) supports automated reporting to the Vanta platform for its agreed scope; Standby reporting covers its equipment and handling scope and does not imply Surya Control or ongoing tenant administration. The configured reporting scope determines which records are transmitted automatically; additional records are available on request. Details: https://suryatechnologies.com/trust#vanta - Surya can arrange independent auditor or assessor relationships as part of the product scope when the client's requirements call for them; for CMMC assessments that require a C3PAO, the relationship is with an authorized C3PAO. The auditor or assessor reaches its own conclusions. There is no guaranteed assessment outcome, automatic certification or official HIPAA certification, and purchasing an infrastructure product alone does not establish an organization's compliance. - Vanta licensing, reporting setup and any independent assessment fees are identified in the written proposal. Pricing is private. - Industry paths: Manufacturing (https://suryatechnologies.com/industrial, CMMC support for relevant defense suppliers at #cmmc) and Healthcare (https://suryatechnologies.com/healthcare, HIPAA Security Rule safeguards at #hipaa). Commercial and other physical operations: https://suryatechnologies.com/commercial - Product outcomes. Standby: keep equipment failures from becoming prolonged business interruptions; keep covered equipment in authorized hands, with custody documented through issue, return and disposition. Endpoint: keep people productive through hiring, device failure and recovery; protect company access and data as people join, change roles and leave. Fabric: keep locations connected and make network recovery predictable; control which systems can connect and limit the spread of threats across the site. - Support coverage: round-the-clock product support, continuous supported-state monitoring and contracted security incident response are distinct. Surya is not an unlimited SOC or MDR service. > Surya keeps physical sites running with standardized endpoints, site networks, and replacement equipment ready when something fails. Surya is not an MSP, a consultancy or a staffing company: customers buy the product, they do not rent engineers. Fit is qualified against the purchased scope, not one universal prerequisite. Named business and data owners are always required. Surya Standby qualifies on an operational basis: the existing customer configurations to reproduce are agreed and reproducible, the issuance permissions and approvals are agreed, and the locker or secure room and cage placement is confirmed; it carries no Microsoft tenant, endpoint-profile or network-profile prerequisite. A supported Microsoft commercial tenant and supported endpoint profiles are Surya Endpoint prerequisites; supported network profiles are Surya Fabric prerequisites, and Endpoint prerequisites do not automatically apply to Fabric. Single-site organizations are not excluded. Surya operates the supported product within the purchased scope. Business applications, AI workflows, access decisions and data authority stay with the customer. ## Questions Direct answers to the questions buyers ask: https://suryatechnologies.com/questions ## Status - There is no free pilot, free hardware offer or paid assessment. The product is bought and installed to the standard. ## The products Three products, Standby-first, one operating standard. Surya Standby is where the customer relationship starts: a complete standalone product, not a trial, pilot or advisory retainer, with no mandatory period and no mandatory upgrade. Surya Endpoint and Surya Fabric are added on top of Standby, independently, in either order or together, at the outset or later; a customer ready for deeper scope can adopt it alongside Standby from the start and is not gated behind a mandatory pilot. Surya Foundation is Surya Standby, Surya Endpoint and Surya Fabric together under one agreement. Surya Control is included with Surya Endpoint and/or Surya Fabric and is never a standalone purchase, and is not used by Standby alone. OT and CPS security is part of Surya Fabric where the supported scope includes it; on a network Surya does not operate it is available as a visibility scope only, without enforcement. Surya Standby (the entry product; a complete product on its own, https://suryatechnologies.com/standby). Business outcome: protect revenue and customer commitments by keeping your sites working when critical equipment fails. Under Standby, Surya captures the customer's existing laptop image and configuration for each employee persona or role and prepares replacement equipment to that agreed configuration through its supply chain, and applies the same principle to qualified switches, firewalls and other agreed critical equipment. Preparing those spares is what Standby is. Physical form follows scope: workstations are held in a badge-access smart locker at the site, accessed with the employee's existing corporate identity; qualified critical network equipment is held in an existing secure onsite room or cage outfitted with Surya RFID and retrieved by designated staff; larger equipment is staged on site or shipped from the Surya facility in Research Triangle Park. A network-only scope does not require a laptop locker. Prepared inventory built to the customer's standard, authorized issuance recorded against the serial number, returns, repair routing, certified erasure to NIST 800-88, readiness checks and replenishment. The customer purchases and owns the equipment, including the prepared replacements; Surya provides, installs, owns and operates the locker it uses at the site. Standby alone does not include Surya Control and does not take over ongoing tenant, endpoint or network administration; the customer or its current provider retains that. Identity integration, access permissions and approvals needed for the replacement workflow are agreed during qualification. It does not include protected-data recovery. A prepared replacement covers device failure, not an application outage, an identity outage, a power loss or every network fault. Surya Endpoint (added on top of Standby, independently of Fabric: Endpoint + Standby + Control). Business outcome: make your people productive from day one and keep control of company access and data through every hire, role change and departure. Ongoing standardization and administration of the production endpoint estate: implementation and ongoing maintenance of Windows Autopilot v2, Intune and Microsoft Zero Trust configuration to Surya standards and agreed customer business requirements, endpoint protection, approved applications, protected data sets with tested restore, joiner/mover/leaver handling, and a prepared working replacement so the physical operation resumes without waiting for a technician to source and build equipment. A defined Microsoft foundation, not every application or every Microsoft feature. A replacement device is not a backup. Surya Fabric (added on top of Standby, independently of Endpoint: Fabric + Standby + Control, with OT and CPS security where applicable). Business outcome: keep every location operating securely and at full speed, with network capacity and resilience that support your growth. Surya provides the complete network system for the agreed sites: Surya supplies the equipment and its standard configuration, installs and tests it before operation, then operates and maintains the agreed network: approved edge, switching, wireless, segmentation, connectivity and a tested recovery procedure, extended to operational and cyber-physical systems through the Claroty integration where that scope applies. A single connection is not sold as redundant. Site readiness, structured cabling, building power, carrier accounts and carrier repair, and production machinery stay outside Surya's control. Equipment ownership and commercial terms are set out in the written proposal and agreement. Surya Foundation is Surya Standby, Surya Endpoint and Surya Fabric together: operated under one operating standard and one agreement, with Surya Control operating the supported state, and OT and CPS security where it is included in Fabric's supported scope. Surya Control is not sold separately. It is the operating layer inside Surya Endpoint and Surya Fabric. Its action model: observe continuously; run routine allowlisted tested operations under a standing policy without per-execution engineer approval; require explicit authorization for consequential changes such as privilege grants, destructive actions and broad policy changes; stop, preserve evidence and raise an exception when a condition is unknown or unsafe. Engineers validate operating classes before release. Response commitments for a scope are set in the written proposal. Routine analysis of the supported operating state runs on hardware dedicated to one customer in the Surya facility in Research Triangle Park, and nothing about the customer's environment trains any model; a proposal still uses an external model service. The identities Surya uses live in the customer's own Microsoft 365 tenant, where their administrator can see, audit and revoke them. It is not an arbitrary privileged AI agent and not custom automation per customer. How it works: https://suryatechnologies.com/control Every Surya customer starts with Surya Standby, which is a complete product on its own and not a mandatory pilot. Standby is defined by the equipment classes in scope, not by one class of device. Tenant, Entra, OS and network prerequisites, and password/sign-in, joiner-mover-leaver and Microsoft recovery ownership, apply to the purchased managed product, Surya Endpoint, Surya Fabric or Surya Foundation, not to Standby alone. ## How it is run Every Surya product is run by the Surya Agent Network. The agent takes the first response on a support request, runs the device flows, and hands anything it is not permitted to finish to Surya engineers on shift. 78% of responses are AI-first: the first response to a support request comes from the Surya Agent Network, not a person, measured across every customer Surya operates over the 90 days to September 2026. Surya engineers work three shifts, 365 days a year. Inside Surya Endpoint and Surya Fabric the Agent Network works under Surya Control, the released action model. Under Surya Standby on its own it runs the replacement loop - issuance, returns, replenishment and the custody record - and Surya Control is not involved, because there is no tenant scope to govern. Response commitments for a scope are set in the written proposal. How it works: https://suryatechnologies.com/control ## OT and cyber-physical systems - OT and CPS security is part of Surya Fabric. Enforcing separation requires Surya to operate the network, which is Surya Fabric. It can also be bought as a visibility scope on a network Surya does not operate: sensors at agreed points, asset inventory of the controllers and equipment found, vulnerability matching, anomaly detection and the evidence that comes out of it. Enforcement is not included, separation cannot be promised on equipment Surya does not configure, and the coverage state is reported rather than assumed. This is a scope, not a product, and it is not part of Surya Foundation's definition. - Surya is a Claroty partner. Delivered with Claroty: asset visibility, segmentation between the business and operational environments, monitoring of the boundary and the paths permitted across it, a defined recovery procedure for supported network components, and evidence of what is connected, what changed and what was denied. - Surya does not perform PLC programming, ladder logic, process engineering, controls engineering or machinery optimization, and does not take responsibility for production equipment or its safety systems. Claroty licensing is a customer requirement where the OT capability is in scope. ## Responsibility - Surya: product operation across the products in scope, device lifecycle and prepared replacement, the defined security and recovery behaviour, product faults inside the accepted scope, product support and supported vendor escalation, release improvements for every customer at once. - Your internal IT: business applications and their vendors, AI workflows and process design, access and business decisions, integration with business systems, adoption and the results the business wants. - Consultants you choose: advice or projects you independently decide to buy. Not required to keep the product running, and unable to create obligations for Surya. - Your IT team and current providers can remain in place. Surya operates and restores the purchased product within its agreed scope. Your organization and its other providers retain responsibility for business applications, workflows and systems outside that scope. ## The standard and the deal - You get a defined system, clear responsibilities and a product support path. You do not get a private architecture, a named engineer or a bespoke roadmap. - Four fit requirements: a supported configuration, the required licenses and equipment, authorized business and data owners, and acceptance of the product change process. - These boundaries do not excuse product failures. Inside the accepted scope, Surya is responsible for restoring the product. - Excluded unless a released profile exists: servers, arbitrary Azure workloads, industrial control systems, medical devices, custom voice systems and specialized peripherals. ## Deployment - A 30-day installation target for a declared, qualified installation, after site, equipment, access, licensing and compatibility requirements are met. - Unmet prerequisites move the start, not the finish line. Completion means the acceptance tests for the products in scope have passed. - Acceptance is a test result at a point in time. Reliability over months is measured and reported separately. ## What you'll experience - Qualify: environment compared against the released product profiles; every prerequisite named, with an owner; one written quote for the declared scope covering the subscription, the deployment fee and what the customer buys directly. - Install: the declared scope installed to the released standard, with a 30-day installation target once readiness is met; every required element passes its acceptance test with the evidence recorded. - Operate: under Surya Standby, Surya keeps the prepared replacements ready, issues them through the authorized recorded workflow, handles returns and replenishment, while ongoing production administration stays with the customer or its current provider. Where Surya Endpoint or Surya Fabric is purchased, Surya Control runs routine allowlisted operations inside that scope, consequential changes wait for customer authorization, and faults inside the accepted scope are Surya's to resolve. - Expand: the next site goes on the same standard with the same acceptance tests; adding the remaining products completes Surya Foundation; reliability is measured and reported separately from acceptance. ## Proof - Acceptance requirements evidenced at every deployment: a working replacement restores the defined working state; network recovery returns the approved configuration; identity recovery works and an unauthorized attempt is denied; a data restore returns protected data; AI access is denied where policy says it should be; a permitted automated correction is applied and verified; a prohibited action is stopped and raised; the operations appliance is replaced and rebuilds its working state. - Surya's documented work covers multi-site device logistics, preparation, delivery, recovery and custody. It is the operational history behind Surya Standby, reported at its own scope. ## Commercial - Pricing architecture: a recurring product subscription for the products in scope, plus a one-time fixed deployment fee for the declared scope. - On the customer's own paper: endpoints and spare inventory for Standby and Endpoint (the Surya Fabric network system is provided by Surya); Microsoft and other software licensing; Claroty licensing where OT and CPS security is in scope; AI, cloud and backup consumption; freight and logistics. - No hourly engineering, no consulting blocks or retainers, no named-resource or per-engineer pricing, and no charge for access to people. - Figures are confirmed in a written quote against a declared scope. Contract terms, remedies and exit treatment come from the approved agreement. ## Security - Operations run on hardware assigned to one customer, in Surya's Research Triangle Park facility. The facility, its power, network, staff and logging infrastructure are shared. - Application identities live in the customer's own tenant, visible in the customer's audit log and revocable at any time. Deleting a credential stops new authentication immediately; already-issued tokens expire under their own lifetime rules. - Consequential changes require explicit authorization. Where a vendor report-only mode does not exist, validation is a staging group, a scoped pilot or a tested rollback, and the record names which one was used. - Full detail: https://suryatechnologies.com/trust ## Pages - Home: https://suryatechnologies.com/ - Product: https://suryatechnologies.com/product - Surya Standby (the entry product): https://suryatechnologies.com/standby - The standard: https://suryatechnologies.com/standard - Deployment: https://suryatechnologies.com/deployment - Surya Control (how it works, not a product): https://suryatechnologies.com/control - Proof and trust: https://suryatechnologies.com/trust - Pricing architecture: https://suryatechnologies.com/pricing - Surya Endpoint: https://suryatechnologies.com/endpoint - Surya Fabric: https://suryatechnologies.com/fabric - OT and CPS security: https://suryatechnologies.com/ot-cps - Healthcare: https://suryatechnologies.com/healthcare - Manufacturing: https://suryatechnologies.com/industrial - Commercial: https://suryatechnologies.com/commercial - Raleigh-Durham: https://suryatechnologies.com/raleigh-durham - Documented work: https://suryatechnologies.com/case-studies - About: https://suryatechnologies.com/about - Check Fit: https://suryatechnologies.com/fit - Existing customer support: https://suryatechnologies.com/support - Request security documentation: https://suryatechnologies.com/security-documentation ## Guides Search-facing explanation pages. They restate the same product, standard and boundaries in the language of a specific question; they do not introduce new capabilities or commitments. - Questions: https://suryatechnologies.com/questions - When a workstation fails: https://suryatechnologies.com/when-a-workstation-fails - Laptop provisioning: https://suryatechnologies.com/laptop-provisioning - IT asset logistics: https://suryatechnologies.com/it-asset-logistics - Device lifecycle management: https://suryatechnologies.com/device-lifecycle-management - IT services for manufacturing companies: https://suryatechnologies.com/manufacturing-it-services - OT network security for plants: https://suryatechnologies.com/ot-network-security-for-plants - Clinic IT infrastructure: https://suryatechnologies.com/clinic-it-infrastructure - Hospital device continuity: https://suryatechnologies.com/hospital-device-continuity - Azure infrastructure management: https://suryatechnologies.com/azure-infrastructure-management - Healthcare IT support: https://suryatechnologies.com/healthcare-it-support - Manufacturing IT support: https://suryatechnologies.com/manufacturing-it-support - HIPAA compliant IT services: https://suryatechnologies.com/hipaa-compliant-it-services - Hospital IT services: https://suryatechnologies.com/hospital-it-services - IT support for multiple locations: https://suryatechnologies.com/it-support-for-multiple-locations - Laptop locker: https://suryatechnologies.com/laptop-locker ## Compliance - SOC 2 Type II audited. Report available on request under NDA. Which parts of the architecture were in the report's scope is confirmed in the report itself. - HIPAA aligned, under a signed business associate agreement. HIPAA compliance remains an organizational responsibility. - NIST 800-171 aligned (the control set CMMC Level 2 is built on) handling for manufacturing customers. - Certified data erasure to NIST 800-88, with a certificate filed against the serial number. ## Contact - sales@suryatechnologies.com ## Operating environments Surya describes the same product architecture in the language of three physical operating environments. These are markets Surya is testing, not separate products, consulting practices or industry-specific engineering. - Manufacturing (/industrial): plant and production environments, with CMMC support for relevant defense suppliers. Emphasis on Surya Fabric with OT and CPS capability, and Surya Endpoint where applicable. Excludes PLC programming, ladder logic, controls engineering, process engineering and machinery optimization. - Commercial (/commercial): connected buildings and campuses. Emphasis on Surya Fabric with Surya Control and OT and CPS capability. Surya does not promise to manage every building vendor. - Healthcare (/healthcare): physical care environments. Emphasis on Surya Standby, Surya Endpoint, Surya Fabric and OT and CPS capability. Surya does not operate clinical workflows or medical equipment functionality. There is one Surya Endpoint and one Surya Fabric. No environment-specific product forks exist. ## Role entry paths (optional) Three optional entry pages explain the same product set in the language of a visitor's responsibility. They change the explanation, examples and evidence presented; they do not change the product, supported configurations, responsibilities or commercial model. - /for-business - CEOs, owners, presidents and executives with physical locations. Business situations that trigger a purchase, the products in plain language, responsibilities, a first deployment and what the investment includes. - /for-private-equity - operating partners and portfolio operations leaders buying Surya products for portfolio companies. Repeatable deployment, cost drivers, defined responsibility and starting with one company. No shared tenant, no pooled data and no automatic cross-company visibility. - /for-operations - owners, executives, operations leaders, plant managers, clinic administrators and site leaders. Keeping work moving when devices fail, networks become unreliable or replacement equipment is hard to get. - /for-it - CIOs, IT directors and internal IT teams. Supported scope of Endpoint and Fabric, what internal IT retains, prerequisites, approvals, acceptance tests and the ongoing support path. - /for-security - CISOs and security leaders. Asset visibility, segmentation, vendor access control, authorization and recorded evidence, with Claroty capabilities where that scope applies. Persona is optional context on the Check Fit form, never a qualification rule.