/ One product. Five elements. One supported standard.

Five elements, delivered as one product.

Surya has built a standardized system for your network, Microsoft environment, AI foundation, automated operations, and device recovery. The result: far less routine IT work, so your team can focus on AI workflows and improving the business.

The product is built, released and operating. Capabilities and deployment commitments are confirmed for the accepted scope.

Every element is released with approved support and substantiated claims. The released profiles define what is supported, and anything outside them is stated plainly rather than customized around.

/ Element 01 - Surya Fabric

The network, built to the standard.

Approved edge, switching, Wi-Fi, segmentation, connectivity and recovery, operated to one released profile with a tested recovery procedure.

Included behaviour

  • Approved edge, switching and wireless profiles
  • Segmentation and allowed paths from the shared specification
  • Connectivity, with a tested alternate path where the selected profile includes one
  • Network inventory, firmware lifecycle and configuration protection
  • Replacement of a supported component without the original designer
Required dependencies
Site readiness, structured cabling, declared power dependencies, and the customer's carrier accounts.
Explicit exclusions
Unsupported network configurations must change before enrollment. A single connection is not sold as redundant. Surya does not control carrier repair, building power or production machinery.
Acceptance test
Inventory matches the installation; required business paths succeed; prohibited cross-segment access is denied; the approved configuration can be restored; losing each included path produces the declared result.
Current availability
Available. Released with approved support, and the acceptance tests are run at every deployment.

/ Element 02 - Surya Workplace

A reproducible Microsoft workplace.

Supported identity, endpoint provisioning, Intune configuration, controls, approved applications and protected-data recovery. Autopilot, Intune and Graph are Microsoft functionality; the product is the engineered combination and its verified operation.

Included behaviour

  • Identity controls, authentication enrollment and a documented recovery path
  • Endpoint provisioning and Intune configuration on the released baseline
  • Endpoint protection, encryption key custody and supported updates
  • Approved application deployment and supported peripherals
  • Defined protected data sets, backup operation and tested restore
  • Joiner, mover and leaver handling from the standard input and role catalogue
Required dependencies
Supported licenses for each released profile, a supported tenant and identity model, and named access and data owners.
Explicit exclusions
A defined Microsoft foundation, not every application or every Microsoft feature. No line-of-business software engineering, business-process redesign or unlimited training. A replacement device is not a backup, and local-only data outside the protected locations is not promised to reappear.
Acceptance test
Provision a new supported device; restore an authorized user to the defined working state on a replacement; test account recovery and the denial of an unauthorized recovery attempt; verify approved controls; execute a safe data restore; validate joiner and leaver handling; run a controlled containment exercise.
Current availability
Available. Released with approved support, and the acceptance tests are run at every deployment.

/ Element 03 - Surya AI Foundation

The controlled foundation for your AI work.

Approved Microsoft Copilot and Cowork capabilities, identities, connectors, data boundaries, auditability and consumption controls. Licensing, access, model selection and consumption are separate requirements, not one statement that Copilot is included.

Included behaviour

  • Release-qualified Copilot and Cowork integration on approved licenses
  • Access groups, approved models and approved connectors
  • Business-data access controls and declared data boundaries
  • Usage visibility, spending policy and audit configuration
Required dependencies
Data owners who identify permitted information and access. Unresolved high-risk access restricts the capability or delays its acceptance rather than becoming hidden consulting.
Explicit exclusions
Your organization builds and owns its business workflows. No AI strategy retainers, departmental discovery, custom workflow development, model training or output-accuracy guarantees. The employee-facing AI foundation is separate from the local model used by Surya Control.
Acceptance test
An authorized user performs a representative permitted task; an unauthorized user or prohibited data path is denied; connector and model restrictions behave as configured; consumption is visible; logging is available; a customer-owned workflow uses the released interface without custom Surya code.
Current availability
Available. Released with approved support, and the acceptance tests are run at every deployment.

/ Element 04 - Surya Control

The system that maintains the system.

Customer-dedicated operations compute in Surya's Research Triangle Park facility, with tested automated actions, continuous configuration verification and an explicit exception path.

Included behaviour

  • Continuous evaluation of the supported operating state
  • Allowlisted, tested routine operations under a standing policy
  • Explicit authorization for privilege grants and other high-impact changes
  • An exception path when a condition is unknown or unsafe
  • Protected evidence for every action and access

Routine operations run from an allowlisted, tested catalogue under a standing policy, so an engineer does not approve every ordinary execution. Privilege grants, destructive changes and broad policy changes require explicit authorization. An unknown or unsafe condition stops the action, preserves the evidence and raises the product exception path. The identities Surya uses live in your own Microsoft 365 tenant, where your administrator can see, audit and revoke them.

Dedicated to you.

Your operations run on hardware assigned to your organization alone, in our Research Triangle Park facility. It is not shared with any other customer. If it fails, your tenant keeps running exactly as before; nothing in your environment depends on it.

Routine analysis of your configuration runs on that dedicated hardware. Where a correction needs to be worked out, the configuration difference and its rationale are processed under terms that prohibit training on or retaining your data. No user content is involved at any stage.

Access is through two identities that live in your own Microsoft 365 tenant. Your administrator can see every sign-in, audit every action, and revoke either identity at any time. Surya holds no global administrator role and no delegated partner access to your tenant.

Nothing is enforced in your tenant without a Surya engineer approving it. Every change is validated against your standard and staged in report-only mode first.

How it works, in the detail your security team will ask for.

Required dependencies
Application identities your administrator consents to and can revoke, and Microsoft Graph permissions tied to the operations actually used.
Explicit exclusions
No arbitrary privileged AI agent and no custom automation built per customer. Dedicated compute does not mean a dedicated facility, power, staff, logging infrastructure or downstream cloud service. Continuous monitoring is not the same as staffed 24/7 incident response.
Acceptance test
A permitted automated correction is applied and verified; a prohibited action is stopped and raised; the operations appliance is replaced and its working state rebuilt from your tenant.
Current availability
Available. Released with approved support, and the acceptance tests are run at every deployment.

/ Element 05 - Surya Standby

Working replacements and the supply chain behind them.

Lockers, prepared inventory, authorized issuance, returns, readiness checks and replenishment, so a replacement is prepared before it is needed.

Included behaviour

  • An on-site badge-access smart locker at each enrolled site
  • Prepared inventory configured to the standard
  • Authorized issuance recorded against the serial number
  • Returns, repair routing, certified erasure to NIST 800-88 and retirement
  • Readiness checks and replenishment from the Surya RTP distribution center
Required dependencies
The customer purchases and owns the devices, including the replacements in the locker. Surya provides, installs, owns and operates the locker. Field response and replenishment follow the published territory.
Explicit exclusions
Supported devices and published logistics terms, not unlimited procurement. A prepared replacement covers device failure, not an application outage, an identity outage, a power loss or every network fault.
Acceptance test
A person at the site obtains a working replacement through the runbook and returns to the defined working state, with the swap recorded.
Current availability
Available. Released with approved support, and the acceptance tests are run at every deployment.

/ Product support

What product support covers.

Product support is included: a defined support path for supported users, plus supported vendor escalation with named owners. Continuous monitoring of the supported state is part of Surya Control and is not the same as staffed 24/7 incident response.

  • Backup operation and supported restore execution
  • Authentication and account recovery under the documented path
  • Supported Microsoft administration inside the released baseline
  • Product-security exceptions, containment and restoration of covered components
  • Escalation to supported vendors with a named owner
  • Faults in the accepted scope, at no consulting fee

Autopilot, Intune, Microsoft Graph and Copilot are Microsoft functionality. What Surya supplies is the engineered combination, the shared release, the verified operation and the physical recovery around them. Regulatory determinations, legal notification and investigation beyond the product boundary stay with your own authorities or their chosen specialists.

/ Who does what

Surya operates the foundation. Your team moves the business forward.

Surya

  • Product operation across all five elements
  • Device lifecycle and prepared replacement
  • The defined security and recovery behaviour
  • Product faults inside the accepted scope
  • Product support and supported vendor escalation
  • Release improvements for every customer at once

Your internal IT

  • Business applications and their vendors
  • AI workflows and process design
  • Access and business decisions
  • Integration with business systems
  • Adoption and the results the business wants

Consultants you choose

  • Advice or projects you independently decide to buy
  • Not required to keep the Surya product running
  • Cannot create obligations for Surya

If ordinary operation of the accepted system still requires an MSP alongside it, the product has not met its design objective.

That is a product standard, not a claim that no organization ever needs specialist help.

Surya operates the supported product. Business applications, AI workflows, access decisions and data authority stay with your organization.

These are five elements of one product, not five services to mix into a custom engagement.