/ Security and trust

Security and trust.

What we do with your access, your data, and your devices. Every item here is a statement of practice, written the way we would answer it in a security review.

/ Controls

Security and privacy controls

  • Access to the Research Triangle Park facility is logged.
  • Every device in our custody is tracked by serial number.
  • Administrative access is role-based: an account gets only the access its role requires.
  • The customer's Microsoft 365 tenant — the customer's own account of users, email, and devices — stays the customer's.

/ Data

Data handling

  • Work runs inside the customer's Microsoft 365 tenant, on the customer's licensing.
  • Surya holds administrative access under named accounts, and that access is logged.
  • Devices in our custody are tracked by serial number from intake to disposition.

/ Erasure

Erasure certification

  • Drives are erased to NIST 800-88 — the United States standard for media sanitization.
  • A certificate is issued per device.

/ Custody

Chain of custody

  • Serialized record from intake to disposition.
  • Every movement of a device is documented.

/ Compliance

Compliance posture

  • HIPAA-aligned processes: our processes are built to the requirements of the healthcare privacy law. This is alignment, not certification.
  • A SOC 2 examination — an independent review of security controls — is in progress.
  • A business associate agreement (BAA), the contract healthcare customers need with a vendor handling patient data, is available.

/ Diligence

Due diligence

  • A security overview, a subprocessor list — the outside vendors involved in delivering the service — and audit accommodation are available on request under NDA.
  • Requests are routed through the conversation form.

Requesting diligence material

Tell us what your review needs and we will come back within one business day.

Price My Fleet →Have a conversation →