/ Security and trust
Security and trust.
What we do with your access, your data, and your devices. Every item here is a statement of practice, written the way we would answer it in a security review.
/ Controls
Security and privacy controls
- Access to the Research Triangle Park facility is logged.
- Every device in our custody is tracked by serial number.
- Administrative access is role-based: an account gets only the access its role requires.
- The customer's Microsoft 365 tenant — the customer's own account of users, email, and devices — stays the customer's.
/ Data
Data handling
- Work runs inside the customer's Microsoft 365 tenant, on the customer's licensing.
- Surya holds administrative access under named accounts, and that access is logged.
- Devices in our custody are tracked by serial number from intake to disposition.
/ Erasure
Erasure certification
- Drives are erased to NIST 800-88 — the United States standard for media sanitization.
- A certificate is issued per device.
/ Custody
Chain of custody
- Serialized record from intake to disposition.
- Every movement of a device is documented.
/ Compliance
Compliance posture
- HIPAA-aligned processes: our processes are built to the requirements of the healthcare privacy law. This is alignment, not certification.
- A SOC 2 examination — an independent review of security controls — is in progress.
- A business associate agreement (BAA), the contract healthcare customers need with a vendor handling patient data, is available.
/ Diligence
Due diligence
- A security overview, a subprocessor list — the outside vendors involved in delivering the service — and audit accommodation are available on request under NDA.
- Requests are routed through the conversation form.
Requesting diligence material
Tell us what your review needs and we will come back within one business day.
Price My Fleet →Have a conversation →