/ Proof and trust
See how your sites recover, and how their controls operate.
These checks define acceptance for the purchased scope. Results are specific to the product, configuration and deployment being tested.
How we verify your deployment.
/ Evidence about your environment
Four questions the evidence answers.
| Question | Evidence types |
|---|---|
| Can the site recover? | Qualified replacement readiness, acceptance results, and applicable recovery-test records. |
| Are security controls operating? | Configuration, authorization, permitted-access tests, and records of supported security actions. |
| Where are the gaps? | Identified exceptions and the agreed owner or next action. |
| How does this support compliance? | Applicable product responsibilities and available evidence for the customer's defined requirements. |
Each evidence type is labelled by the product that generates it and the scope it covers. Configured automated reporting to Vanta is supported for all three products; additional records outside the configured reporting scope are available on request.
What each evidence record establishes.
- Site, product, assets, and scope.
- Control or recovery procedure tested.
- Date and source of the evidence.
- Result, exception, and owner.
- Applicable customer requirement where a reviewed mapping exists.
- How the customer can obtain it.
/ Vanta partnership and independent review
Operated controls. Automated reporting. Independent review when required.
Surya is a Vanta partner. Standby, Endpoint, and Fabric all support automated reporting to the Vanta platform. We can also arrange independent auditor relationships as part of your products when required, connecting the operation of your supported environment to your compliance and assessment workflow.
Surya
Operates the purchased products, supports their automated reporting, and coordinates auditor relationships where included in scope.
Vanta
Provides the platform for organizing reported evidence and supporting the compliance workflow.
Independent auditor or assessor
Conducts the agreed evaluation and makes its own findings.
Your organization
Sets its required framework and scope, owns retained obligations, and approves the relevant assessment arrangements.
Your agreed reporting configuration identifies the evidence sent to Vanta, how it is transferred, and who can access it. Reporting coverage and evidence mapping are defined for each purchased scope.
The evidence listed illustrates the product's contribution; the configured reporting scope determines which records are transmitted automatically. Vanta licensing, connection scope, reporting details and any third-party assessment fees are confirmed in the commercial scope.
The arrangement follows your requirements. There is no guaranteed assessment outcome, no automatic certification and no official HIPAA certification. Company SOC 2 reporting is not a certificate of a customer's CMMC or HIPAA compliance.
/ Company assurance
What the company already holds.
- SOC 2 Type II audited. The report is available on request under NDA. An attestation is not a certification.
- HIPAA-aligned handling under a signed business associate agreement. HIPAA compliance remains an organizational responsibility.
- Handling for manufacturing customers is aligned to NIST 800-171, the control set CMMC Level 2 is built on. Compliance remains an organizational responsibility.
- Certified data erasure to NIST 800-88, with a certificate filed against the serial number.
A company's SOC 2 report is not a certificate of its customer's CMMC or HIPAA compliance. These are company-level credentials. Which parts of the architecture were inside the scope of the report is confirmed in the report itself, which your reviewers can request.
/ Acceptance evidence
How we verify your deployment.
These checks define acceptance for the purchased scope. Results are specific to the product, configuration and deployment being tested.
Each check belongs to the product named beside it, so acceptance for a purchased scope runs the checks that scope requires rather than all seven.
- Surya Standby: a working replacement prepared to the agreed configuration reaches the person, and the issuance and custody are recorded.
- Surya Endpoint: a replacement restores the defined working state, and a data restore returns protected data to that state.
- Surya Endpoint: identity recovery works, and an unauthorized recovery attempt is denied.
- Surya Fabric: network recovery returns the approved configuration.
- Surya Control, inside Endpoint or Fabric: a permitted automated correction is applied and verified.
- Surya Control, inside Endpoint or Fabric: a prohibited action is stopped and raised through the exception path.
- Surya Control, inside Endpoint or Fabric: the operations appliance is replaced and rebuilds its working state.
Surya's documented work covers multi-site device logistics, preparation, delivery, recovery and custody. It is the operational history behind Surya Standby, reported at its own scope rather than as a claim about the whole product.
/ Architecture and controls
Where the work runs, and what it can do.
These describe Surya Control, the operating layer included with Surya Endpoint and Surya Fabric. Surya Standby on its own does not include Surya Control, and ongoing tenant, endpoint and network administration stays with your organization or its current provider.
What runs where
Your operations run on hardware assigned to your organization alone, in Surya's Research Triangle Park facility. The facility is Surya-controlled, badge-access logged, and the hardware sits in a locked enclosure. No other customer's work runs on it. Routine analysis of your configuration runs there. Where a correction needs to be worked out, the configuration difference and its rationale are processed under terms that prohibit training on or retaining your data. Mailbox content, file content and business-document content are not part of routine infrastructure operation.
Network
The dedicated hardware makes outbound connections only, to Microsoft services and to Surya's own management and logging systems. It accepts no inbound connections from the internet or from your network. No VPN to your sites terminates on it. Traffic between customers' hardware is blocked at the network layer.
Identity and access
Surya works in your tenant through two application identities that you create and own: one that reads, one that writes. They authenticate with certificates bound to your dedicated hardware; there are no passwords or shared secrets. Permissions are scoped to the work (Conditional Access, device management, audit and sign-in logs) and are consented by your administrator. Surya holds no Global Administrator role and no delegated partner relationship. Your administrator can see every sign-in by these identities in your own logs and can revoke either one at any time.
Change control
Operations are classified before release, not improvised per customer. Observation involves no change at all. A routine operation runs only if it is on the allowlisted, tested catalogue and permitted by your standing policy, and it is validated and staged where staging applies. A consequential change - privilege grants, destructive actions, broad policy changes - requires explicit authorization from your named owner. Anything unknown, ambiguous or unsafe stops, preserves the evidence and raises the product exception path. Surya engineers validate the operating classes before they are released; they do not approve each ordinary execution.
Logging and evidence
Every action, every access to your tenant, and every decision is recorded and shipped off the dedicated hardware within seconds to Surya's security logging platform, where it is retained under Surya's retention standard. The dedicated hardware cannot alter what it has already shipped. Reports from this log are available to you on request.
If the hardware fails
Your tenant keeps running exactly as before. The dedicated hardware holds nothing of record: your tenant is at Microsoft, your standard is version-controlled, and every case and approval is in Surya's operations system. A replacement is enrolled with new certificates that your administrator registers, and it rebuilds its working state from your tenant. Nothing is restored from the failed unit, which is wiped before it leaves the enclosure.
What data is involved
Surya operates infrastructure, not your business content. Mailbox content, file content, business documents, patient records and production data are not part of routine infrastructure operation. Configuration, device, identity, network and security telemetry is in scope, and that telemetry can contain personal identifiers such as user names, device names, sign-in locations and IP addresses. Data is minimized to what operation requires and handled under contract. Surya retains operational audit records under its retention policy. Data used by an external model is subject to that provider's applicable processing terms.
How to stop it
Your organization can revoke Surya's application credentials in your tenant. This prevents new authentication with those credentials. Existing tokens and sessions remain subject to their expiry and revocation rules. Surya can also quarantine your dedicated hardware from its management system.
/ What needs a person
Four action classes.
These describe Surya Control, the operating layer included with Surya Endpoint and Surya Fabric. Surya Standby on its own does not include Surya Control, and ongoing tenant, endpoint and network administration stays with your organization or its current provider.
Observe
Read approved state and telemetry, identify deviations and produce evidence. No human step per observation.
Routine operation
Run an allowlisted, tested operation under a standing policy, within its target and rate limits. No engineer approval per execution.
Consequential change
Privilege grants, destructive changes and broad policy changes require explicit authorization and, where appropriate, separation of duties.
Unknown or unsafe
Stop the action, preserve state and evidence, and raise the product exception path for a qualified responder.
The product team approves and tests routine action classes before release. An existing customer is not moved from human-approved behaviour to automatic execution by a change to this page.
/ Said precisely
Where an absolute claim would be wrong.
| Term | What it actually means |
|---|---|
| Dedicated customer compute | The operations hardware is assigned to one customer. The facility, its power, network, staff and logging infrastructure are shared. |
| Data minimization | Surya operates infrastructure, not business content. Mailbox, file and business-document content are not part of routine operation. Configuration, device, identity and security telemetry is in scope, and it can contain personal identifiers such as user names, device names, sign-in locations and IP addresses. |
| A local operations model | The local model is used for Surya's operations analysis within the purchased product scope. |
| Revocation | Your organization can revoke Surya's application credentials. This prevents new authentication with those credentials. Existing tokens and sessions remain subject to their expiry and revocation rules. |
| Retention | Surya retains operational audit records under its retention policy. Data used by an external model is subject to that provider's applicable processing terms. |
| Report-only staging | Not every change supports a vendor report-only mode. Where it does not, validation is a staging group, a scoped pilot, or a tested rollback, and the record names which one was used. |
| Continuous monitoring | The supported state is evaluated continuously. That is not the same as a staffed 24/7 incident response desk. |
| Round-the-clock support | Three things are different and are kept separate. Round-the-clock product support is the support path for supported users, staffed across three shifts, 365 days a year. Continuous supported-state monitoring is how Surya Control evaluates the Endpoint and Fabric scope. Security incident response is covered only to the extent written into your contract; Surya is not an unlimited SOC or MDR service. |
| Automated Vanta reporting | Supported for Standby, Endpoint and Fabric within the configured reporting scope. It does not mean every audit requirement is automatically evidenced, and it does not imply a fixed transmission frequency, a compliance score or a separate Surya dashboard. |
Access and custody
- Access to the Surya facility in Research Triangle Park is logged.
- Every device in our custody is tracked by serial number.
- Every swap and return is documented.
Erasure
- Drives are erased to NIST 800-88, the United States standard for media sanitization.
- A certificate is issued per device where erasure applies.
SOC 2 Type II audited - HIPAA-aligned handling - Business associate agreement available - NIST 800-88 certified erasure - Serial-level chain of custody.