/ Proof and trust

Show that it works.

These are the acceptance requirements evidenced for the declared scope. Every deployment is accepted against them, and the results are recorded.

The product is built, released and operating. Capabilities and deployment commitments are confirmed for the accepted scope.

/ Company credentials

What the company already holds.

  • SOC 2 Type II examination complete. The report is available on request under NDA. An attestation is not a certification.
  • HIPAA-aligned handling under a signed business associate agreement. HIPAA compliance remains an organizational responsibility.
  • Handling for manufacturing customers is aligned to NIST 800-171. Compliance remains an organizational responsibility.
  • Certified data erasure to NIST 800-88, with a certificate filed against the serial number.

These are company-level credentials. Which parts of the architecture were inside the scope of the report is confirmed in the report itself, which your reviewers can request.

/ Acceptance evidence

Every deployment is accepted against these tests.

  • A working replacement reaches the person and restores the defined working state.
  • Network recovery returns the approved configuration.
  • Identity recovery works, and an unauthorized recovery attempt is denied.
  • A data restore returns protected data to the defined state.
  • AI access is denied where the policy says it should be.
  • A permitted automated correction is applied and verified.
  • A prohibited action is stopped and raised through the exception path.
  • The operations appliance is replaced and rebuilds its working state.

Surya's documented work covers multi-site device logistics, preparation, delivery, recovery and custody. It is the operational history behind Surya Standby, reported at its own scope rather than as a claim about the whole product.

Read the documented work and its scope →

/ Architecture and controls

Where the work runs, and what it can do.

What runs where

Your operations run on hardware assigned to your organization alone, in Surya's Research Triangle Park facility. The facility is Surya-controlled, badge-access logged, and the hardware sits in a locked enclosure. No other customer's work runs on it. Routine analysis of your configuration runs there. Where a correction needs to be worked out, the configuration difference and its rationale are processed under terms that prohibit training on or retaining your data. No user content, mailbox content, file content, or personal data is involved at any stage.

Network

The dedicated hardware makes outbound connections only, to Microsoft services and to Surya's own management and logging systems. It accepts no inbound connections from the internet or from your network. No VPN to your sites terminates on it. Traffic between customers' hardware is blocked at the network layer.

Identity and access

Surya works in your tenant through two application identities that you create and own: one that reads, one that writes. They authenticate with certificates bound to your dedicated hardware; there are no passwords or shared secrets. Permissions are scoped to the work (Conditional Access, device management, audit and sign-in logs) and are consented by your administrator. Surya holds no Global Administrator role and no delegated partner relationship. Your administrator can see every sign-in by these identities in your own logs and can revoke either one at any time.

Change control

Nothing is enforced in your tenant automatically. A proposed correction is validated against your standard, checked with Microsoft's own policy evaluation where it applies, and applied in report-only mode or to a staging group first. A Surya engineer reviews the proposal, the validation results, and the staging observations, then approves or rejects it. Changes to Conditional Access require two approvers during your first ninety days. Privileged role membership is never changed automatically; it is always a case for a person.

Logging and evidence

Every action, every access to your tenant, and every decision is recorded and shipped off the dedicated hardware within seconds to Surya's security logging platform, where it is retained under Surya's retention standard. The dedicated hardware cannot alter what it has already shipped. Reports from this log are available to you on request.

If the hardware fails

Your tenant keeps running exactly as before. The dedicated hardware holds nothing of record: your tenant is at Microsoft, your standard is version-controlled, and every case and approval is in Surya's operations system. A replacement is enrolled with new certificates that your administrator registers, and it rebuilds its working state from your tenant. Nothing is restored from the failed unit, which is wiped before it leaves the enclosure.

How to stop it

Delete the two application credentials in your tenant. Surya's access ends immediately. Surya can also quarantine your dedicated hardware from its management system. Either action alone is sufficient.

/ What needs a person

Four action classes.

Observe

Read approved state and telemetry, identify deviations and produce evidence. No human step per observation.

Routine operation

Run an allowlisted, tested operation under a standing policy, within its target and rate limits. No engineer approval per execution.

Consequential change

Privilege grants, destructive changes and broad policy changes require explicit authorization and, where appropriate, separation of duties.

Unknown or unsafe

Stop the action, preserve state and evidence, and raise the product exception path for a qualified responder.

The product team approves and tests routine action classes before release. An existing customer is not moved from human-approved behaviour to automatic execution by a change to this page.

/ Said precisely

Where an absolute claim would be wrong.

TermWhat it actually means
Dedicated customer computeThe operations hardware is assigned to one customer. The facility, its power, network, staff and logging infrastructure are shared.
No personal dataIdentity and security logs can contain personal identifiers such as user names, sign-in locations and device names.
A local operations modelThe local model is used for Surya's operations analysis. Employee Copilot data is processed by Microsoft-hosted services, not on that machine.
RevocationDeleting a credential stops new authentication immediately. Already-issued tokens and active sessions expire under their own lifetime rules.
Report-only stagingNot every change supports a vendor report-only mode. Where it does not, validation is a staging group, a scoped pilot, or a tested rollback, and the record names which one was used.
Continuous monitoringThe supported state is evaluated continuously. That is not the same as a staffed 24/7 incident response desk.

Access and custody

  • Access to the Surya RTP distribution center is logged.
  • Every device in our custody is tracked by serial number.
  • Every swap and return is documented.

Erasure

  • Drives are erased to NIST 800-88, the United States standard for media sanitization.
  • A certificate is issued per device where erasure applies.

SOC 2 Type II examination complete - HIPAA-aligned handling - Business associate agreement available - NIST 800-88 certified erasure - Serial-level chain of custody.

Your security team can request the full data-flow and access documentation before anything is enrolled.