Derived Ground Truth

The enterprise has no trustworthy map of itself. Agents are about to make that fatal.

231 identities can reach one crown-jewel account at a manufacturer we work with. Their CMDB names none of them.

Samyoga reads the logs and APIs you already have, resolves every human, machine, and AI agent into one graph, and answers what an attacker can reach. No agents to deploy, no bytes to move, no inventory kept by hand.

Read the thesis

We are not the first to notice. Three venture firms published versions of this hypothesis in 2026, independently, using different words for the same missing layer. We read all 103 of their published ideas. 12 describe this. 79 have nothing to do with us.

Read the evidence
How it works

Discover. Resolve. Reason.

Three moves turn the exhaust your stack already produces into an accurate picture of your environment, and then into answers you could never get from an inventory.

Discover
Agentless

Nothing to deploy. Nothing to migrate.

Connectors read what your stack already emits, across XDR, firewall, identity, vulnerability, cloud, and OT, over API or syslog. Where a network is closed, one collector relays out. There is no endpoint agent to roll out and no inventory to keep true by hand, because discovery is a read of the systems that already know the answer.

Your data lakeSnowflake · Databricks · S3 · IcebergSamyoga Control PlaneDetect · Connect · NarrateOutcomesBoard narrative · SOC alignment · auto-remediationNo data movement. No ingest tax. No agents on every endpoint.
Resolve
One graph

The same host, spelled nine ways, is one host.

Every record resolves to a canonical entity. Hostnames normalized, cases folded, duplicates merged, identities joined to the assets and accounts they touch. What comes out is one graph of every human, machine, and AI agent, rebuilt continuously, rather than a spreadsheet that was accurate in March.

Cross-domain risk propagation from one compromised identitysvc-backupapp-01app-02admin-jdoedb-fin01file-sharedc-01hr-app01guest-wifi
Compromised identityReachable from itOutside the blast radius
Reason
Live ontology

Your logs already describe your company.

Events land as OCSF-typed objects, so the graph is derived from your data rather than declared by an administrator. That is what makes the hard questions answerable: which accounts can reach this crown jewel, which routes have nothing watching them, what changed since last quarter.

Samyoga reads and reasons. Anything that writes back runs through a staged approval gate, including the local model in air-gapped deployments.

NODES SIZED BY REACHIDPSVC-ACCTENG-ADMINCI-RUNNERVAULTPROD-DBPPR 0.42BLAST RADIUS: 3 HOPS
What we are

An accurate picture is not an inventory.

Derived ground truth measures what an attacker can actually reach across identities, assets, and OT, then adapts on the evidence. Risk is a flow, not a column. Here is the line against the four things it gets mistaken for.

Mistaken forWhat we are notWhat we are
A CMDB or asset inventoryA system of record somebody has to keep true by hand.A graph derived from live telemetry, re-resolved continuously.
A louder SIEMA per-event rule engine that counts 50,000 alerts.The decision surface above the lake: twelve named campaigns.
An identity toolA role-redesign program or a cloud-entitlement-only scanner.Identity, assets, and OT joined in one exposure graph.
Compliance or GRCA control-to-framework mapping exercise.Signed, offline-verifiable exposure your board and insurer can check.
231
identities that could reach one crown-jewel account
0
bytes moved across the lake
2.1M
events analyzed in one engagement
$697M
exposure quantified at one enterprise, methodology published

Three sectors. Real exposure. Names withheld for now.

Customers introduced through PwC India and EY India are running Samyoga in production today. Identifying details are withheld until consent is on the record.

PHARMA

A top-3 Indian generics manufacturer connected Setu to its existing data lake without migrating a byte. The first weekly digest surfaced campaigns the prior tooling had missed.

0 bytes
moved across the lake boundary
HOSPITALITY

A national hospitality group ran the platform across a fleet of Windows endpoints with on-prem agents. FIM hostnames resolved, severity dropped 24x in the first week.

24x
reduction in High-severity alert volume
TECHNOLOGY

A global technology enterprise uses Dispatches as the weekly board artifact. Twelve campaigns surface where the prior platform showed only an alert count.

12 vs 0
campaigns surfaced vs prior tooling
The wedge

The picture pays for itself in the SOC.

An accurate environment graph is not an end in itself. It is what makes 50,000 events resolve into twelve named campaigns, what tells you which routes to a crown jewel have nothing watching them, and what lets a NIST CSF tier claim be measured instead of asserted. That work ships weekly as a dispatch.

50,000+ EVENTS12 CAMPAIGNSQ3-Pharma-DLP-ReconM&A-IP-Exfil-AttemptOT-Mfg-Lateral-ProbeHosp-Booking-SprayAzAD-Guest-PersistPHI-Egress-SpikeCloudConsole-BruteVendor-Token-ReuseRealty-Front-Office-PhishTech-CodeSign-HijackPharma-MfgFloor-FIMHosp-POS-Skim-Recon
Step 1 — Detect

Coordinated activity collapses into one campaign, not fifty alerts.

Step 2 — Connect

The resolved graph makes a campaign one object, not a stack of tickets across nine consoles.

Step 3 — Narrate

Each dispatch is named, ranked, and dated. Readable on a board slide, actionable on the SOC console.

Which seat are you in?

Where it runs.

Deploy
Multi-tenant SaaS or single-tenant on-prem.
Air-gapped
On-prem with an embedded local LLM. No outbound calls.
Standards
OCSF 1.0 throughout. Audit trails for regulated industries.
Data
India data residency available. Customer data never leaves the lake.

See it on your data.

Tell us a little about your stack. We reply within one business day with two or three time slots.

Or email sales@samyoga.tech