02RESOLVE GRAPHhumans, machines, AI agents: one graph
↓
03DISPATCHnamed campaigns, not alert counts
↓
04PRESCRIBEfixes ranked by blast radius
↓
05PROVE OUTCOMEsigned, verifiable evidence
⟳ the proved outcome re-enters the graph
For
CISOs and SOC teams in regulated enterprises: pharma, BFSI, manufacturing, hospitality.
Who
Own the risk but cannot see what an attacker can actually reach across identities, assets, and OT.
Setu is
The derived-ground-truth layer above the lake, built from telemetry you already pay to store.
That
Enforces this loop continuously: every event lands in one resolved graph, every dispatch names a campaign, every prescription is ranked by blast radius, and every outcome is proved.
Unlike
An inventory kept true by hand, or a per-event rule engine that stops at 50,000 alerts. Neither closes the loop.
Proof
Across three production engagements: 50,000 events resolved into twelve named campaigns. High-severity volume down 24× in week one. 0 bytes moved across the lake. See the proof →
We are not the first to notice. Three venture firms published versions of this hypothesis in 2026, independently, using different words for the same missing layer. We read all 103 of their published ideas. 12 describe this. 79 have nothing to do with us.
Three moves turn the exhaust your stack already produces into an accurate picture of your environment, and then into answers you could never get from an inventory.
01
Discover
Agentless
Nothing to deploy. Nothing to migrate.
Connectors read what your stack already emits, across XDR, firewall, identity, vulnerability, cloud, and OT, over API or syslog. Where a network is closed, one collector relays out. There is no endpoint agent to roll out and no inventory to keep true by hand, because discovery is a read of the systems that already know the answer.
Every record resolves to a canonical entity. Hostnames normalized, cases folded, duplicates merged, identities joined to the assets and accounts they touch. What comes out is one graph of every human, machine, and AI agent, rebuilt continuously, rather than a spreadsheet that was accurate in March.
Compromised identityReachable from itOutside the blast radius
03
Reason
Live ontology
Your logs already describe your company.
Events land as OCSF-typed objects, so the graph is derived from your data rather than declared by an administrator. That is what makes the hard questions answerable: which accounts can reach this crown jewel, which routes have nothing watching them, what changed since last quarter.
Samyoga reads and reasons. Anything that writes back runs through a staged approval gate, including the local model in air-gapped deployments.
Derived ground truth measures what an attacker can actually reach across identities, assets, and OT, then adapts on the evidence. Risk is a flow, not a column. Here is the line against the four things it gets mistaken for.
Mistaken for
What we are not
What we are
A CMDB or asset inventory
A system of record somebody has to keep true by hand.
A graph derived from live telemetry, re-resolved continuously.
A louder SIEM
A per-event rule engine that counts 50,000 alerts.
The decision surface above the lake: twelve named campaigns.
An identity tool
A role-redesign program or a cloud-entitlement-only scanner.
Identity, assets, and OT joined in one exposure graph.
Compliance or GRC
A control-to-framework mapping exercise.
Signed, offline-verifiable exposure your board and insurer can check.
Three sectors. Real exposure. Names withheld for now.
Customers introduced through PwC India and EY India are running Samyoga in production today. Identifying details are withheld until consent is on the record.
PHARMA
A top-3 Indian generics manufacturer connected Setu to its existing data lake without migrating a byte. The first weekly digest surfaced campaigns the prior tooling had missed.
0 bytes
moved across the lake boundary
HOSPITALITY
A national hospitality group ran the platform across a fleet of Windows endpoints with on-prem agents. FIM hostnames resolved, severity dropped 24x in the first week.
24x
reduction in High-severity alert volume
TECHNOLOGY
A global technology enterprise uses Dispatches as the weekly board artifact. Twelve campaigns surface where the prior platform showed only an alert count.
12 vs 0
campaigns surfaced vs prior tooling
The wedge
The picture pays for itself in the SOC.
An accurate environment graph is not an end in itself. It is what makes 50,000 events resolve into twelve named campaigns, what tells you which routes to a crown jewel have nothing watching them, and what lets a NIST CSF tier claim be measured instead of asserted. That work ships weekly as a dispatch.
Step 1 — Detect
Coordinated activity collapses into one campaign, not fifty alerts.
Step 2 — Connect
The resolved graph makes a campaign one object, not a stack of tickets across nine consoles.
Step 3 — Narrate
Each dispatch is named, ranked, and dated. Readable on a board slide, actionable on the SOC console.