Everything, wrapped around your network

SurroundNet is more than a CMDB. It layers security, cost, accountability, governance, planning, change, and procurement onto the infrastructure that runs your business — one source of truth across network, cloud, and containers.

Who it's for

A single organization, an MSP, multi-company oversight, or a private air-gap

However your world is shaped, SurroundNet fits it — with the boundaries kept clean.

  • SaaS single organization — one company, hosted and live the same day, with no infrastructure to stand up.
  • Managed service provider — run many customer tenants from a single fleet console, with usage metering and branded services billing.
  • Multi-company oversight — a parent overseeing many companies or divisions, each strictly isolated, all rolled up under one roof.
  • Private / air-gapped — a single, fully isolated on-premises deployment for estates that can't touch the internet.
  • Row-level data isolation keeps every organization strictly separated.
  • Consented managed support — customers grant and revoke your access on their terms, fully audited.
  • Break-glass access that is permission-checked and logged.
  • Signed, per-configuration-item licensing tied to your organization.
Source of truth

One source of truth — network, cloud, and containers

It all rests on one accurate, living record of everything you run — discovered automatically across every domain and kept current.

  • Network discovery — built-in scanning and SNMP walks with CDP/LLDP topology: devices, interfaces, and links.
  • Cloud discovery — agentless inventory across Azure, AWS, and Google Cloud, brought into the same CMDB.
  • Container discovery — Kubernetes clusters, nodes, and workloads, governed like any other asset.
  • Imports from Cisco DNA Center, Prime, and SolarWinds, merged safely with what's already known.
  • A lightweight connector for segmented, remote, or customer networks.
  • Endpoint-on-port and wireless-client mapping — know what's plugged in where.
  • IPAM, VLANs, VRFs, and network zones with exposure reporting.
  • Relationships and dependencies for real blast-radius analysis, with unmanaged and rogue-device detection.
Security & compliance

Security and compliance, built in

For healthcare and government especially, compliance can't be bolted on at audit time. SurroundNet scans the estate continuously and maps what it finds to the frameworks you answer to.

  • Regulatory cross-walk across SOC 2, ISO 27001, HIPAA / HIPA, PIPEDA, and GDPR — one control set, mapped to every framework.
  • Continuous compliance auto-scan — technical controls checked against the live estate, not a once-a-year spreadsheet.
  • Findings raised against the real assets and tracked to closure.
  • Breach reconstruction — drift and fault evidence assembled into a forensic timeline for the affected asset.
  • Notification clock — data classification drives your statutory obligations and deadlines automatically.
  • Provable offboarding — a verifiable hard-wipe with a signed data-destruction certificate.
Proves itself

A glass-box platform that proves itself

Most platforms ask you to trust that they work. SurroundNet shows you — it validates and documents itself, and every cost and change traces end to end.

  • A living feature-validation portfolio — the platform tests its own capabilities and publishes the results.
  • Test plans that double as user documentation — provably true, because they're executed, not just written.
  • Actor-goal journey proofs that walk real workflows end to end.
  • End-to-end traceability — originating ticket → change → project → work order → PO → invoice → billing → closure, in one thread.
  • Every cost tied to the asset and the approval behind it.
  • A complete audit trail across changes, approvals, and access.
Cost of ownership

Total cost of operations and ownership

Know what every asset really costs — to buy, to run, and to replace. SurroundNet ties price, depreciation, and contracts to the assets themselves, so total cost of ownership is a number you can actually see.

  • Every configuration item attributed to a financial account.
  • Replacement cost from catalog MSRP; actual cost from what you last paid.
  • Depreciation calculated from real actuals, not guesses.
  • Contracts, support coverage, and warranties tracked against the assets they cover.
  • CAPEX vs OPEX treatment on the work that builds and maintains assets.
  • Cost rolls up by account, cost centre, project, and portfolio.
Ownership & accountability

Total ownership and accountability

Every asset, service, and decision has a name attached. SurroundNet closes the loop from the person who logs in to the service they own and the approvals they sign.

  • Services mapped to their owners, teams, and contacts.
  • Role-based access control down to page and function level.
  • Approvals recorded with who, when, and on what basis.
  • Full audit trail across changes, approvals, and access.
  • Delegation and alternate approvers for coverage.
  • Accountability from login → person → service → sign-off.
Lifecycle governance

Total process lifecycle governance

The disciplines that keep infrastructure trustworthy — built around the real assets, not bolted-on spreadsheets.

  • SOPs, runbooks, DRPs, and lessons-learned linked to the assets they govern.
  • SLAs with breach tracking and template-driven escalation ladders.
  • Fault and incident management tied to affected infrastructure.
  • Maintenance and outage windows planned, scheduled, and communicated.
  • Work orders with test results and definition-of-done closure gates.
  • Ownership and stewardship controls on the documents that matter.
Planning & projects

Total planning and project management

Plan the work, fund it, and watch it land — with budgets and portfolios that see all the way down to the invoice line.

  • Budgets → portfolios (nestable) → projects → WBS, in one hierarchy.
  • Committed and actual spend rolled up from real POs and invoices.
  • Project governance: test plans, DRP, lessons-learned, affected users & services.
  • WBS templates so new projects start structured.
  • Health signals — budget vs committed vs actual — at every level.
  • Cascading drill-down from a portfolio to a single receipt.
Change & cost control

Total change management and cost control

Change with confidence. Every change is planned, approved, scheduled, and costed — and the money is controlled before it's spent.

  • Guided change lifecycle with approvals and post-implementation review.
  • Maintenance and outage windows scheduled straight from the change.
  • Change → project → work order → WBS linkage in one thread.
  • Threshold- and role-based approval routing with cascading sign-off.
  • Committed spend checked against budget before it's incurred.
  • An emergency-change path for when speed matters.
Procurement

Total procurement cycle

From purchase order to received asset to paid invoice — the whole cycle, matched and traceable at the line level.

  • Purchase orders with line-level project and WBS attribution.
  • Goods receipt and true three-way match: ordered ↔ received ↔ invoiced.
  • Invoice-line matching with variance flags.
  • SKU and BOM catalog with pricing history.
  • Received serial numbers registered as tracked assets, ready for discovery.
  • Customer AR invoicing and MSP charge-back.
Continuous improvement

Process maturity through continuous feedback and improvement

The platform improves the way your operation should — a closed loop from feedback to backlog to shipped improvement.

  • In-app feedback capture from the people doing the work.
  • A backlog pipeline that turns feedback into planned work.
  • Release notes that record what shipped and why.
  • Feedback → backlog → release, linked end to end.
  • Executive dashboard with KPIs, trends, and drill-down.
  • A measurable maturity loop — not a one-time deployment.
The right deployment

The right deployment

Run SurroundNet where your security posture requires — in the cloud, on your own metal, or fully disconnected.

  • Azure SaaS, on-premises, or fully air-gapped and isolated.
  • Signed, per-CI licensing tied to your organization.
  • Secure by design — Key Vault secrets, managed identity, passwordless data access.
  • White-label and OEM branding for partners.
  • Scales by configuration-item count as your estate grows.
  • Data residency and isolation on your terms.

See it on your own infrastructure

A working demo, tailored to how your organization actually runs.

Request a demo