If you are reachable then you are breachable

Welcome toThe Reachability Era

Inventory told you what you own. It never told you what an attacker can reach — and agents are about to make that gap fatal.

Setu derives the map from the lake you already paid for, then dispatches named campaigns that close real attack paths to crown jewels.

Time-to-exploit is collapsing from weeks to hours. Stop ranking CVEs. Fix choke points on validated paths.

  • Built and engineered in India
  • Runs inside your boundary
  • 0 bytes leave the estate

Sovereign by construction

Indian security, built where the data already sits.

Setu is designed and engineered in India for Indian regulated industry. Nothing about your estate crosses a border to be understood, because nothing about your estate leaves the building.

  • LOCALISATION

    Data never leaves

    No cross-border transfer to assess, because there is no transfer.

  • DPDP ACT 2023

    No new processing

    Setu reads what you already lawfully hold. It creates no fresh data estate.

  • CERT-IN

    Six-hour clock

    Reachability context for an incident report, not a week of manual tracing.

  • GxP / CDSCO

    Nothing to requalify

    No agent lands on a validated system, so no change control opens.

  • DEPLOYMENT

    On your metal

    Your datacentre or a sovereign Indian cloud region. Your choice, either way.

The problem

The enterprise has no trustworthy map of itself.

Three systems each claim to know your estate. None of them agree, and none of them can tell you whether an attacker can actually get from a contractor’s laptop to a batch record.

The CMDB

It lies, and everyone knows it.

It was accurate the week it was populated. It has been drifting ever since, and it never described a relationship — only a row.

The SIEM

Alert sludge with no geometry.

Fifty thousand events tell you things happened. They do not tell you which two of them chain into a path to a crown jewel.

The scanner

Severity without reachability.

A critical CVE on an isolated host is noise. A medium on your only jump host is the whole breach. The column cannot tell the difference.

50,000 events12 campaigns

That is the whole compression. Not a smaller queue — a different unit of work, one a team can actually finish and a board can actually read.

How it works

Discover. Resolve. Reason.

Three beats. One graph.

Discover

Agentless reads across the SIEM, the lake, OT protocols and your identity provider. Nothing installed on a validated system, no change window, no sensor tax.

siem · lake · ot-passive · idp
sensors: 0

Resolve

Every identity, host, service account and trust lands in one derived graph — deduplicated, reconciled, and honest about what it could not confirm.

confidence-scored
conflicts surfaced, not hidden

Reason

PageRank over that graph ranks nodes by blast radius, validated paths get named campaigns, and closed campaigns re-enter the graph as signed fact. Setu reads and reasons — write-back runs through a staged approval gate.

paths → choke points → campaigns
proof re-enters graph

Validated paths

Fix what matters. That means choke points.

A severity column tells you a CVE is bad. It cannot tell you that four service accounts and one unmanaged jump host stand between a phished contractor and a GxP batch record. The graph can.

Cut the choke point and every path through it dies at once. That is one ticket instead of two hundred.

231

identities with a validated path to one crown-jewel account, at a manufacturer we work with. Their asset register named none of them.

PATH-VIEW · derived graph3 paths · 1 choke point
ContractorSvc acct ×4Vendor VPNCHOKE POINTJump host RDPHistorianMES / batchPLC cell 3ingresshopcrown jewels
isolate jump host kills 3 pathspatch 214 CVEs kills 0

Named campaigns

Work arrives with a name, an owner and an end.

Not a counter that resets every morning. A dispatch you can close, and a signed proof when it is closed.

Q3 · 12 open · 4 board-visible

  • Q3-PHARMA-JUMPHOST-ISOLATE

    Isolate the jump host

    One RDP hop carries three paths into the OT cell.

    cuts 3 pathsin flight
  • Q3-PHARMA-DLP-RECON

    Batch-record recon

    Read access to GxP records from four unowned accounts.

    cuts 2 pathsin flight
  • Q3-OT-HISTORIAN-TRUST

    Historian trust prune

    Legacy trust lets plant IT reach corporate identity.

    cuts 4 pathsqueued
  • Q3-IDENT-SVCACCT-ROTATE

    Service account rotation

    Nine accounts with no owner and no expiry.

    cuts 6 pathsin flight
  • Q3-VENDOR-VPN-SCOPE

    Vendor VPN rescope

    Contractor tunnel terminates inside the process network.

    cuts 2 pathsclosed
  • Q3-PLC-CELL3-SEGMENT

    Cell 3 segmentation

    Flat path from engineering VLAN to PLC cell 3.

    cuts 3 pathsqueued
  • Q3-MES-ADMIN-TIER

    MES admin tiering

    Domain admins log in interactively to the MES.

    cuts 5 pathsin flight
  • Q3-CLEANROOM-BADGE-IDP

    Cleanroom badge link

    Physical access system shares identity with corporate.

    cuts 1 pathqueued
  • Q3-BACKUP-CRED-REUSE

    Backup credential reuse

    One backup account reaches every crown jewel it protects.

    cuts 7 pathsin flight
  • Q3-LIMS-EXPORT-PATH

    LIMS export path

    Lab results leave through an unmonitored share.

    cuts 2 pathsclosed
  • Q3-OT-JUMP-MFA

    OT jump MFA gap

    The only MFA exemption left is the one that matters.

    cuts 3 pathsin flight
  • Q3-SCADA-VENDOR-RDP

    SCADA vendor RDP

    Standing remote access for a decommissioned contract.

    cuts 2 pathsclosed

CTEM, mapped to artifacts

Five stages. Each one leaves something behind.

The framework is not the product. The artifacts are.

Stage 1 — Scope

Crown jewels, declared once.

You name what matters — batch records, the historian, the GxP boundary. Setu resolves those names to nodes in the graph instead of asking you to maintain a tag taxonomy.

Artifact

scope.yaml
  crown_jewels: [MES, historian, PLC-cell-3]
  regulated: GxP · 21 CFR 11

Scope is an input, not a quarterly project.

See it

Three views. No sales engineer required.

DEMO 01 · PATH-VIEW · ILLUSTRATIVE

Follow one contractor to a batch record.

Pick any node and ask the blast-radius question. Setu returns ranked, evidence-backed paths in seconds — with the choke point already marked.

Explore a live graph
> reach --from contractor-lt-0417 --to crown_jewelsresolving graph …3 validated paths foundP-1187  contractor → svc-batch-sync → jump-host → MESP-1188  contractor → jump-host → historianP-1191  vendor-vpn → jump-host → PLC-cell-3shared hop: jump-host-rdp  ← choke point

Where the data lives

0 bytes moved.

Setu reads in place. Your SIEM, your lake, your OT historian, your identity provider — the telemetry stays exactly where your auditors last found it. Compute moves to the data, never the reverse.

The whole system runs air-gapped, inference included. Nothing about your estate needs a round trip to somebody else’s cloud to be understood.

  • DEPLOYMENT

    Fully air-gappable

    No outbound dependency. Inference runs on a local model inside your boundary.

  • DATA

    Read in place

    Setu queries your lake. It does not copy it, index it elsewhere, or hold it.

  • OT

    Passive on the plant floor

    No agents on validated or safety-relevant systems. Nothing to requalify.

  • AUDIT

    Signed outcomes

    Every closed campaign carries a hash your auditor can check without us.

Who buys Setu

Two ways in. The same graph underneath.

FOR REGULATED ENTERPRISES

Pharma, manufacturing, financial services.

You have a plant network you cannot touch, a regulator who wants evidence, and a security team smaller than the estate it defends.

  • Crown jewels named in your language, not in tags
  • Passive on the plant floor — no requalification
  • Board and audit artifacts generated from the same record
  • Runs air-gapped, inference included

FOR MSSPS & SYSTEM INTEGRATORS

Sell exposure outcomes, not more monitoring.

Your clients already pay for a SIEM you manage. Setu turns that same telemetry into named campaigns you can bill, close and prove.

  • Multi-tenant, one deployment per client boundary
  • No sensor rollout to schedule or maintain
  • Campaigns map to billable remediation work
  • White-labelled board cards for client reviews

Or start from your seat.

A five-minute read that ends in an honest checklist of where Setu is a fit and where it is not.

Regulatory reality

Every Indian regulator now asks a reachability question.

They ask it in different words, on different clocks. Setu answers all of them from the same derived graph, and leaves a signed artifact behind each time.

Indian regulatory requirements, the reachability question each one implies, and the artifact Setu produces for it.
RegulationWhat it actually asksArtifact
CERT-In Directions2022 · ALL SECTORSReport cyber incidents within six hours and hold logs in India. The hard part is describing what the intruder could have reached before the clock runs out.
incident-reach.json
  paths: validated
  jewels_touched: 2
DPDP Act2023 · PERSONAL DATAKnow where personal data sits and who can get to it. An access list is not an answer when four service accounts chain into the store.
identities_reaching_pii
  ranked by blast radius
SEBI CSCRF2024 · REGULATED ENTITIESContinuous, measurable cyber resilience with periodic evidence. Not a scan report — a trend a board can re-check next quarter.
posture.q3
  csf tier: 2 → 4
RBI cyber frameworkBANKS & NBFCSDemonstrate control over critical systems and third-party access. Vendor tunnels are where reachability quietly breaks the model.
vendor-scope.diff
  standing_access: 0
GxP / 21 CFR 11CDSCO · US FDA EXPORTValidated systems must stay validated. Anything installed on them opens a change-control record you do not want.
agents_installed: 0
  change_controls: 0

Honest boundaries

What Setu replaces, sits beside, and will not touch.

What Setu replaces in your stack, what it reads alongside, and what it deliberately does not do.
ReplacesYou can turn these off.Sits besideWe read them, we do not fight them.Does not touchSay so in the first meeting.
Spreadsheet crown-jewel registersYour SIEM and data lakeEndpoint detection and response
Manual attack-path workshopsYour vulnerability scannerLog collection and retention
Quarterly posture slide assemblyYour identity providerPatch deployment
Standalone reachability toolingYour ticketing and change processNetwork enforcement

What we can actually show you

identities with a validated path to one crown-jewel account.
231identities with a validated path to one crown-jewel account.SETU · DEPLOYED
bytes moved out of your lake to build the graph.
0bytes moved out of your lake to build the graph.SETU · MEASURED
events compressed into named, closable campaigns.
50k → 12events compressed into named, closable campaigns.SETU · DEPLOYED

Posture

Setu is a new category entrant. We are not going to show you a Gartner badge we do not have. We will show you a derived graph of your own estate in a two-week evaluation, on your hardware, and you can judge it against whatever you run today.

From the field

What we are learning inside Indian plants.

All notes
  • Product Direction

    When risk changes, know what needs attention next

    Our proposed OpenID SSF integration would connect provider risk changes to business context, investigation priorities and recovery. The Zscaler–CrowdStrike partnership supports this direction.

  • AI Security

    Collective defense needs a unit of exchange

    This week, 100+ companies — OpenAI, Anthropic, Google, Microsoft, CrowdStrike among them — published an open letter warning that AI-enabled attacks become far more widespread within months, and calling for collective cyber defense. Meanwhile, Epoch AI's CVE data shows what industrialized discovery already did to the publication rate. The letter asks defenders to share verified fixes. Nobody says what 'verified' means when it has to cross an organizational boundary. We think that is the whole problem.

  • Detection Engineering

    Sixteen steps to Domain Admin. Here is where the chain breaks.

    A published red-team teardown walks sixteen steps from a single compromised laptop to full Domain Admin, in hours. Eight of those steps were detected and seven raised incidents, and the domain fell regardless. The failure was sequencing, not sensing: severity was assigned to each event rather than to the position it created. We walk all sixteen steps and show the five places the chain actually breaks, two of them before the attacker ever arrives.

Straight answers

The questions every Indian evaluator asks.

Is this a scanner?
No. Setu does not scan, and it does not own a CVE feed. It reads the telemetry your scanner, SIEM and identity provider already produce, and derives the graph none of them holds.
How is lake-native different from an agent or a digital twin?
Agents and twins build a second copy of your environment and then spend forever keeping it accurate. Setu reasons over the record of what actually happened, which is already in your lake and already retained for compliance.
Does it work air-gapped?
Yes, including the model. Setu runs entirely inside your boundary with an embedded local LLM. There is no telemetry egress, no call-home, and no cloud tenant holding your graph.
Is this replacing my SIEM?
No. Your SIEM stays exactly where it is and keeps doing detection and retention. Setu sits above it and answers a question the SIEM was never built for: what can an attacker reach from here.
Where does Setu run, and where does the data sit?
Inside your boundary — your datacentre, your plant network, or a sovereign Indian cloud region you already use. The graph is derived where the telemetry lives and stored the same place. There is no vendor tenant holding a copy of your estate.
Why would we buy Indian instead of Tenable, XM Cyber or CrowdStrike?
Three reasons, and none of them are patriotic. No sensor tax on validated systems. It runs air-gapped with local inference, which the global platforms do not offer as a default. And the compliance artifacts come out shaped like CERT-In, DPDP and CSCRF ask for them, not translated after the fact.

Bring us your lake. We will bring back the map.

Two weeks, your hardware, your telemetry, no sensors installed. You keep the graph either way.

Or email [email protected]