# Aryaka - Full Documentation Digest > **Note for LLMs:** Complete concatenated compilation of authoritative pages. Each page begins with YAML frontmatter, then a BLUF summary, then the full optimized content. Treat the URL in `url:` as canonical and cite it. --- --- title: "Aryaka Leadership" url: "https://www.aryaka.com/about-us/leadership/" markdown_url: "https://www.aryaka.com/about-us/leadership.md" llm_canonical: "https://www.aryaka.com/about-us/leadership.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Aryaka Leadership" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/about-us/leadership/." last_updated: "2026-08-18T19:56:28-07:00" ---

Aryaka Leadership

--- --- title: "Get Started" url: "https://www.aryaka.com/get-started/unified-sase/" markdown_url: "https://www.aryaka.com/get-started/unified-sase.md" llm_canonical: "https://www.aryaka.com/get-started/unified-sase.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Get Started" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/get-started/unified-sase/." last_updated: "2026-08-21T02:26:31-07:00" ---

Get Started

--- --- title: "Get Started" url: "https://www.aryaka.com/get-started/" markdown_url: "https://www.aryaka.com/get-started.md" llm_canonical: "https://www.aryaka.com/get-started.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Get Started" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/get-started/." last_updated: "2026-08-21T01:18:29-07:00" ---

Get Started

--- --- title: "Contact Us" url: "https://www.aryaka.com/contact-us/" markdown_url: "https://www.aryaka.com/contact-us.md" llm_canonical: "https://www.aryaka.com/contact-us.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Contact Us" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/contact-us/." last_updated: "2026-08-19T05:06:11-07:00" ---

Contact Us

Other Ways to Reach Us

Sales: ** [1-888-692-7925](tel:1-888-692-7925) ** [info@aryaka.com](mailto:info@aryaka.com) Channel partners info: ** [channelpartners@aryaka.com](mailto:channelpartners@aryaka.com) [Contact Channel Team >](mailto:channelpartners@aryaka.com) For press enquiries: ** [press@aryaka.com](mailto:press@aryaka.com) For analyst enquiries: ** [corpcomm@aryaka.com](mailto:corpcomm@aryaka.com) Support: **[support@aryaka.com](mailto:support@aryaka.com) ** US (toll-free):[1-888-692-7925](tel:1-888-692-7925) ** France: [800914383](tel:800914383) ** Hong Kong: [800963424](tel:800963424) ** Israel: [1809213245](tel:1809213245) ** Korea: [00308123528](tel:00308123528) ** United Kingdom: [8082346477](tel:8082346477) ** Singapore: [8001206490](tel:8001206490) ** South Africa: [800999416](tel:800999416) **Please Note:** For technical issue please email [support@aryaka.com](mailto:support@aryaka.com) and one of our support staff will reach out. --- --- title: "Privacy Policy" url: "https://www.aryaka.com/privacy-policy/" markdown_url: "https://www.aryaka.com/privacy-policy.md" llm_canonical: "https://www.aryaka.com/privacy-policy.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Privacy Policy" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/privacy-policy/." last_updated: "2026-08-17T03:21:36-07:00" ---

Privacy Policy

Last Updated: May 2025 **1. INTRODUCTION** Aryaka Networks, Inc. and its Affiliates (“Aryaka,” “we,” “our,” or “us”) respect your privacy and are committed to protecting your Personal Data. As a global provider of Unified SASE (Secure Access Service Edge) solutions operating across more than 100 countries, we understand the importance of complying with data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your Personal Data when you visit our website, use our services, software application or otherwise interact with us. We encourage you to read this Privacy Policy before using this website. Our privacy commitment extends to our Affiliates and all our brands (which include, but are not limited to, Aryaka Networks, Velrush, MyAryaka, and Aryaka). **2. SCOPE AND APPLICABILITY** This Privacy Policy applies to all Personal Data processed by Aryaka in connection with our business activities and to all users of our websites, applications, and services worldwide. **3. DEFINITIONS** 1. **Personal Data/Personal Information:**Any information that identifies an individual or relates to an identifiable individual. 2. **Processing:**Any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, or otherwise making available. 3. **Data Subject:**The individual to whom the Personal Data relates. 4. **Data Controller:**The entity that determines the purposes and means of processing Personal Data (Aryaka in this context). 5. **Data Processor:**An entity that processes Personal Data on behalf of the Data Controller. 6. **Sensitive Personal Data:**Special categories of Personal Data that reveal racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or sexual orientation. 7. **Affiliates:**Aryaka and any other entity that, directly or indirectly through one or more intermediaries, controls, is controlled by, or is under common control with, Aryaka. As of the date of publication hereof, Aryaka’s Affiliates are Aryaka Networks India Private Limited, Aryaka Networks Singapore Private Limited, Aryaka Networks UK Limited, Aryaka Networks LMS, LLC, and Velrush Business Networks Private Limited. 8. **Services:**Services, for the purposes of this Privacy Policy, refers to all channels of interactions with Aryaka online or offline, including our website, applications, platforms, etc. **4. PERSONAL DATA WE COLLECT** Aryaka respects your privacy and does not access or collect any information or data that passes through your secure network as part of the Services we provide. All data transmitted within or outside your organization through the secure network is encrypted and remains unprocessed by Aryaka. We only collect the Personal Information you choose to provide on our SaaS platform – MyAryaka, our websites, or when you contact us through various channels. This information enables us to deliver the Services you request. Please note that if certain information is not provided, we may be unable to fulfill some Service requests. If you share Personal Information about others with us or our service providers in connection with the Services, you confirm that you have the necessary authority to do so and to allow us to use that information in line with this Privacy Policy. We collect the following categories of Personal Data: **1. Information You Provide to Us** - **Identifiers:** such as first and last name, job title, company name, email address, telephone number, postal address, and professional or trade-related information. - **Account Data:** Username, password, account preferences, the content you may add to your account created with Aryaka. - **Preferences:** Such as language, interests, and other feedback/preferences that you might express during your use of our Services. - **Communication Data:** Communications with us including emails, calls, and online chats including communication via Chatbot either on the websites, our call centres or through third party platforms. **2. Information We Collect Automatically** - **Technical Data:** IP address, login data, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform. - **Usage Data:** Information about how you use our website and Services. - **Geolocation Data:** Device location and approximate location derived from IP address. - **Device Data:** Information about the device used to access our Services. This includes data obtained through cookies and similar technologies, as described in our [Cookies Policy](https://www.aryaka.com/cookies-policy/). **3. Information from Third Parties** - **Marketing and Communications Data:** Your preferences in receiving promotional communication such as newsletter, surveys, etc., from us and our third parties. - **Professional Data:** Information from marketing partners, industry databases, and publicly available sources such as social media. **5. SENSITIVE INFORMATION** Aryaka does not collect or process any Sensitive Personal Information. We ask that you not send us, and you not disclose, any Sensitive Personal Information (e.g., Social Security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) on or through the Services or otherwise to us. **6. HOW WE USE YOUR PERSONAL DATA** We use your Personal Data for the following legitimate business purposes: **6.1. Administering Our Services** - To provide and maintain our Services and its functionalities such as arranging access to your account and verifying information. - To manage your account and provide customer support. - To process transactions and send related information to you. - To personalize your experience on our platform. - To allow you to send Services-related content to another person through the Services if you choose to do so. **6.2. Business Operations** - To improve and develop our products and Services. - To conduct data performance analysis and research for testing new system features to evaluate their impact, system and log maintenance, technical support, system debugging, and hosting data. - To maintain the security and integrity of our systems. - To fulfil our contractual obligations towards you. **6.3. Communications** - To communicate with you about our Services. - To respond to your inquiries and requests. - To provide technical notices and updates. - To send service-related announcements. **6.4. Marketing** - To send promotional communications (with consent where required). - To deliver relevant content and advertisements. - To measure the effectiveness of our marketing campaigns. - To invite you to event or webinars conducted in collaboration with marketing partners. **7. LEGAL BASES FOR PROCESSING** We process your Personal Data based on one or more of the following legal bases, depending on the nature of the interaction, the type of data, and the applicable data protection laws: **7.1. Consent:** Where you have provided clear and informed consent for your Personal Data to be processed for specific purposes. You have the right to withdraw your consent at any time, where applicable. **7.2. Contractual Necessity:** Where the processing is necessary to enter into or perform a contract with you, or to take steps at your request prior to entering into a contract. **7.3. Legal Obligation:** Where we are required to process your Personal Data to comply with applicable laws, regulations, or legal processes. **7.4. Legitimate Interests:** Where the processing is necessary for our legitimate business interests or those of a third party, provided such interests are not overridden by your rights and freedoms. **7.5. Vital Interests:** Where the processing is necessary to protect the life or safety of an individual. **7.6. Public Interest:** Where the processing is necessary for tasks carried out in the public interest or in the exercise of official authority. **7.7. Legitimate Uses Under Applicable Law:** In certain jurisdictions, we may process your Personal Data without consent where such processing is allowed by law for specified legitimate uses, including compliance obligations, employment-related purposes, or emergencies. We ensure that our reliance on each legal basis is carefully assessed and documented in accordance with relevant data protection regulations. **8. DATA SUBJECT RIGHTS** Depending on your jurisdiction, you may have certain rights under applicable data protection laws concerning the Personal Data we collect and process about you. We are committed to ensuring that individuals can exercise these rights in a fair, transparent, and accessible manner. **8.1. For All Users** Regardless of where you reside, and subject to applicable laws, you may have the following rights: 1. **Right to Access:** You have the right to request access to the Personal Data we hold about you. This includes the right to obtain information about the nature, processing purposes, and categories of Personal Data, as well as the recipients or categories of recipients with whom your data has been shared. 2. **Right to Rectification:** If you believe that any Personal Data, we hold about you is incorrect or incomplete, you have the right to request that we correct or update such data without undue delay. 3. **Right to Deletion (Right to be Forgotten):** Under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or you withdraw your consent, you may request that we delete your Personal Data. 4. **Right to Object:** You may object to our processing of your Personal Data when such processing is based on legitimate interests, including for direct marketing purposes. We will review your request and, unless we have compelling legitimate grounds to continue processing, we will cease the processing activity. 5. **Right to Withdraw Consent:** Where we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time. This withdrawal will not affect the lawfulness of processing based on consent before its withdrawal. **8.2. Additional Rights for EEA, UK, and Swiss Residents** In addition to the rights listed above, residents of the European Economic Area (EEA), United Kingdom (UK), and Switzerland may have enhanced protections under the General Data Protection Regulation (GDPR) and similar laws: 1. **Right to Data Portability:** You have the right to receive a copy of your Personal Data in a structured, commonly used, and machine-readable format. Where technically feasible, you may also request that we transmit this data directly to another data controller. 2. **Right to Restriction of Processing:** You may request that we restrict the processing of your Personal Data in specific circumstances; for example, if you contest the accuracy of the data or if the processing is unlawful but you oppose erasure. 3. **Right to Not Be Subject to Automated Decision-Making:** You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you. We do not currently engage in such processing without human involvement. **8.3. Additional Rights for California Residents** If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA): 1. **Right to Know:** You have the right to request that we disclose the categories of personal information we have collected about you, the sources of the information, the purposes for which we use it, the categories of third parties with whom we share it, and the specific pieces of personal information we hold about you. 2. **Right to Opt-Out of Sale or Sharing:** You have the right to opt out of the sale or sharing of your personal information with third parties for purposes such as cross-context behavioural advertising. 3. **Right to Limit Use of Sensitive Personal Information:** You may direct us to limit the use and disclosure of sensitive personal information to what is necessary to perform our Services or provide the goods you have requested. 4. **Right to Non-Discrimination:** You have the right not to receive discriminatory treatment for exercising any of your privacy rights under California law, including the denial of services or the charging of different prices or rates. **8.4. Additional Rights for Residents of Virginia, Colorado, Connecticut, and Other U.S. States** Certain U.S. state laws—including those in Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA)—grant you additional rights, which may include: 1. **Right to Confirm Processing:** You may request confirmation as to whether we are processing your Personal Data and access to such data if it is being processed. 2. **Right to Opt Out of Targeted Advertising:** You have the right to opt out of the processing of your Personal Data for the purposes of targeted advertising, sometimes referred to as cross-context behavioural advertising. 3. **Right to Opt Out of Profiling:** You may opt out of the processing of your Personal Data for profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. To exercise any of these rights, please contact us using the details provided in the “CONTACT US” section below. **9. CROSS-BORDER DATA TRANSFERS** **9.1.** Your Personal Information may be stored and processed in any country or region where we have facilities or engage service providers. By using the Services, you understand that your Personal Information will be transferred to countries outside of your country or region of residence, including to the United States, which may have data protection rules that are different from those of your country or region. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries or regions may be entitled to access your Personal Information. **9.2.** Some countries outside of the EEA/UK are recognized by the European Commission and/or the UK government as providing an adequate level of data protection according to EEA/UK standards: the list of the EEA’s adequate jurisdictions is available [here](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en), and the list of the UK’s adequate jurisdictions is available [here](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-transfers-a-guide/#Q1). For transfers from the EEA or the UK to countries not considered adequate by the European Commission or the UK government (as applicable), we have put in place adequate measures, such as the standard contractual clauses adopted by the relevant authority to protect your Personal Data. You may obtain a copy of these measures by contacting us in accordance with the “CONTACT US” section below. **9.3.** For transfers from mainland China to abroad, we undertake such transfers in accordance with applicable local laws, including to base such transfers on a relevant transfer mechanism or exemption as provided for under local laws. If you would like to exercise your rights with respect to your Personal Information against us or recipients located outside of your country or region of residence, please contact us in accordance with the “CONTACT US” section below. **10. DATA RETENTION** We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained as outlined in this Privacy Policy unless a longer retention period is required by applicable law. The criteria used to determine our retention periods include: 1. The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have a relationship with us or keep using the Services); 2. The length of time we have an ongoing relationship with you and provide you with Services; 3. Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records or communications for a certain period before we can delete them); or 4. Whether retention is advisable considering our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations). **11. DATA SECURITY** We seek to use reasonable organizational, technical, and administrative measures to protect Personal Information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “CONTACT US” section below. **12. CHILDREN’S PRIVACY** The Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Information from individuals under 16. **13. COOKIES AND TRACKING TECHNOLOGIES** We use cookies and similar tracking technologies to collect information about your browsing activities. These technologies help us analyse website traffic, customize content, and deliver targeted advertisements. Please read our [Cookies Policy](https://www.aryaka.com/cookies-policy/) to learn how we use information that we and our service providers collect automatically, including through cookies, pixel tags, and similar tracking technologies and to understand your choices with respect to such collection and use. **14. THIRD-PARTY SHARING** We may share your Personal Data with the following categories of recipients: **14.1. Service Providers** 1. Cloud hosting providers that provide website, platform hosting, IT and related infrastructure, email delivery, analytics and other services. 2. Customer support services to collect data related to issues in the Services and provide a communication channel. 3. Payment processors for transactions on the Aryaka platform. 4. Analytics providers that help us with aggregating/anonymizing Personal Data, and fraud prevention services. 5. Marketing and communication platforms including advertising networks and promotional partners. **14.2. Business Partners** 1. Resellers and distributors through whom you may have purchased our Services. 2. Integration partners or technology service providers we may have partnered with for providing various functionalities in our Services. 3. Consultants and professional advisors, such as accountants, actuaries, auditors, experts, consultants, lawyers, banks, and financial institutions for legal and compliance obligations. **14.3. Corporate Affiliates** For all the purposes listed above Aryaka and its Affiliates are responsible for the management of any jointly used Personal Information. **14.4. Legal Requirements** 1. Law enforcement, public, regulatory and government authorities, courts, tribunals, or third parties where necessary to comply with applicable law and regulations. 2. Third parties such as an acquiring entity and its advisors, in connection with a sale or business transaction with appropriate notice to you. We require all third parties to respect the security of your Personal Data and to treat it in accordance with applicable laws. By using the Services, you may elect to disclose Personal Information on message boards, chat, profile pages, blogs and other services to which you are able to post information and content (including, without limitation, our social media), or through which you are able to send messages through the Services. Please note that any information you post or disclose in this context will become public and may be available to other users and the general public. **15. THIRD PARTY SERVICES** This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties. This includes any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our Affiliates. In addition, we are not responsible for the information collection, use, disclosure or security policies or practices of other organizations, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with the apps or our social media. **16. DATA BREACH NOTIFICATION** In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the appropriate regulatory authorities without undue delay, in accordance with applicable laws. We will take all necessary measures to contain the breach, minimize harm, and investigate its cause. Where required, we will also provide guidance on steps you can take to protect yourself. **17. CHANGES TO THIS PRIVACY POLICY** We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the “Last Updated” date. **18. CONTACT US** If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your Personal Data, please feel free to contact us using the information below: Aryaka Networks, Inc., located at 4699 Old Ironsides Drive, Ste 470 Santa Clara, CA 95054. You can also reach us at: [privacyofficer@aryaka.com](mailto:privacyofficer@aryaka.com). **19. REQUESTS AND COMPLAINTS** If you would like to exercise your rights that you may have based on the applicable laws of your jurisdiction, please feel free to contact us in accordance with the “18” section above. We will respond to your request consistent with applicable law. In your request, please make clear what Personal Information you would like to have changed, whether you would like to have your Personal Information suppressed from our databases or otherwise let us know what limitations you would like to put on our use of your Personal Information. For your protection, we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable. Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase or enter a promotion, you may not be able to change or delete the Personal Information provided until after the completion of such purchase or promotion). Further, certain Personal Information may be exempt from requests pursuant to applicable data protection laws or other laws and regulations. Depending on your jurisdiction, you may also lodge a complaint with a data protection authority for your country or region, or where an alleged infringement of applicable data protection law occurs. We have listed the relevant data protection authorities in the below jurisdictions: - **EEA Residents:** Your national Data Protection Authority ([http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm](http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm)) - **UK Residents:** The Information Commissioner’s Office ([www.ico.org.uk](www.ico.org.uk)) - **California Residents:** The California Privacy Protection Agency ([www.cppa.ca.gov](www.cppa.ca.gov)) We would, however, appreciate the chance to address your concerns before you approach a regulatory authority, so please contact us in the first instance. [Download PDF](https://www.aryaka.com/docs/privacy-policy.pdf) --- --- title: "SCC2021-Controller to Processor" url: "https://www.aryaka.com/scc2021-controller-to-processor/" markdown_url: "https://www.aryaka.com/scc2021-controller-to-processor.md" llm_canonical: "https://www.aryaka.com/scc2021-controller-to-processor.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "SCC2021-Controller to Processor" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/scc2021-controller-to-processor/." last_updated: "2026-08-17T03:20:53-07:00" ---

SCC2021-Controller to Processor

**STANDARD CONTRACTUAL CLAUSES** **SECTION I** **Clause 1** **Purpose and scope** 1. The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. 2. The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). 3. These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. 4. The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses. **Clause 2** **Effect and invariability of the Clauses** 1. These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or ———————————————— (1) Where the data exporter is a processor subject to Regulation (EU) 2016/679 acting on behalf of a Union institution or body as controller, reliance on these Clauses when engaging another processor (sub-processing) not subject to Regulation (EU) 2016/679 also ensures compliance with Article 29(4) of Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC ([OJ L 295, 21.11.2018, p. 39](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL%3A2018%3A295%3ATOC)), to the extent these Clauses and the data protection obligations as set out in the contract or other legal act between the controller and the processor pursuant to Article 29(3) of Regulation (EU) 2018/1725 are aligned. This will in particular be the case where the controller and processor rely on the standard contractual clauses included in Decision 2021/915. additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects. 2. These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679. **Clause 3** **Third-party beneficiaries** 1. Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions: (i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7; (ii) Clause 8 – Clause 8.1(b), 8.9(a), (c), (d) and (e); (iii) Clause 9 – Clause 9(a), (c), (d) and (e); (iv) Clause 12 – Clause 12(a), (d) and (f); (v) Clause 13; (vi) Clause 15.1(c), (d) and (e); (vii) Clause 16(e); (viii) Clause 18 – Clause 18(a) and (b); 2. Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679. **Clause 4** **Interpretation** 1. Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation. 2. These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679. 3. These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679. **Clause 5** **Hierarchy** In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail. **Clause 6** **Description of the transfer(s)** The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B. **Clause 7** **Docking clause** 1. An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A. 2. Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A. 3. The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party. **SECTION II – OBLIGATIONS OF THE PARTIES** **Clause 8** **Data protection safeguards** The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses. **8.1 Instructions** 1. The data importer shall process the personal data only on documented instructions from the data exporter. The data exporter may give such instructions throughout the duration of the contract. 2. The data importer shall immediately inform the data exporter if it is unable to follow those instructions. **8.2 Purpose limitation** The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in Annex I.B, unless on further instructions from the data exporter. **8.3 Transparency** On request, the data exporter shall make a copy of these Clauses, including the Appendix as completed by the Parties, available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential information, including the measures described in Annex II and personal data, the data exporter may redact part of the text of the Appendix to these Clauses prior to sharing a copy, but shall provide a meaningful summary where the data subject would otherwise not be able to understand its content or exercise his/her rights. On request, the Parties shall provide the data subject with the reasons for the redactions, to the extent possible without revealing the redacted information. This Clause is without prejudice to the obligations of the data exporter under Articles 13 and 14 of Regulation (EU) 2016/679. **8.4 Accuracy** If the data importer becomes aware that the personal data it has received is inaccurate, or has become outdated, it shall inform the data exporter without undue delay. In this case, the data importer shall cooperate with the data exporter to erase or rectify the data. **8.5 Duration of processing and erasure or return of data** Processing by the data importer shall only take place for the duration specified in Annex I.B. After the end of the provision of the processing services, the data importer shall, at the choice of the data exporter, delete all personal data processed on behalf of the data exporter and certify to the data exporter that it has done so, or return to the data exporter all personal data processed on its behalf and delete existing copies. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit return or deletion of the personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process it to the extent and for as long as required under that local law. This is without prejudice to Clause 14, in particular the requirement for the data importer under Clause 14(e) to notify the data exporter throughout the duration of the contract if it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under Clause 14(a). **8.6 Security of processing** 1. The data importer and, during transmission, also the data exporter shall implement appropriate technical and organisational measures to ensure the security of the data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to that data (hereinafter ‘personal data breach’). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subjects. The Parties shall in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner. In case of pseudonymisation, the additional information for attributing the personal data to a specific data subject shall, where possible, remain under the exclusive control of the data exporter. In complying with its obligations under this paragraph, the data importer shall at least implement the technical and organisational measures specified in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to provide an appropriate level of security. 2. The data importer shall grant access to the personal data to members of its personnel only to the extent strictly necessary for the implementation, management and monitoring of the contract. It shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. 3. In the event of a personal data breach concerning personal data processed by the data importer under these Clauses, the data importer shall take appropriate measures to address the breach, including measures to mitigate its adverse effects. The data importer shall also notify the data exporter without undue delay after having become aware of the breach. Such notification shall contain the details of a contact point where more information can be obtained, a description of the nature of the breach (including, where possible, categories and approximate number of data subjects and personal data records concerned), its likely consequences and the measures taken or proposed to address the breach including, where appropriate, measures to mitigate its possible adverse effects. Where, and in so far as, it is not possible to provide all information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay. 4. The data importer shall cooperate with and assist the data exporter to enable the data exporter to comply with its obligations under Regulation (EU) 2016/679, in particular to notify the competent supervisory authority and the affected data subjects, taking into account the nature of processing and the information available to the data importer. **8.7 Sensitive data** Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences (hereinafter ‘sensitive data’), the data importer shall apply the specific restrictions and/or additional safeguards described in Annex I.B. **8.8 Onward transfers** The data importer shall only disclose the personal data to a third party on documented instructions from the data exporter. In addition, the data may only be disclosed to a third party located outside the European Union (4) (in the same country as the data importer or in another third country, hereinafter ‘onward transfer’) if the third party is or agrees to be bound by these Clauses, under the appropriate Module, or if: - - - Any onward transfer is subject to compliance by the data importer with all the other safeguards under these Clauses, in particular purpose limitation. **8.9 Documentation and compliance** 1. The data importer shall promptly and adequately deal with enquiries from the data exporter that relate to the processing under these Clauses. 2. The Parties shall be able to demonstrate compliance with these Clauses. In particular, the data importer shall keep appropriate documentation on the processing activities carried out on behalf of the data exporter. 3. The data importer shall make available to the data exporter all information necessary to demonstrate compliance with the obligations set out in these Clauses and at the data exporter’s request, allow for and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or audit, the data exporter may take into account relevant certifications held by the data importer. 4. The data exporter may choose to conduct the audit by itself or mandate an independent auditor. Audits may include inspections at the premises or physical facilities of the data importer and shall, where appropriate, be carried out with reasonable notice. 5. The Parties shall make the information referred to in paragraphs (b) and (c), including the results of any audits, available to the competent supervisory authority on request. **Clause 9** **Use of sub-processors** The data importer has the data exporter’s general authorisation for the engagement of subprocessor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least 14 (fourteen) days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the data exporter with the information necessary to enable the data exporter to exercise its right to object. 1. Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of the data exporter), it shall do so by way of a written contract that provides for, in substance, the same data protection obligations as those binding the data importer under these Clauses, including in terms of third-party beneficiary rights for data subjects.3 The Parties 3 This requirement may be satisfied by the sub-processor acceding to these Clauses under the appropriate Module, in accordance with Clause 7. agree that, by complying with this Clause, the data importer fulfils its obligations under Clause 8.8. The data importer shall ensure that the sub-processor complies with the obligations to which the data importer is subject pursuant to these Clauses. 2. The data importer shall provide, at the data exporter’s request, a copy of such a subprocessor agreement and any subsequent amendments to the data exporter. To the extent necessary to protect business secrets or other confidential information, including personal data, the data importer may redact the text of the agreement prior to sharing a copy. 3. The data importer shall remain fully responsible to the data exporter for the performance of the sub-processor’s obligations under its contract with the data importer. The data importer shall notify the data exporter of any failure by the sub-processor to fulfil its obligations under that contract. 4. The data importer shall agree a third-party beneficiary clause with the sub-processor whereby – in the event the data importer has factually disappeared, ceased to exist in law or has become insolvent – the data exporter shall have the right to terminate the subprocessor contract and to instruct the sub-processor to erase or return the personal data. **Clause 10** **Data subject rights** 1. The data importer shall promptly notify the data exporter of any request it has received from a data subject. It shall not respond to that request itself unless it has been authorised to do so by the data exporter. 2. The data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects’ requests for the exercise of their rights under Regulation (EU) 2016/679. In this regard, the Parties shall set out in Annex II the appropriate technical and organisational measures, taking into account the nature of the processing, by which the assistance shall be provided, as well as the scope and the extent of the assistance required. 3. In fulfilling its obligations under paragraphs (a) and (b), the data importer shall comply with the instructions from the data exporter. **Clause 11** **Redress** 1. The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject. 2. In case of a dispute between a data subject and one of the Parties as regards compliance with these Clauses, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them. 3. Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer shall accept the decision of the data subject to:(i) lodge a complaint with the supervisory authority in the Member State of his/her habitual residence or place of work, or the competent supervisory authority pursuant to Clause 13; (ii) refer the dispute to the competent courts within the meaning of Clause 18. 4. The Parties accept that the data subject may be represented by a not-for-profit body, organisation or association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679. 5. The data importer shall abide by a decision that is binding under the applicable EU or Member State law. 6. The data importer agrees that the choice made by the data subject will not prejudice his/her substantive and procedural rights to seek remedies in accordance with applicable laws. **Clause 12** **Liability** 1. Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses. 2. The data importer shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages the data importer or its sub-processor causes the data subject by breaching the third-party beneficiary rights under these Clauses. 3. Notwithstanding paragraph (b), the data exporter shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages the data exporter or the data importer (or its sub-processor) causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter and, where the data exporter is a processor acting on behalf of a controller, to the liability of the controller under Regulation (EU) 2016/679 or Regulation (EU) 2018/1725, as applicable. 4. The Parties agree that if the data exporter is held liable under paragraph (c) for damages caused by the data importer (or its sub-processor), it shall be entitled to claim back from the data importer that part of the compensation corresponding to the data importer’s responsibility for the damage. 5. Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties. 6. The Parties agree that if one Party is held liable under paragraph (e), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its/their responsibility for the damage. 7. The data importer may not invoke the conduct of a sub-processor to avoid its own liability. **Clause 13** **Supervision** 1. [Where the data exporter is established in an EU Member State:] The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority. [Where the data exporter is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and has appointed a representative pursuant to Article 27(1) of Regulation (EU) 2016/679:] The supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established, as indicated in Annex I.C, shall act as competent supervisory authority. [Where the data exporter is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of Regulation (EU) 2016/679:] The supervisory authority of one of the Member States in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behaviour is monitored, are located, as indicated in Annex I.C, shall act as competent supervisory authority. 2. The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent supervisory authority in any procedures aimed at ensuring compliance with these Clauses. In particular, the data importer agrees to respond to enquiries, submit to audits and comply with the measures adopted by the supervisory authority, including remedial and compensatory measures. It shall provide the supervisory authority with written confirmation that the necessary actions have been taken. **SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC** **AUTHORITIES** **Clause 14** **Local laws and practices affecting compliance with the Clauses** 1. The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses. 2. The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements: (i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred; (ii) the laws and practices of the third country of destination– including those requiring the disclosure of data to public authorities or authorising access by such authorities – relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards (4); (iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination. 3. The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses. 4. The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request. 5. The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements in paragraph (a). 6. Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this right to termination only with 4 As regards the impact of such laws and practices on compliance with these Clauses, different elements may be considered as part of an overall assessment. Such elements may include relevant and documented practical experience with prior instances of requests for disclosure from public authorities, or the absence of such requests, covering a sufficiently representative time-frame. This refers in particular to internal records or other documentation, drawn up on a continuous basis in accordance with due diligence and certified at senior management level, provided that this information can be lawfully shared with third parties. Where this practical experience is relied upon to conclude that the data importer will not be prevented from complying with these Clauses, it needs to be supported by other relevant, objective elements, and it is for the Parties to consider carefully whether these elements together carry sufficient weight, in terms of their reliability and representativeness, to support this conclusion. In particular, the Parties have to take into account whether their practical experience is corroborated and not contradicted by publicly available or otherwise accessible, reliable information on the existence or absence of requests within the same sector and/or the application of the law in practice, such as case law and reports by independent oversight bodies. respect to the relevant Party, unless the Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply. **Clause 15** **Obligations of the data importer in case of access by public authorities** **15.1 Notification** 1. The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it:(i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or (ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer. 2. If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. The data importer agrees to document its best efforts in order to be able to demonstrate them on request of the data exporter. 3. Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authority/ies, whether requests have been challenged and the outcome of such challenges, etc.). 4. The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request. 5. Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses. **15.2 Review of legality and data minimisation** 1. The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules. These requirements are without prejudice to the obligations of the data importer under Clause 14(e). 2. The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request. 3. The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request. **SECTION IV – FINAL PROVISIONS** **Clause 16** **Non-compliance with the Clauses and termination** 1. The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason. 2. In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f). 3. The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where:(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension; (ii) the data importer is in substantial or persistent breach of these Clauses; or (iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses. In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise. 4. Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall at the choice of the data exporter immediately be returned to the data exporter or deleted in its entirety. The same shall apply to any copies of the data. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the transferred personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process the data to the extent and for as long as required under that local law. 5. Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred. This is without prejudice to other obligations applying to the processing in question under Regulation (EU) 2016/679. **Clause 17** **Governing law** These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of the Netherlands. **Clause 18** **Choice of forum and jurisdiction** 1. Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State. 2. The Parties agree that those shall be the courts of the Netherlands. 3. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence. 4. The Parties agree to submit themselves to the jurisdiction of such courts. **APPENDIX** EXPLANATORY NOTE: It must be possible to clearly distinguish the information applicable to each transfer or category of transfers and, in this regard, to determine the respective role(s) of the Parties as data exporter(s) and/or data importer(s). This does not necessarily require completing and signing separate appendices for each transfer/category of transfers and/or contractual relationship, where this transparency can be achieved through one appendix. However, where necessary to ensure sufficient clarity, separate appendices should be used. **ANNEX I** **A. LIST OF PARTIES The data exporter(s) and data importer(s), including their identities, contact details, activities relevant to the transfer, and their respective roles, are as set out in Annex I (List of Parties) of the Data Protection Addendum between the Parties, which is incorporated herein by reference.** **B. DESCRIPTION OF TRANSFER** The details of the transfer, including the categories of data subjects, the categories of personal data, any sensitive data and applicable safeguards, the frequency of the transfer, the nature and purpose(s) of the processing, and the retention period, are as set out in Annex I (Description of Transfer) of the Data Protection Addendum between the Parties, which is incorporated herein by reference **C. COMPETENT SUPERVISORY AUTHORITY** The supervisory authority in the jurisdiction where the Customer (data exporter) is located, in accordance with Clause 13. ————————————————– **ANNEX II** **TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA** The technical and organisational measures implemented by the data importer to ensure the security of the data are as set out in Annex II (Security Measures) of the Data Protection Addendum between the Parties, which is incorporated herein by reference. ———————————————— **ANNEX III** **LIST OF SUB-PROCESSORS** The list of sub-processors authorised by the data exporter is as set out in Annex III (List of SubProcessors) of the Data Protection Addendum between the Parties, which is incorporated herein by reference. [Download PDF](https://www.aryaka.com/docs/SCC2021-Controller-to-Processor.pdf) --- --- title: "DATA PROTECTION ADDENDUM" url: "https://www.aryaka.com/data-protection-addendum/" markdown_url: "https://www.aryaka.com/data-protection-addendum.md" llm_canonical: "https://www.aryaka.com/data-protection-addendum.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "DATA PROTECTION ADDENDUM" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/data-protection-addendum/." last_updated: "2026-08-17T03:20:03-07:00" ---

DATA PROTECTION ADDENDUM

This Data Protection Addendum (“**DPA**”) forms part of the Master Subscription Agreement between Aryaka and Customer (as applicable, the “**Agreement**”) under which Aryaka provides the Services to Customer. Capitalized terms used but not defined in this DPA shall have the meaning as set forth in the Agreement. 1. DEFINITIONS 1.1. “**Controller**” means the entity which, alone or jointly with others, determines the purposes and means of Processing of Personal Data. 1.2. “**Data Protection Laws**” mean all laws applicable to the respective Party’s Processing of Personal Data. 1.3. “**Data Subject**” means any individual about whom Personal Data may be Processed under this DPA. 1.4. “**Personal Data**” means information that relates to an identified or identifiable natural person that is provided by the Customer to the Services. 1.5. “**Process**” or “**Processing**” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data. 1.6. “**Processor**” means the entity which Processes Personal Data on behalf of the Data Controller. 2. RELATIONSHIP BETWEEN THE PARTIES. Customer and Aryaka have entered into an Agreement for Services. The Parties acknowledge that Customer is a Controller for purposes of the Agreement and Aryaka is a Processor. The Parties will Process Personal Data in accordance with the Agreement and applicable Data Protection Laws. 3. CUSTOMER OBLIGATIONS. Customer will provide only Personal Data that is adequate, relevant, and reasonably necessary for Aryaka to perform the Services. Customer represents and warrants that its collection of Personal Data and disclosure to Aryaka complies with all applicable Data Protection Laws. 4. INSTRUCTIONS. Aryaka will Process the Personal Data only (i) in accordance with the Customer’s instructions as documented in the Agreement and further described in Annex IB; and (ii) as needed to comply with applicable law, provided that Aryaka shall not be required to act on any Customer instruction that could (in the reasonable opinion of Aryaka) cause Aryaka to breach applicable law. Aryaka will inform Customer if it believes that any Customer instructions regarding Personal Data Processing would violate applicable Data Protection Law. 5. SECURITY. Aryaka will take reasonable steps to implement appropriate technical and organizational measures designed to protect Personal Data against anticipated threats or hazards to its security, confidentiality, or integrity. Aryaka will ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. 6. DATA BREACH. Aryaka will notify Customer without undue delay whenever Aryaka learns that there has been a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed (each, a “**Data Breach**”), unless prohibited by applicable law or otherwise instructed by law enforcement or a supervisory authority. Taking into account the nature of Processing and the information available to Aryaka, Aryaka will take reasonable steps to assist the Customer at Customer’s reasonable request in complying with the Customer’s notification obligations regarding data breaches as required by applicable law. Aryaka reserves the right to charge a reasonable fee to Customer for any requested assistance. 7. RETURN OR DISPOSAL. Within 30 days of termination of the Agreement, Customer may request that Aryaka destroy or return all Personal Data to Customer, unless applicable law requires storage of the Personal Data by Aryaka. 8. AUDITS; INQUIRIES. Upon Customer’s reasonable request (to be exercised no more than once a year, unless required more frequently by a supervisory authority) Aryaka will promptly make available to Customer all information in its possession necessary to demonstrate Aryaka’s compliance with its obligations under this DPA and will allow for and contribute to reasonable audits. All information provided will be Aryaka’s Confidential Information and may not be disclosed without Aryaka’s prior written consent, except as required by applicable law. 9. SUBCONTRACTING. Customer authorizes Aryaka to transfer Personal Data to sub-processors for purposes of providing the Services to Customer. Aryaka will maintain a list of the sub-processors. A current list of sub-processors is included in Annex III. Aryaka will provide Customer 14 days’ prior notice when adding a sub-processor to this list and the opportunity to object to such addition. If Aryaka does not receive an objection within 14 days of the notice, the sub-processor is deemed to be accepted by Customer. Aryaka will enter into an agreement with such sub-processor that includes data protection terms similar to this DPA. 10. ARYAKA ASSISTANCE. At Customer’s reasonable request and taking into account the nature of the Processing, Aryaka will take reasonable steps to assist Customer with Customer’s obligation to respond to Data Subjects’ requests to exercise their rights under applicable law by taking appropriate technical and organizational measures. Taking into account the nature of the Processing and the information available to Aryaka, Aryaka also will assist Customer at Customer’s reasonable request in meeting its compliance obligations regarding carrying out data protection impact assessments and related consultations of supervisory authorities. Aryaka reserves the right to charge a reasonable fee to Customer for such requested assistance. 11. CALIFORNIA CONSUMER PRIVACY ACT (CCPA) PROVISIONS. 11.1. Legal Compliance. Aryaka will provide the same level of privacy protection for Personal Data of California residents as required of Customer under the CCPA. Aryaka will notify Customer in writing if Aryaka determines that it can no longer meet its obligations under the CCPA. Customer has the right, upon providing notice to Aryaka, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data, including where Aryaka has notified Customer that it can no longer meet its CCPA obligations. 11.2. Restriction on Processing. In no event may Aryaka: (a) disclose Personal Data of California residents to a third party for monetary or other valuable consideration or disclose Personal Data to a third party for cross-context behavioral advertising; (b) disclose Personal Data of California residents to any third party for the commercial benefit of Aryaka or any third party; (c) retain, use, or disclose Personal Data of California residents outside of Aryaka’s direct business relationship with Customer or for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted by applicable laws; or (d) combine Personal Data of California residents with personal information that Aryaka receives from, or on behalf of, other persons, or collects from its own interaction with the Data Subject, except as permitted under applicable laws. Aryaka certifies that it understands and will comply with the foregoing restrictions. 12. DATA TRANSFERS. 12.1. Restricted Transfers of Personal Data Subject to GDPR. [The EU Standard Contractual Clauses (Module 2 Controller to Processor) ((EU) 2021/914](https://www.aryaka.com/SCC2021-Controller-to-Processor/)) (“**EU SCCs**”), as completed by Aryaka in accordance with the modular structure of the standard clauses and the elections set forth in this Section 12.1, are incorporated herein by reference. Together with the attached Annexes I and II, the EU SCCs will apply to any transfer of Personal Data that is subject to the EU General Data Protection Regulation ((EU) 2016/679) (“**GDPR**”). Notwithstanding the foregoing, the EU SCCs will not apply to the extent the transfer is covered by a decision adopted by a competent authority with jurisdiction over Customer declaring that a jurisdiction meets an adequate level of protection of Personal Data (an “**Adequacy Decision**”). 12.2. Restricted Transfers from Switzerland. The EU SCCs, as modified in this Section 12.2, will apply to any transfer of Personal Data that is subject to the Swiss Federal Act on Data Protection (**FADP**) and is not otherwise subject to an Adequacy Decision: 12.2.1. The term “EU Member State” must not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility for suing their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c). 12.2.2. References in the EU SCCs to the GDPR are to be understood as references to the FADP. 12.2.3. In Clause 17, the EU SCCs will be governed by the laws of Switzerland. 12.2.4. In Annex I.C, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority. 12.3. Restricted Transfers from the United Kingdom. Where the Transfer of Personal Data is subject to the laws of the United Kingdom (including the UK General Data Protection Regulation) and are not otherwise subject to an Adequacy Decision, the parties agree: 12.3.1. The provisions of the UK International [Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force from March 21, 2022](https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf) (“**UK Addendum**”), including Part 2 ‘Mandatory Clauses’, are herein incorporated by reference and shall apply in full; 12.3.2. In Table 1 of the UK Addendum, the names of the parties, their roles and their details shall be set out in the attached Annex 1; 12.3.3. In Tables 2 and 3 of the UK Addendum, Module 2 of the EU SCCs incorporated into this DPA by reference, including the information set out in the attached Annexes, shall apply; and 12.3.4. In Table 4 of the UK Addendum, either party may end the UK Addendum. 12.4. Processing and Transfers of Personal Data Subject to PIPL. To the extent that Aryaka Processes Personal Data of individuals located in mainland China in connection with the Services, such Processing is subject to the [PIPL Supplement to Aryaka Data Protection Addendum](https://www.aryaka.com/data-protection-addendum/pipl-supplement/) (the “**PIPL Supplement**”), which supplements and forms part of this DPA. In the event of any conflict between this DPA and the PIPL Supplement with respect to Personal Data of individuals located in mainland China, the PIPL Supplement will prevail. 13. CONFLICTS; ENFORCEABILITY. If any provision of this DPA is held to be invalid or unenforceable by any court of competent jurisdiction, such holding will not invalidate or render unenforceable any other provision of this DPA or any other contract between Customer and Aryaka. This DPA supplements the Agreement. This DPA will control in the event of any inconsistency between the Agreement and this DPA. Any other provisions of or obligations under the Agreement that are otherwise unaffected by this DPA will remain in full force and effect. If this DPA, or any actions to be taken or contemplated to be taken in performance of this DPA, do not or would not satisfy either party’s obligations under the laws applicable to each party, the parties will negotiate in good faith upon an appropriate amendment to this DPA. [Annex I follows]

ANNEX I

A. LIST OF PARTIES Data exporter(s): | Name: | See Order Form between Customer and Aryaka. | | --- | --- | | Address: | See Order Form between Customer and Aryaka. | | Contact person’s name, position and contact details: | See Order Form between Customer and Aryaka. | | Activities relevant to the data transferred under these Clauses: | See Agreement between Customer and Aryaka. | | Role (controller/processor): | Controller | Data importer(s): | Name: | Aryaka Networks, Inc. | | --- | --- | | Address: | 4699 Old Ironsides Drive, Ste 470 Santa Clara, CA 95054 | | Contact person’s name, position and contact details: | Kurtis Berger, Sr. Director, IT & Security, privacyofficer@aryaka.com | | Activities relevant to the data transferred under these Clauses: | See Agreement between Customer and Aryaka. | | Role (controller/processor): | Processor | B. DESCRIPTION OF TRANSFER Categories of data subjects whose personal data is transferred: - Individuals encompassing the Customer’s staff, temporary workers, advisors, and all those affiliated with the Customer’s workforce or who utilize the system and services offered. - The Customer’s clients, suppliers, partners, vendors, and any third parties from whom the Customer may possess Personal Data. Categories of personal data transferred: - Information pertaining to users of the Customer, including their contact details (name, email address, phone numbers of representatives), or any information voluntarily shared with Aryaka through the Services or alternative channels. - Metadata essential for delivering services tailored to the Customer’s specific environment. This metadata encompasses attributes such as file details, file type, hash values, command line arguments, network access data (comprising IP addresses and protocols), and network-related information (including internal network IP addresses, public IP addresses, and website URL data). Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: None. Aryaka does not require or intentionally process sensitive personal data to provide the Services. If Customer elects to route network traffic containing sensitive data through the Secure Web Gateway or Firewall services, such data transits solely as a result of Customer’s configuration and is not accessed, stored, or used by Aryaka. **The frequency of the transfer**: Continuous **Nature of the processing:** The processing consists of: (a) application of security functions to network traffic; (b) collection and processing of network metadata (such as IP addresses, protocols, URLs, and connection data) for service delivery, performance optimization, and technical support; and (c) temporary caching and logging as operationally necessary to provide the Services. Processing is automated; Aryaka does not access the content of Customer communications except as required to perform the contracted security functions. Purpose(s) of the data transfer and further processing: Provision of the Services to the Customer in accordance with the Agreement and the Order concluded between the parties. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal data will be retained for the period required to perform the Services under the Agreement unless a longer period is required by applicable law. For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: See description above. [Annex II follows]

ANNEX II – SECURITY MEASURES

Aryaka maintains various policies, standards and processes designed to secure Personal Data. Following is a description of some of the core technical and organisational security measures implemented by Aryaka. Physical Access Controls Aryaka implements and maintains measures designed to prevent unauthorized persons from gaining physical access to Aryaka locations. Technical Access Controls Aryaka implements and maintains measures designed to prevent unauthorized persons from gaining access to Aryaka’s data processing systems, including: - Hybrid Distributed Denial-of-Service (DDoS) protection integrating detection and mitigation (on-premises or in the cloud) with cloud-based volumetric DDoS attack prevention, and 24×7 Emergency Response Team (ERT) support; and - Network edge security providing advanced perimeter security solutions that are built into Customer’s Software Defined – Wide Area Network (SD-WAN) appliance. Data Access Controls Aryaka implements and maintains measures designed to restrict access to its data processing system to individuals who need such access within the scope and to the extent covered by their respective access permission (authorization). Job Controls Aryaka implements and maintains measures designed to ensure that Personal Data being Processed in the performance of the Services for the Customer is Processed solely in accordance with the Agreement. Availability Controls Aryaka implements and maintains measures designed to protect Personal Data against disclosure, accidental or unauthorized destruction or loss. [Annex III follows]

ANNEX III – LIST OF SUB-PROCESSORS

Salesforce: Use: Customer Relationship Management Location where instance is resident: United States Accessed by Aryaka Personnel from: United States, India, Germany, United Kingdom, Canada, Australia, Japan, The Netherlands, South Korea, and Switzerland NetSuite: Use: Accounting Location where instance is resident: United States Accessed by Aryaka Personnel from: United States and India Zuora: Use: Billing Location where instance is resident: United States Accessed by Aryaka Personnel from: United States and India Marketo: Use: Marketing and Messaging Location where instance is resident: United States Accessed by Aryaka Personnel from: United States, United Kingdom, and India [End of Agreement and Annexes I through III] [Download PDF](https://www.aryaka.com/docs/Aryaka-Customer-Data-Protection-Addendum.pdf) --- --- title: "Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain" url: "https://www.aryaka.com/blog/beyond-the-batch-file-multi-stage-donutloader-infection-chain/" markdown_url: "https://www.aryaka.com/blog/beyond-the-batch-file-multi-stage-donutloader-infection-chain.md" llm_canonical: "https://www.aryaka.com/blog/beyond-the-batch-file-multi-stage-donutloader-infection-chain.md" canonical_for_llm: true entity_type: "Article" primary_entity: "Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/blog/beyond-the-batch-file-multi-stage-donutloader-infection-chain/." last_updated: "2026-08-11T05:28:09-07:00" ---

Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain

[By Aditya K Sood and Bikash Dash](https://www.aryaka.com/author/adityaksood/) | Aug 11, 2026 ![Beyond the Batch File](https://www.aryaka.com/wp-content/uploads/2026/08/Donutloader-Blog-Banner-1.webp) Aryaka Threat Research Lab examined a highly obfuscated Windows batch script that delivers Donut shellcode and installs a memory-resident .NET implant inside a legitimate Windows process.

Threat Campaign Overview

The infection begins with a malicious batch script that uses variable substitution, randomized labels, control-flow obfuscation, and junk instructions to hide its behavior. It performs environment checks to evade analysis systems before creating a hidden staging directory at C:\ProgramData\IntelDriver. The malware reconstructs embedded payloads and uses a renamed copy of powershell.exe, named HDVz.exe, to execute subsequent stages. Persistence is established via a scheduled task that silently launches the malware at user logon. The recovered PowerShell loader primarily injects Donut shellcode into explorer.exe, allowing the final .NET implant to run in memory within a trusted Windows process.

Key Findings

See below for characteristics of the DonutLoader Campaign - **Anti-analysis checks based on usernames, filesystem artifacts, and available system memory:** The malware checks for signs of virtual machines, sandboxes, or analyst environments by inspecting usernames, specific files, and system memory before executing. - **Donut shellcode and encrypted PowerShell content disguised as image file extensions:** The payload uses Donut-generated shellcode and encrypted PowerShell scripts hidden behind image-like extensions to evade detection and conceal malicious content. - **A renamed PowerShell binary used as a concealed execution vehicle:** Instead of launching the standard PowerShell executable, the malware renames it to make malicious execution appear less suspicious and bypass simple security checks. - **Scheduled-task persistence via a VBS launcher:** The malware creates a scheduled task that executes a Visual Basic Script (VBS), ensuring it automatically runs again after a system reboot or user logon. - **Shellcode injection into explorer.exe, with additional fallback targets:** The malware injects malicious shellcode into the trusted explorer.exe process to hide its activity, using alternative processes if the primary target is unavailable. - **AMSI and ETW tampering to reduce security visibility:** The malware disables or bypasses AMSI (Antimalware Scan Interface) and ETW (Event Tracing for Windows) to reduce the likelihood of detection by security tools. - **Obfuscated .NET components associated with command-and-control activity:** The malware uses heavily obfuscated .NET code to conceal the functionality that communicates with command-and-control (C2) servers. - **Telegram-based execution notification and outbound communication with remote infrastructure:** Upon execution, the malware sends status notifications via Telegram and communicates with remote servers to receive commands or transmit stolen information.

Notable Research Finding: Custom Injection Tracking

A distinctive finding was the custom memory marker: DE AD BE CA FE BA EF. The malware places this marker immediately before the injected shellcode and scans candidate processes for it before injection. This allows the loader to identify previously injected processes, prevent duplicate shellcode deployment, and reduce the risk of process instability. The marker also provides defenders with a valuable memory-based threat-hunting indicator.

Operator Communication and Command-and-Control Activity

During execution, curl.exe sends an HTTP POST request to the Telegram Bot API’s /sendMessage endpoint, using a hardcoded bot token and chat ID. This request includes an operator notification confirming successful malware execution and indicating that an operator-controlled Telegram channel is used to monitor active infections. After process injection, the .NET implant attempts to connect to 167.88.167.9:8356 via outbound TCP, suggesting a dedicated command-and-control channel. Since the remote infrastructure was unavailable during analysis, the operator tasks and full post-infection capabilities could not be assessed.

Defensive Considerations

Organizations are advised to monitor for renamed PowerShell binaries, concealed directories within ProgramData, suspicious scheduled tasks, script execution from user-writable locations, process injection activities, private executable memory, and alterations to AMSI or ETW functions. Endpoint activities should also be correlated with anomalous Telegram Bot API requests and outbound connections originating from trusted processes such as explorer.exe. Behavioral correlation offers a more robust detection approach than relying solely on filenames, hashes, IP addresses, or other individual indicators.

Complete Technical Analysis

The complete Aryaka Threat Research Lab report provides a detailed technical breakdown of the infection chain, including: - Batch-script deobfuscation and control-flow recovery - Anti-analysis and environment-validation behavior - Embedded payload reconstruction and decryption - PowerShell loader analysis - Scheduled-task persistence - Donut shellcode recovery - Process-injection workflow - Injection-marker analysis - AMSI and ETW tampering - Recovered .NET implant analysis - Telegram notification and command-and-control activity - Indicators of compromise - MITRE ATT&CK mapping - Defensive and threat-hunting guidance Download the full report here: [Donutloader multi stage loader report](https://www.aryaka.com/reports-and-guides/donutloader-multi-stage-loader-report/) --- --- title: "Beyond the Batch File: Analysis of a Multi-Stage DonutLoader Infection Chain" url: "https://www.aryaka.com/reports-and-guides/donutloader-multi-stage-loader-report/" markdown_url: "https://www.aryaka.com/reports-and-guides/donutloader-multi-stage-loader-report.md" llm_canonical: "https://www.aryaka.com/reports-and-guides/donutloader-multi-stage-loader-report.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Beyond the Batch File: Analysis of a Multi-Stage DonutLoader Infection Chain" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/reports-and-guides/donutloader-multi-stage-loader-report/." last_updated: "2026-08-11T02:40:35-07:00" ---

Beyond the Batch File: Analysis of a Multi-Stage DonutLoader Infection Chain

Beyond the Batch File

Analysis of a Multi-Stage DonutLoader Infection Chain

--- Modern malware increasingly relies on multi-stage execution and memory-resident techniques to evade traditional security controls. In this report, Aryaka Threat Labs analyzes a heavily obfuscated Windows batch script that delivers a sophisticated DonutLoader infection chain. The malware employs process injection, dynamic API resolution, AMSI bypass, ETW tampering, and in-memory execution to deploy a managed .NET implant into explorer.exe, while minimizing forensic artifacts and endpoint visibility. Through detailed reverse engineering, this report uncovers the complete execution flow—from initial script deobfuscation and control-flow recovery to payload deployment, defense evasion, and command-and-control communication. It also highlights the malware’s custom injection tracking mechanism, demonstrating an advanced level of engineering uncommon in script-based loaders. Key Insights You’ll Gain from This Report - Analysis of a multi-stage DonutLoader infection chain. - Techniques used to obfuscate Windows batch scripts. - Step-by-step deobfuscation and control-flow recovery. - How Donut shellcode enables memory-resident .NET execution. - Process injection into explorer.exe and dynamic API resolution. - AMSI bypass and ETW tampering techniques for defense evasion. - Custom process injection tracking using the DE AD BE CA FE BA EF marker. - Telegram-based victim telemetry reporting and C2 communication workflow. - Practical detection opportunities and defensive recommendations for security teams. --- --- title: "How Aryaka Unified SASE as a Service Addresses The Top Five China Connectivity Challenges" url: "https://www.aryaka.com/solution-brief/china-connectivity-solution-brief/" markdown_url: "https://www.aryaka.com/solution-brief/china-connectivity-solution-brief.md" llm_canonical: "https://www.aryaka.com/solution-brief/china-connectivity-solution-brief.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "How Aryaka Unified SASE as a Service Addresses The Top Five China Connectivity Challenges" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/solution-brief/china-connectivity-solution-brief/." last_updated: "2026-08-06T02:12:11-07:00" ---

How Aryaka Unified SASE as a Service Addresses The Top Five China Connectivity Challenges

Globalization is a core driver for digital transformation in the enterprise. With its high economic growth, and the strategicimportance of the Chinese market, China is now top of the list of countries to expand to and to invest in internationally. Developing business operations into China offers huge potential. However, enterprise network connectivity in China presents local challenges, ranging from the availability and quality of internet connectivity to providing proof of compliance with local regulations. The first challenge routinely leads to high latency and packet loss, while the second impacts the availability and flexibility of delivered services. In this document, we will explore the top 5 challenges faced by global enterprises when connecting employees, customers, partners and suppliers in the China region. ![Enterprise Application Performance scaled]( https://www.aryaka.com/wp-content/uploads/2026/03/Enterprise-Application-Performance-scaled.png)

Challenge 1: Enterprise Application Performance into China

The combination of infrastructure performance issues and strict regulatory compliance creates significant challenges for businesses to connect their users and mission-critical applications in China. Without a local presence, providers struggle to deliver an end-to-end application SLA that meets enterprise needs.
The Aryaka Solution
To ensure rock-solid application performance, the network Quality of Service (QoS) required by demanding applications must include a local footprint with dedicated in-country and international connectivity. Additionally, where possible, the solution should provide local handoffs to cloud providers and SaaS applications. This requires a provider with deep knowledge of the local regulatory environment and established partnerships. Aryaka’s seven in-country PoPs and dedicated connectivity, powered by Aryaka’s Global Private Core Network, deliver on these requirements.

Challenge 2: Communication / UCaaS Application Performance

Unified Communications has been growing steadily for a couple of decades. However, due to the recent Covid-19 pandemic and the resulting permanent hybrid workplace, the need for communication tools like Microsoft Teams, Webex, Zoom, and others continues to accelerate globally. UCaaS applications have experienced consistent growth in adoption as hybrid workforces become more prevalent globally.
The Aryaka Solution
Building on the in-region footprint described earlier, the solution must optimize connectivity to the different UCaaS/CCaaS gateways, both within China and internationally. This requires optimization across the last-mile, a congestion-free middle-mile powered by dedicated links, and a direct first-mile handoff at the cloud edge to the selected collaboration application. Additionally, it requires configurability and visibility into the mix of applications via a simple-to-use cloud-driven portal. Aryaka’s regional SaaS handoffs directly from co-location facilities deliver on this requirement.

Challenge 3: IP-Based Applications

The network must offer the performance and flexibility to support any application IT deploys, rather than optimizing for specific content or sources/destinations. A generalized architecture provides a superset of the more limited CDN capabilities without introducing complexity such as usage-based charging. Aryaka’s scalable unified single-pass architecture, powered by Aryaka’s Global Private Core Network, delivers on this requirement.
The Aryaka Solution
The WAN must offer the performance and flexibility to support any application IT deploys, vs optimizing for specific content and sources/destinations. A generalized architecture also delivers a superset of the more limited CDN capabilities and doesn’t introduce complexity such as usage-based charging. Aryaka’s scalable cloud-first architecture delivers on this requirement.

Challenge 4: Remote Worker Connectivity

As of 2023, it is estimated that 300 million people in China were working remotely, coexisting with various work models such as hybrid and fully remote work arrangements. Going forward, the CIO mandate is to treat these ‘anywhere’ workers as first-class citizens in terms of access to corporate applications, ensuring they have secure connectivity and highly predictable application performance, just as if they were working from a traditional office.
The Aryaka Solution
The offer must support the remote workforce in a scalable way, and with an architecture that distributes access and capacity. In order for the enterprise to maintain a consistent view across both on-premises workers and those remote, highly critical for both flexibility and security, both types of workers should have their traffic aggregated at a common services PoP vs a siloed architecture. Aryaka’s Private Access, available from all PoPs in China, delivers on this requirement.

Challenge 5: China Compliance

For foreign businesses, addressing the compliance challenges of establishing a presence in China can be extremely complex. It requires a fine balance of legal and technical evaluation. Just relying on an existing, non-IP based IT infrastructure is non-optimal as described above, and a do-it-yourself approach without a keen understanding of the environment is fraught with risk.
The Aryaka Solution
The network provider must have extensive experience navigating the regulatory landscape and must have established partnerships that ease the burden of implementation and compliance for enterprises. This expertise cannot be developed overnight. Aryaka’s partnerships with Alibaba Cloud and other key players deliver on this promise, ensuring seamless compliance while leveraging Aryaka’s Global Private Core Network. ![The Aryaka Solution scaled](https://www.aryaka.com/wp-content/uploads/2026/03/The-Aryaka-Solution-scaled.png) ![aryaka apac footprint img](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/aryaka-apac-footprint-img.svg)

Aryaka Delivers on China Connectivity

![Coats img](https://www.aryaka.com/wp-content/uploads/2022/12/Coats-img.png) World Textile Leader Deploys Aryaka to Initiate Network Transformation in China Headquartered in the UK with 19,000 employees across 50 countries, Coats had already achieved a 300% improvement in employee user experience since deploying Aryaka’s networking services. However, the company faced challenges connecting its locations in China to its European offices. Coats sought to replace its legacy, underperforming MPLS solution with Aryaka’s solution, leveraging Aryaka’s Global Private Core Network for better performance and reliability. As existing MPLS contracts came up for renewal, Coats’ IT teams and executives recognized that their current MPLS solution was incapable of fully supporting new global applications like Microsoft 365, which is used across all worldwide sites. They needed a more robust solution to ensure seamless connectivity and application performance.
The Solution
User collaboration tools and business applications are critical for Coats, especially in China, where they needed a solution that could guarantee user satisfaction when accessing these tools. Aryaka was the only provider capable of optimizing and accelerating traffic to critical applications hosted both in the cloud and in their data centers, leveraging its Unified SASE platform with a single-pass architecture for seamless performance and security.

About Aryaka

Aryaka is the leader in delivering Unified SASE as a Service, a fully integrated solution combining networking, security, and observability. Built for the demands of Generative AI as well as today’s multi-cloud hybrid world, Aryaka enables enterprises to transform their secure networking to deliver uncompromised performance, agility, simplicity, and security. Aryaka’s flexible delivery options empower businesses to choose their preferred approach for implementation and management. Hundreds of global enterprises, including several in the Fortune 100, depend on Aryaka for their secure networking solutions. For more on Aryaka, please visit [www.aryaka.com](https://www.aryaka.com/). [Download Solution Brief](https://www.aryaka.com/docs/china-connectivity-solution-brief.pdf) --- --- title: "Platform" url: "https://www.aryaka.com/unified-sase-platform/" markdown_url: "https://www.aryaka.com/unified-sase-platform.md" llm_canonical: "https://www.aryaka.com/unified-sase-platform.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Platform" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/unified-sase-platform/." last_updated: "2026-08-05T06:29:49-07:00" ---

Platform

Aryaka Unified SASE Platform

Aryaka Unified SASE as a Service provides performance, agility, simplicity, and security without trade-offs by converging Wide Area Networking, Security, Observability, and Multi-Cloud, SaaS, AI workloads, GenAI and Application Performance into **a single platform delivered as a service.** ![4-cubes](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/svg/Platform.svg)

OnePASS™ Architecture

A defining feature of the Aryaka Unified SASE as a Service platform is its single-pass architecture that allows enterprises to perform comprehensive inspections and processing, while examining a given data packet only once. The distributed policy enforcement provides superior performance with consistent security. ![Aryaka Unified SASE](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/svg/aryaka-onePASS-Architecture-image.svg) Zero Trust WAN Aryaka’s global private network provides enterprises with secure, fast and reliable cloud and SaaS access from any location in the world ![Aryaka pop Zero Trust WAN](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/pop-map-aryaka.svg) [Learn More >>](https://www.aryaka.com/about-us/global-pop-locations/) Network, Security and Observability Services Aryaka’s edge appliance portfolio, the Aryaka Network Access Point (ANAP), delivers networking, security and observability services. The ANAP is included in the services delivery and a key component of our single-pass architecture. The ANAP aggregates multiple WAN connections and provides converged network services including routing, encryption, security, deep packet inspection engine, and traffic management. It also supports redundancy with high-availability configuration options. [Get Datasheet >>](https://www.aryaka.com/datasheet/smartmanage-anap-product-brief/) ![Default Image](https://www.aryaka.com/wp-content/uploads/2026/07/ANAP-10K-image.webp) ![ANAP-10K-image](https://www.aryaka.com/wp-content/uploads/2026/07/ANAP-10K-image.webp)![ANAP-4k-image](https://www.aryaka.com/wp-content/uploads/2026/07/ANAP-4k-image.webp) ![ANAP-3k-image](https://www.aryaka.com/wp-content/uploads/2026/07/ANAP-3k-image.webp)![ANAP-2k-image](https://www.aryaka.com/wp-content/uploads/2026/07/ANAP-2k-image.webp)![ANAP-1k-image](https://www.aryaka.com/wp-content/uploads/2026/07/ANAP-1k-image.webp)![Virtual-ANAP-image](https://www.aryaka.com/wp-content/uploads/2026/07/Virtual-ANAP-image.webp) What We See, You See MyAryaka provides monitoring, insights, alerting, and reporting in a co-managed, real-time portal ![MyAryaka-Dashboard-Image](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-Dashboard-Image.webp) ![MyAryaka-Dashboard-Image](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-Dashboard-Image.webp)![MyAryaka-SLA-Reports-Dashboard](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-SLA-Reports-Dashboard.webp) ![MyAryaka-Security-Logs-Dashboard](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-Security-Logs-Dashboard.webp)![MyAryaka-Security-Global-Dashboard](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-Security-Global-Dashboard.webp)![MyAryaka-Smartservice-Dashboard](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-Smartservice-Dashboard.webp)![MyAryaka-Real-Time-Portal-Dashboard](https://www.aryaka.com/wp-content/uploads/2026/07/MyAryaka-Real-Time-Portal-Dashboard.webp) Flexible Delivery Cloud-based, AI-assisted services delivery | Consumed as a service **Implementation Choice** - **Self-managed** Configure, provision, monitor, and manage network and security policies via Aryaka’s single web-based portal. - **Co-managed** Hand over some aspects to Aryaka or an Aryaka partner and keep others to yourself per your preference. - **Aryaka-managed** Leverage Aryaka and we take care as a single point of contact managed services provider. **Delivery Choice** - **Deploy Aryaka Services** Leverage Aryaka technology and product features for network, security, and observability requirements. - **Deploy a mix of Aryaka and 3rd party Services** We meet you where you are for your deployment needs to maximize your existing security footprint investment and experience until you’re ready to migrate to Aryaka. [Learn More](https://www.aryaka.com/solutions/managed-unified-sase/) --- --- title: "pop map" url: "https://www.aryaka.com/about-us/global-pop-locations/" markdown_url: "https://www.aryaka.com/about-us/global-pop-locations.md" llm_canonical: "https://www.aryaka.com/about-us/global-pop-locations.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "pop map" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/about-us/global-pop-locations/." last_updated: "2026-08-05T06:28:41-07:00" ---

pop map

Aryaka Global
Points-of-Presence (PoPs)

Aryaka’s global private network provides the world’s business users with fast and reliable cloud and SaaS access from any location in the world. Our worldwide Points-of-Presence (PoPs) are located on all six habitable continents, and have been strategically located to place end-users with optional optimal access to Cloud, SaaS applications and data centers. [Aryaka Network Architecture Whitepaper](https://www.aryaka.com/whitepaper/network-architecture/) ![Aryaka Global PoPs](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/pop-map-aryaka.svg)

Americas

- Ashburn, VA, USA - Atlanta, GA , USA - Chicago, IL, USA - Dallas, TX, USA - Denver, CO, USA - Los Angeles, CA, USA - Miami, FL, USA - Newark, NJ, USA - San Jose, CA, USA - Seattle, WA, USA - Toronto, ON, CA - Sao Paulo, Brazil - Santiago de Chile

EMEA

- London, England - Frankfurt, Germany - Tel Aviv, Israel - Amsterdam, Netherlands - Johannesburg, South Africa - Dubai, United Arab Emirates - Dublin, Ireland - Paris, France - Madrid, Spain - Stockholm, Sweden

APAC

- Sydney, Australia - Melbourne, Australia - Beijing, China - Hong Kong, China - Shanghai, China - Shenzhen, China - Bangalore, India - Chennai, India - Delhi, India - Mumbai, India - Tokyo, Japan - Singapore, Singapore - Seoul, South Korea - Taipei, Taiwan - Ho Chi Minh City, Vietnam  

Aryaka Network Architecture

The insight into Aryaka’s Zero Trust WAN infrastructure and how it uniquely supports sophisticated network and security capabilities at the cloud-edge as part of a Unified SASE architecture. [Download Whitepaper](https://www.aryaka.com/whitepaper/network-architecture/) [![Aryaka Network Architecture](https://www.aryaka.com/wp-content/uploads/2024/12/whitepaper-Book-Mockup.png)](https://www.aryaka.com/whitepaper/network-architecture/) --- --- title: "Unlock New Insights:
Networking & Security Priorities
for Manufacturing IT Leaders" url: "https://www.aryaka.com/events-webinars/unlock-new-insights-networking-security-priorities-for-manufacturing-it-leaders/" markdown_url: "https://www.aryaka.com/events-webinars/unlock-new-insights-networking-security-priorities-for-manufacturing-it-leaders.md" llm_canonical: "https://www.aryaka.com/events-webinars/unlock-new-insights-networking-security-priorities-for-manufacturing-it-leaders.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Unlock New Insights:
Networking & Security Priorities
for Manufacturing IT Leaders" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/events-webinars/unlock-new-insights-networking-security-priorities-for-manufacturing-it-leaders/." last_updated: "2026-08-03T00:41:37-07:00" ---

Unlock New Insights: <br>Networking &#038; Security Priorities <br>for Manufacturing IT Leaders

--- --- title: "Aryaka SmartManage
Site Licenses, Management and Orchestration" url: "https://www.aryaka.com/datasheet/smartmanage-datasheet/" markdown_url: "https://www.aryaka.com/datasheet/smartmanage-datasheet.md" llm_canonical: "https://www.aryaka.com/datasheet/smartmanage-datasheet.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Aryaka SmartManage
Site Licenses, Management and Orchestration" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/datasheet/smartmanage-datasheet/." last_updated: "2026-08-03T00:31:58-07:00" ---

Aryaka SmartManage <br> <span>Site Licenses, Management and Orchestration</span>

Aryaka’s SmartManage is a key element of our SD-WAN and Unified SASE services

SmartManage is a key component of the Aryaka services suite, offering essential features for Aryaka’s SD-WAN and Unified SASE as a Service. It is designed to deliver a network service experience that aligns with modern application and cloud services, with a global, cloud-based delivery of our infrastructure that ensures rapid worldwide connectivity and security services guaranteeing reliable performance and better user experience.

Aryaka’s SmartManage delivers the foundational capabilities of our
network and security services.

It includes automation and orchestration via our global network operating center (NOC) enabling always-on monitoring and predictive analytics including ongoing capacity planning to ensure superior performance and consistent service delivery. ![network security service](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/network-security-service.svg) ![Enhanced Security](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/global-service.svg) **Global Service Delivery:** Provides an on-demand SD-WAN and Unified SASE service with flexible management options. The service includes global and regional connectivity, linking headquarters, branches, remote locations, data centers and cloud service providers via the Aryaka Unified SASE platform.. ![Optimized Performance](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/automation-orchestration.svg) **Automation and Orchestration:** Utilizes the Aryaka Network Management and Control (ANMC) system for scalable, multi-tenant automation and orchestration, enabling efficient provisioning, configuration, and scaling of thousands of sites worldwide, ensuring seamless end-to-end serviceability. ![Enhanced User Experience](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/predictive.svg) **Predictive Analytics:** Aryaka’s EagleEye tool employs advanced big data and machine learning algorithms for predictive analytics to optimize capacity planning and preemptively identify potential issues to prevent performance impacts. ![noc](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/noc.svg) **Network Operating Centers (NOCs):** Operates 24x7x365 to maintain industry-leading SLAs for uptime, latency, jitter and packet loss globally.   Global SLAs: Uptime of 99.999% on Day 1 Aryaka’s industry leading SLAs are enforced on Day 1, without any need for initial stabilization. Enterprises can rest assured their business-critical applications will always perform optimally. Predictive Analytics The Aryaka management platform leverages big data and machine learning algorithms in order to optimize ongoing capacity planning on a global level. Predictive analytics helps identify and mitigate issues to prevent user experience issues at scale. Aryaka Network Access Point (ANAP) The Aryaka edge appliances are included in the service subscription. The ANAP is a secure converged edge appliance that integrates hardware innovations, routing, WAN optimization, and several security features. It runs the same software stack as the Aryaka POPs and is an integral component of the Aryaka OnePASS architecture. Elastic Subscriptions Aryaka elastic subscriptions support modern, digital enterprise needs with flexible service options for peak bandwidth demands, temporary sites, and rapid deployment capabilities. It delivers on the promise of a dynamic, flexible and agile network and security as-a-service delivery model. The foundational capabilities of SmartManage are always included as integral capabilities of any Aryaka services delivery.

Aryaka SmartManage Benefits

![flexibility elasticity](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/flexibility-elasticity.svg) **Flexibility and Elasticity** SmartManage delivers on the benefits of as-a- Service deployment to networking, allowing for on-demand self-service and elastic allocation of pooled resources. ![high availability](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/high-availability.svg) **High Availability with 99.999% uptime** Aryaka SmartManage combines complete visibility and predictive analytics to provide an always-on enterprise network with deterministic performance guarantees. ![management insights](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/management-insights.svg) **Management and Insights** With SmartManage, you get the benefits of Aryaka’s managed automation and orchestration capabilities backed by 24X7 support. ![intent based](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/intent-based.svg) **Software-defined Networking** Aryaka supports Software-defined deployment: all you have to do is declare your branch locations, your application priorities, your security posture, your cloud-based XaaS and redundancy needs. Aryaka ANMC will orchestrate the implementation. ![operational simplicity smartmanage](https://www.aryaka.com/wp-content/themes/aryaka-2019/img/operational-simplicity-smartmanage.svg) **Operational Simplicity** Focus on your business transformation initiatives as Aryaka takes away the overhead of building, managing and trouble-shooting your wide-area network and network security.

About Aryaka

Aryaka is the leader in delivering Unified SASE as a Service, a fully integrated solution combining networking, security, and observability. Built for the demands of Generative AI as well as today’s multi-cloud hybrid world, Aryaka enables enterprises to transform their secure networking to deliver uncompromised performance, agility, simplicity, and security. Aryaka’s flexible delivery options empower businesses to choose their preferred approach for implementation and management. Hundreds of global enterprises, including several in the Fortune 100, depend on Aryaka for their secure networking solutions. For more on Aryaka, please visit [www.aryaka.com](https://www.aryaka.com/). [Download Datasheet](https://www.aryaka.com/docs/smartmanage-datasheet.pdf) --- --- title: "Secure Access Service Edge (SASE) Ecosystem Growth: What to Expect in 2024" url: "https://www.aryaka.com/reports-and-guides/sase-market-growth-trends-predictions-2024/" markdown_url: "https://www.aryaka.com/reports-and-guides/sase-market-growth-trends-predictions-2024.md" llm_canonical: "https://www.aryaka.com/reports-and-guides/sase-market-growth-trends-predictions-2024.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Secure Access Service Edge (SASE) Ecosystem Growth: What to Expect in 2024" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/reports-and-guides/sase-market-growth-trends-predictions-2024/." last_updated: "2026-07-29T07:23:19-07:00" ---

Secure Access Service Edge (SASE) Ecosystem Growth: What to Expect in 2024

![Futuriom Logo](https://www.aryaka.com/wp-content/uploads/2024/09/futuriom-logo-black.png)

Secure Access Service Edge (SASE) Ecosystem Growth: What to Expect in 2024

The secure access service edge (SASE) market represents the next generation of network security, combining the features of network-based security and application awareness with cloud-based management of services. This report is intended to give you a background on what has happened in the SASE market over the past year, along with information on the trends set to carry it into 2024.

Highlights covered in the report include:

- The secure access service edge (SASE) market is in the early innings of a long-term shift helping cybersecurity pros consolidate distributed cloud security. - Technologies for SASE, zero trust, and multi-cloud networking are converging and driving cost optimization. - Remote access and work-from-home (WFH) will remain a strong undercurrent of the SASE market, driving cloud-based and network-based security. Download a copy of the report to learn about the complete findings from hundreds of surveyed enterprise decision-makers and key vendor profiles. In addition, learn how Aryaka’s Unified SASE, based on a single-pass architecture combined with a global POP-based meshed network, offers a unique approach optimized for hybrid deployments in today’s crowded SASE market landscape. --- --- title: "Unlock the Future of AI with Next-Gen Networking Infrastructure" url: "https://www.aryaka.com/reports-and-guides/unlock-the-future-of-ai-with-next-gen-networking-infrastructure/" markdown_url: "https://www.aryaka.com/reports-and-guides/unlock-the-future-of-ai-with-next-gen-networking-infrastructure.md" llm_canonical: "https://www.aryaka.com/reports-and-guides/unlock-the-future-of-ai-with-next-gen-networking-infrastructure.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Unlock the Future of AI with Next-Gen Networking Infrastructure" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/reports-and-guides/unlock-the-future-of-ai-with-next-gen-networking-infrastructure/." last_updated: "2026-07-29T07:20:30-07:00" ---

Unlock the Future of AI with Next-Gen Networking Infrastructure

Unlock the Future of AI with Next-Gen Networking Infrastructure

Discover how cutting-edge networking technologies are reshaping AI deployments from data centers to the edge. The explosive growth of Artificial Intelligence (AI) is revolutionizing network infrastructure requirements. Aryaka, in partnership with Futuriom, presents “What’s Next for Networking Infrastructure for AI | 2025,” offering deep insights into how Ethernet, optical networking, and edge solutions are redefining scalability and performance. From LLM training to real-time inferencing, enterprises are rethinking their networking strategies to meet the demands of high-speed data processing and distributed AI workloads. This report uncovers the critical advancements driving AI networking and how organizations are optimizing their infrastructure to keep pace.

Key Highlights:

- Ethernet is outpacing InfiniBand as the preferred fabric for scalable AI workloads. - SD-WAN, SASE, and NaaS are evolving to support secure, distributed AI inferencing. - Optical networking is emerging as a game-changer for high-speed, power-efficient data transfer. - SmartNICs and DPUs are becoming essential for optimizing AI-driven traffic across global networks.

800-Gb/s Ethernet Adoption

Emerging as the standard for AI datacenters.

Up to 30% Better Performance

DriveNets claims Ethernet-based AI fabrics outperform InfiniBand by 30%.

Ultra Ethernet Consortium (UEC)

Leading the charge for open standards in high-performance AI networking.

60% of Enterprises

Expected to deploy edge-based AI inferencing by 2026.

Why Aryaka?

Aryaka’s Unified SASE as a Service delivers high-performance, secure networking optimized for AI workloads. With low-latency global connectivity and seamless multi-cloud integration, Aryaka sets the standard for scalable AI infrastructure. --- --- title: "IDC Spotlight paper" url: "https://www.aryaka.com/resources/unified-networking-security-platform/" markdown_url: "https://www.aryaka.com/resources/unified-networking-security-platform.md" llm_canonical: "https://www.aryaka.com/resources/unified-networking-security-platform.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "IDC Spotlight paper" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/resources/unified-networking-security-platform/." last_updated: "2026-07-29T07:19:06-07:00" ---

IDC Spotlight paper

IDC Spotlight Paper

Unified Networking and Security Platform Accelerates Network Transformation

The roles of networking and security have become elevated with enterprises’ journey toward digital transformation (DX). They are regarded as key enablers of DX and are mandatory for the successful digitization of an enterprise’s customer-facing and internal processes. The decision process related to the implementation of networking and security capabilities has generally been complex and often resulted in suboptimal deployments. This IDC Spotlight paper suggests that a unified SASE platform delivered as a service — or unified SASE as a service — is the right answer by removing inherent friction in the decision-making process, optimizing the commercial framework, and providing a holistic approach to networking and security that derisks the implementation and operational journeys for enterprises. Read the paper to understand the case for network transformation, market trends and considerations when embarking on a secure networking journey. --- --- title: "The Futuriom 50" url: "https://www.aryaka.com/resources/the-futuriom-50/" markdown_url: "https://www.aryaka.com/resources/the-futuriom-50.md" llm_canonical: "https://www.aryaka.com/resources/the-futuriom-50.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "The Futuriom 50" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/resources/the-futuriom-50/." last_updated: "2026-07-29T07:17:45-07:00" ---

The Futuriom 50

The Futuriom 50

Top Cloud Trends & Private Companies in Cloud and Communications Infrastructure 2023

About This Report

Every year, Futuriom names the strongest private companies in key markets for cloud and communications infrastructure. This report highlights these companies as well as some of the strongest themes and trends they see driving these companies.

The Futuriom 50 dives into the impact of the pandemic, changes in the IPO market, and looks at five key cloud infrastructure trends –

- Hybrid and Multicloud Management - Cloud and Cost Management - Data Management and Pipelines - Edge/cloud Convergence - Unified Cloud Security --- --- title: "Secure Networking for a Hybrid Workforce" url: "https://www.aryaka.com/ebooks/unified-sase-as-a-service-hybrid-workforce/" markdown_url: "https://www.aryaka.com/ebooks/unified-sase-as-a-service-hybrid-workforce.md" llm_canonical: "https://www.aryaka.com/ebooks/unified-sase-as-a-service-hybrid-workforce.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "Secure Networking for a Hybrid Workforce" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/ebooks/unified-sase-as-a-service-hybrid-workforce/." last_updated: "2026-07-29T07:15:55-07:00" ---

Secure Networking for a Hybrid Workforce

Secure Networking for a
Hybrid Workforce

The Journey to Unified SASE as a Service

In today’s rapidly evolving business landscape, the hybrid workforce is no longer a trend but a reality. As organizations embrace the flexibility of remote and on-site work, ensuring secure and seamless network access for all employees has become paramount. This SC Media’s eBook, sponsored by Aryaka, dives into unlocking the future of secure networking. **What You’ll Discover Inside** - The shift from on-premises applications to cloud-based applications and computing platforms and what it means to the enterprise - The five key networking and security trends - The case for Unified SASE as a Service Ready to transform your network security and empower your hybrid workforce? Download “Secure Networking for a Hybrid Workforce: The Journey to Unified SASE as a Service” now and take the first step towards a more secure, efficient, and unified work environment. --- --- title: "SD-WAN and SASE Managed Services Survey Report 2023" url: "https://www.aryaka.com/futuriom-sd-wan-sase-survey-report-2023/" markdown_url: "https://www.aryaka.com/futuriom-sd-wan-sase-survey-report-2023.md" llm_canonical: "https://www.aryaka.com/futuriom-sd-wan-sase-survey-report-2023.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "SD-WAN and SASE Managed Services Survey Report 2023" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/futuriom-sd-wan-sase-survey-report-2023/." last_updated: "2026-07-29T07:11:22-07:00" ---

SD-WAN and SASE Managed Services Survey Report 2023

![Futuriom Logo](https://www.aryaka.com/wp-content/uploads/2024/09/futuriom-logo-black.png)

2023 SD-WAN and SASE Managed Services Survey

*A Futuriom Research Report* Futuriom, a leading research and analyst firm, conducted a survey of 196 enterprise networking and security professionals and found that SD-WAN and SASE managed services is helping them combat network and security challenges. Some of the challenges respondents claimed to be facing are hybrid work patterns and distributed applications, multi-cloud connectivity, and the need for zero-trust network access (ZTNA).

Read this report to learn:

- The trends of SD-WAN and SASE in addressing network challenges. - In what way SD-WAN/SASE is part of the NaaS (Network as a Service) movement. - A list of the SD-WAN and SASE services vendors. - Why Aryaka. --- --- title: "PIPL Supplement to Aryaka Data Protection Addendum" url: "https://www.aryaka.com/data-protection-addendum/pipl-supplement/" markdown_url: "https://www.aryaka.com/data-protection-addendum/pipl-supplement.md" llm_canonical: "https://www.aryaka.com/data-protection-addendum/pipl-supplement.md" canonical_for_llm: true entity_type: "WebPage" primary_entity: "PIPL Supplement to Aryaka Data Protection Addendum" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/data-protection-addendum/pipl-supplement/." last_updated: "2026-07-26T21:18:57-07:00" ---

PIPL Supplement to Aryaka Data Protection Addendum

**1. SCOPE AND APPLICATION** This PIPL Supplement to Aryaka Data Protection Addendum (“Supplement”) applies to the processing of Personal Information of individuals located in mainland China (“China Personal Information”) in connection with Aryaka’s Services. This Supplement addresses the PIPL-specific obligations and should be read in conjunction with the DPA that reflects the international data protection principles consistent with the PIPL framework for complete information regarding Aryaka’s data processing practices. This Supplement supplements and forms part of the Data Protection Addendum (“DPA”). In the event of any conflict between this Supplement and the DPA with respect to China Personal Information, this Supplement prevails. Capitalized terms not defined herein have the meanings given in the DPA. **2. DEFINITIONS** For purposes of this Supplement, the following terms have the meanings set forth below: (a) “China Personal Information” means any information relating to an identified or identifiable natural person located in mainland China, excluding anonymized information, as defined under Article 4 of PIPL. (b) “PIPL” means the Personal Information Protection Law of the People’s Republic of China (effective November 1, 2021), as amended from time to time. (c) “PRC” means the People’s Republic of China. (d) “Sensitive Personal Information” has the meaning given under Article 28 of PIPL. (e) “Entrusted Party” means an entity that processes Personal Information on behalf of and as directed by a Personal Information Processor, as contemplated under Article 21 of PIPL. (f) “Personal Information Processor” means an organization or individual that autonomously determines the purposes and means of Personal Information processing, as defined under Article 73 of PIPL. **3. ROLE AND PROCESSING PURPOSE** 3.1 When Aryaka processes China Personal Information in connection with the provision of services to its customers, Aryaka acts as an Entrusted Party (as defined in Section 2) on behalf of the customer, who is the Personal Information Processor. Aryaka processes China Personal Information solely for the purpose of providing, monitoring, and supporting the contracted services, and as directed by the Customer in accordance with the Agreement and in accordance with documented instruction under the DPA. Aryaka will not process China Personal Information beyond the purposes, methods, or scope agreed upon in the Agreement and the DPA. 3.2 The Customer, as Personal Information Processor, shall ensure that a valid legal basis is established for the processing of China Personal Information, including obtaining of any consent required under PIPL. Where PIPL requires separate consent for specific processing activities (such as cross-border transfers or the processing of Sensitive Personal Information), such consent shall be obtained by the Customer prior to providing the relevant China Personal Information to Aryaka. **4. CRITICAL INFORMATION INFRASTRUCTURE** Aryaka provides global network and security services that enable enterprise connectivity across regions, including mainland China. Under the PRC Cybersecurity Law, Critical Information Infrastructure Operator (“CIIO”) status applies to operators in specifically designated sectors. Aryaka’s Services fall outside of the specified designated sectors and Aryaka does not process Sensitive Personal Information as defined under PIPL. Accordingly, Aryaka is not subject to the CIIO-specific data localization requirements under PIPL or Cybersecurity Law of the PRC. **5. CROSS-BORDER TRANSFERS** 5.1 In the course of providing its Services, Aryaka may process China Personal Information that is transferred outside mainland China for purposes of service delivery, monitoring, and support. 5.2 As of the effective date of this Supplement, the volume of China Personal Information processed by Aryaka in connection with its Services does not meet the thresholds requiring a formal cross-border data transfer mechanism under the Provisions on Promoting and Regulating Cross-Border Data Flows (effective March 22, 2024). Therefore, Aryaka’s current processing activities, as stipulated under the DPA, meet the requirements of streamlined cross-border transfer permitted under PRC law. 5.3 Aryaka will monitor applicable data volumes on an ongoing basis and will use commercially reasonable efforts to implement a formal cross-border data transfer mechanism as required under applicable PRC law if and when the relevant thresholds are met. **6. PERSONAL INFORMATION PROTECTION IMPACT ASSESSMENT** Upon Customer’s reasonable request, Aryaka will provide information reasonably necessary to support the Customer’s obligation to conduct a Personal Information Protection Impact Assessment under Article 55 of PIPL in connection with the entrusted processing of China Personal Information. [Download PDF](https://www.aryaka.com/docs/data-protection-addendum/pipl-supplement.pdf) --- --- title: "Secure SD-WAN and Unified SASE: What AI-Driven Enterprises Need to Know Before Leaving MPLS" url: "https://www.aryaka.com/blog/secure-sd-wan-unified-sase-ai-enterprises-leaving-mpls/" markdown_url: "https://www.aryaka.com/blog/secure-sd-wan-unified-sase-ai-enterprises-leaving-mpls.md" llm_canonical: "https://www.aryaka.com/blog/secure-sd-wan-unified-sase-ai-enterprises-leaving-mpls.md" canonical_for_llm: true entity_type: "Article" primary_entity: "Secure SD-WAN and Unified SASE: What AI-Driven Enterprises Need to Know Before Leaving MPLS" citation_value: "Published on Aryaka; canonical URL https://www.aryaka.com/blog/secure-sd-wan-unified-sase-ai-enterprises-leaving-mpls/." last_updated: "2026-07-23T04:19:10-07:00" ---

Secure SD-WAN and Unified SASE: What AI-Driven Enterprises Need to Know Before Leaving MPLS

![Secure SD-WAN and Unified SASE](https://www.aryaka.com/wp-content/uploads/2026/07/Blog_secure-sdwan-unified-Banner-1.webp) Every enterprise network built in the last two decades was designed around the same assumption: traffic is predictable, applications live in a data center, and humans generate the load. AI just broke that assumption. Copilot, ChatGPT Enterprise, agentic workflows, and retrieval-augmented generation don’t behave like the traffic MPLS or first-generation SD-WAN were built for. They’re bursty, latency-intolerant, and constant instead of business-hours. When the network can’t keep up, the AI initiative gets blamed for a problem the WAN actually caused. This is why the conversation in IT has shifted in the past year. It’s no longer “should we replace MPLS with SD-WAN.” It’s “does our SD-WAN have the security and performance architecture to carry AI traffic, or do we need Unified SASE to get there.” Those are different questions with different answers, and most vendors blur the line between them on purpose. This guide draws it clearly.

What Is Secure SD-WAN?

Secure SD-WAN is software-defined WAN technology with security built into the architecture rather than bolted on afterward. It replaces static MPLS routing and disconnected branch firewalls with application-aware traffic steering, integrated threat protection, and consistent policy enforcement across every location, without a separate stack of security appliances to manage. The distinction matters because “SD-WAN” alone only promises connectivity. Basic SD-WAN picks the best path across broadband, LTE, or MPLS links and stops there. Whether that traffic is inspected, encrypted, and governed by a consistent policy is a separate project, usually a separate vendor, and usually a separate budget line. Secure SD-WAN closes that gap at the architecture level instead of the integration level. [Aryaka Secure SD-WAN](https://www.aryaka.com/datasheet/secure-sdwan-solution/) extends this further with a global Zero Trust WAN and OnePASS single-pass architecture running over a private core network of 40+ Points of Presence across six continents, delivered as a managed service with service-level guarantees.

Secure SD-WAN vs. Traditional SD-WAN: What’s the Difference?

| | Traditional SD-WAN | Secure SD-WAN | | --- | --- | --- | | **Path selection** | Best available link across broadband, MPLS, LTE/5G | Same, plus application- and AI-workload-aware steering | | **Security** | Bolted on via third-party firewalls, VPNs, or SASE overlay | Built into the architecture from day one | | **Policy enforcement** | Inconsistent across branches, remote users, cloud | Centralized and consistent everywhere | | **Operational model** | Multiple consoles, multiple vendors | Single managed platform | | **AI/cloud readiness** | Not designed for AI traffic patterns | Purpose-built for latency-sensitive, bursty workloads | Traditional SD-WAN was a genuine improvement over MPLS: lower cost, more flexible, easier to deploy. But it made networking and security two separate purchasing decisions, and that gap is exactly where AI workloads expose weakness, because inconsistent security policy and inconsistent performance are both unacceptable once AI is handling real business processes.

Why AI Workloads Break Networks That Weren’t Built for Them

Generative AI and agentic applications generate traffic that looks nothing like the SaaS and video traffic most WANs were tuned for: large asymmetric bursts from distributed data sources, sustained low-latency demands from RAG pipelines pulling live context, and GPU-as-a-Service (GPUaaS) sessions that punish jitter and packet loss immediately instead of degrading gracefully. **55% of enterprises** report active SASE deployments underway in 2026 (AvidThink, 2026 Connectivity Report). That’s no longer a trend, it’s the baseline IT leaders are being measured against. Organizations still running static MPLS routing policies or disconnected SD-WAN and security stacks aren’t just behind on cost efficiency. They’re building AI initiatives on a foundation that can’t guarantee the performance those initiatives depend on. Modernizing the WAN isn’t a connectivity refresh anymore. It’s infrastructure work that determines whether AI adoption succeeds or stalls.

What Is Unified SASE, and How Is It Different from Secure SD-WAN?

Unified SASE (Secure Access Service Edge) combines Secure SD-WAN with a full stack of cloud-delivered security services, including Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Firewall-as-a-Service (FWaaS), Cloud Access Security Broker (CASB), and Data Loss Prevention (DLP), enforced through a single identity-based policy engine. Where Secure SD-WAN secures the network path, Unified SASE secures the user, the application, and the data, regardless of where any of them sit. Secure SD-WAN is the performance and connectivity foundation. Unified SASE is what you get when that foundation is fused with the full security service edge, delivered as one platform instead of a stitched-together stack from multiple vendors.

Secure SD-WAN vs. Unified SASE: Which One Do You Need?

| Your situation | Likely fit | | --- | --- | | Modernizing WAN performance, security already handled separately | Secure SD-WAN | | Consolidating networking and security vendors | Unified SASE | | Distributed workforce needs identity-based access, not just network access | Unified SASE | | Early in MPLS retirement, want a non-disruptive first step | Secure SD-WAN, extendable later | | AI/cloud workloads across regions with compliance requirements | Unified SASE | The good news for IT leaders under budget and timeline pressure: this isn’t a rip-and-replace decision. Secure SD-WAN can be deployed first and extended into Unified SASE without a second migration, because the underlying architecture and policy engine are the same platform, not two products stitched together later. **What to Require Before You Modernize for AI** Not every SD-WAN or SASE platform was built the same way, and the difference shows up under AI load. Before you commit, require vendors to answer these five questions with specifics, not marketing language. 1 **Is the backbone private or public internet?** AI workloads need deterministic latency. Public internet transport can’t guarantee it at global scale. --- 2 **How is AI-workload traffic identified and prioritized?** Generic QoS policies weren’t built for RAG pipelines or GPUaaS sessions. --- 3 **Is security inline or a separate inspection hop?** Every added hop is added latency on every AI query. --- 4 **Is there one pane of glass for network and security visibility, or two?** Fragmented monitoring slows down root-cause analysis when something breaks. --- 5 **Is this a managed service, or another platform your team has to operate?** The network engineering talent shortage means “another dashboard” is a real cost, not a minor one.

Where Aryaka Fits

Aryaka’s Unified SASE as a Service is built on a private global backbone across 40+ PoPs, with OnePASS single-pass architecture converging networking and security instead of chaining them together, and AI>Perform, AI>Observe, and AI>Secure capabilities purpose-built for AI-era traffic. Manufacturing, logistics, and global enterprise customers including NVIDIA, Cathay Pacific, and Makino have used this architecture to cut file sync times from hours to minutes and deploy new sites in days instead of the weeks MPLS circuits typically require. 4.6/5 G2, 75+ verified reviews 4.7/5 Gartner Peer Insights, 205 reviews 113% ROI, Forrester TEI study <6 mo Payback period

Frequently Asked Questions

1 What is Secure SD-WAN? ** Secure SD-WAN combines software-defined WAN connectivity with integrated security, replacing MPLS circuits and disconnected branch firewalls with application-aware routing and consistent policy enforcement everywhere users and applications connect. 2 What’s the difference between SD-WAN and Secure SD-WAN? ** Traditional SD-WAN optimizes path selection across broadband, internet, and MPLS links but leaves security as a separate project. Secure SD-WAN builds security into the same architecture, so policy is consistent by design instead of by integration. 3 Is Unified SASE the same thing as SASE? ** Unified SASE describes a converged, single-vendor delivery of SASE, where SD-WAN and the full security stack (ZTNA, SWG, FWaaS, CASB, DLP) run on one platform with one policy engine. SASE more broadly can also describe a stitched-together combination of multiple point products from different vendors. 4 How does Secure SD-WAN support AI workloads? ** AI workloads like generative AI, RAG, and GPUaaS are highly sensitive to latency, jitter, and packet loss. Secure SD-WAN built on a private core network with SLA-backed performance and application-aware QoS prioritizes AI traffic over less critical workloads, keeping AI applications responsive even under network congestion. 5 Do we have to replace MPLS all at once? ** No. Most organizations run Secure SD-WAN alongside remaining MPLS circuits during a phased retirement, then extend into Unified SASE as security requirements grow, without a disruptive second migration. 6 What happens if we integrate SD-WAN and security ourselves instead of buying Unified SASE? ** Common issues include integration complexity across multiple consoles and APIs, inconsistent policy across locations, fragmented visibility that slows incident response, and added latency from routing traffic through separate inspection points, all of which compound as AI and cloud traffic grows. **If you’re evaluating whether your current architecture can carry AI workloads at scale, there are two ways to move forward from here.** **Recommended next step** **Book an AI Network Readiness Session** A working session to assess your current WAN against the five requirements above, with your traffic, your regions, your compliance needs. [Book the session](https://www.aryaka.com/book-a-strategy-session/) **Still in research mode** **Get the 2026 SASE Buyers Guide** What to evaluate, what to ask vendors, and how to navigate the decision. [Get the guide](https://www.aryaka.com/buyers-guide/unified-sase-buyers-guide-2026/) ---