Network, directory, endpoint and snapshot evidence can resolve into one inventory.
Know your IT assets without an enterprise-first rollout
Start with one approved scanner, build a reliable inventory, understand coverage, review evidence and findings, and create useful operational reports from one console.
See it, trust it, act on it.
AssetObserve is designed for growing IT and security teams that need a clear rollout, controlled discovery boundaries and evidence they can explain to colleagues and auditors.
Coverage and agent health show what was expected, observed, stale or unreachable.
Findings and source provenance provide a focused work queue instead of raw scan output.
Endpoint mode records heartbeats, inventory deltas, queue state and the requested update version.
Cloud stores credential profiles and audit metadata. Secrets stay local to the agent or operating system vault.
Large scans require explicit confirmation and stay limited to internal, loopback or link-local networks.
Discovery tasks, source observations, exports and administrative actions remain attributable.
Choose the AssetObserve plan that's right for you
Every plan keeps the same operational model: reusable agent tokens, scheduled scans, reports and an audit trail. Limits scale without changing the rollout.
Free Trial
Start with one scanner, PDF reports and limited asset discovery.
- Asset inventory
- Agent scans
- AD-lite
- PDF reports
- Assets
- Agent
- 20 scans / month
- 30-day report retention
Starter
Small IT teams documenting a single site.
- Asset inventory
- Agent scans
- AD-lite
- PDF reports
- Assets
- Agent
- 100 scans / month
- 90-day report retention
Professional
Multi-site visibility, AD-lite collection and longer retention.
- Asset inventory
- Agent scans
- AD-lite
- PDF reports
- API access
- Assets
- Agent
- 500 scans / month
- 365-day report retention
Controlled discovery, evidence and operations
Combine approved sources, keep identity and coverage visible, and operate large inventories without pretending every connector or workflow is already fully commercialized. Open any card to read what that source or workflow is worth once it is connected.
Browse all capabilitiesSubscription-scoped resource inventory through an approved cloud collector.
Connector foundationMicrosoft 365Entra ID device inventory through an approved Microsoft Graph connection.
Connector foundationAWSEC2 instance inventory through signed API requests.
Connector foundationGoogle CloudCompute Engine inventory through a scoped service-account collector.
Connector foundationGoogle WorkspaceAdmin SDK application and OAuth visibility through delegated read-only access.
Connector foundationOracle Cloud InfrastructureOCI compute inventory through API signing credentials and tenancy-scoped reads.
Connector foundationOpen Telekom CloudOpen Telekom Cloud project inventory for ECS resources in approved regions.
FinOpsCloud cost importsAWS Cost Explorer, Azure Cost Management and Google Cloud Billing export imports feed cost views.
Provider riskCloud supplier registerAWS, Azure, GCP, Microsoft 365, OCI and OTC assets can inform DORA-oriented provider review.
Persistent agentEndpoint fleetOptional local inventory, heartbeats, offline replay and HMAC-signed agent requests.
Read-onlyWindowsWinRM-based inventory, hardware, software and hotfix evidence.
Read-onlyLinux / macOSSSH-based package, service, FileVault, firewall and system inventory.
Read-onlyVMwareHypervisor and virtual machine inventory via an approved vSphere connection.
Read-onlyKubernetesService-account inventory for nodes, namespaces, pods and container image metadata.
SoftwareSoftware inventoryInstalled software, packages, hotfixes, license signals and EOL matching feed governance views.
LifecycleHardware warrantyDell, HP and Lenovo warranty API lookups enrich assets with lifecycle and renewal dates.
PostureEndpoint securityBitLocker, FileVault, Defender, firewall, TPM and patch evidence feed risk and compliance checks.
DeliveryAgent release channelAgent versions, update requests, release manifests and signed installer delivery stay visible.
SNMPv3Network devicesRead approved switch, router, printer and device inventory without configuration changes.
HTTPS snapshotDHCP and DNSRecord authorized DHCP and DNS state through a read-only snapshot connector.
Read-onlyOT / ModbusRead Device Identification probing for authorized industrial controllers.
Scope controlAuthorized IP discoveryQuick, site and enterprise scan boundaries keep large discovery runs explicit and bounded.
TLSCertificate evidenceHTTPS certificate expiry, issuer, subject and self-signed signals feed renewal and risk workflows.
Port signaturesSAP and KMS signalsSAP HANA, SAP NetWeaver, SAProuter and Microsoft KMS ports are identified as review signals.
OT signaturesIndustrial protocolsModbus, S7, IEC 60870-5-104, OPC UA, DNP3 and EtherNet/IP signatures mark OT candidates.
Approved labPassive observationExplicitly gated ARP and mDNS metadata observation supports owned-lab discovery only.
Firewall importFirewall and controller inventoryFortinet, Palo Alto, Meraki, Firepower, Sophos, pfSense/OPNsense and UniFi device imports.
TopologyNetwork and service mapObserved links, cloud relationships, services and dependencies build topology views.
Read-only LDAPSActive DirectoryDirectory inventory uses a read-only AD LDAPS connector and keeps source provenance.
ReconciliationAsset identityStable identifiers resolve source observations while uncertain matches remain reviewable.
Entra IDMicrosoft Entra devicesMicrosoft 365 inventory links directory device state into asset and coverage evidence.
Access controlMFA readinessMFA declarations and identity evidence support insurance, NIS2, ISO and SOC 2 checks.
Enterprise identitySSO and SCIMEnterprise SSO, SCIM and identity lifecycle controls can be enabled for provisioned plans.
Tenant boundaryRBAC and isolationWorkspace roles, tenant scoping and admin actions keep customer data boundaries explicit.
Review queueIdentity reviewUncertain matches and ownership gaps remain reviewable instead of being merged silently.
AuditAdmin audit trailAdministrative and workspace actions remain attributable for operations and evidence review.
MarketplaceConnector catalogITSM, risk, endpoint, RMM, firewall, SIEM, BI and collaboration connectors with release-state labels.
Risk importTenable / Qualys / Rapid7Vulnerability platform imports enrich AssetObserve findings and asset context.
ASMrunZero / Armis / AxoniusAttack-surface and device-graph connectors reconcile external discovery with the inventory.
EDRCrowdStrike / SentinelOne / DefenderEndpoint protection coverage can be matched against known assets.
ITSMServiceNow / Jira / FreshserviceCMDB and ticket workflows connect findings and assets to service-management tools.
Service deskZendesk / FreshdeskOpen support or remediation tickets from prioritized work queues.
ITAMIntune / Jamf / Snipe-ITManaged-device and asset-management records can be reconciled with discovery evidence.
MonitoringDatadog / Zabbix / PRTGMonitoring and RMM sources help spot assets outside current coverage.
RMMNinjaOne / Datto RMM / AteraRMM device imports feed inventory and coverage comparison workflows.
FirewallFortinet / Palo Alto / MerakiFirewall and controller inventories add observed devices from network infrastructure.
SAMFlexera / Snow SoftwareSoftware asset management sources support license and entitlement review.
BI exportPower BI / CSV / ExcelScheduled and on-demand exports support external analysis and reporting.
SIEMSplunk / Sentinel / Syslog CEFFinding and evidence events can be forwarded to SIEM and log platforms.
CollaborationSlack / Teams / PagerDutyCritical findings and scan summaries can notify collaboration and incident channels.
APIPublic API and webhooksAPI access and signed outbound webhooks support automation around scans and findings.
Cloud financeAWS / Azure / GCP cost sourcesCloud billing connectors feed FinOps allocation and optimization workflows.
Extended ITSMHaloITSM / ManageEngineAdditional service-management connectors can open requests from AssetObserve actions.
AutomationAutomox / Cortex XSOARPatch-management and orchestration connectors support coverage and response workflows.
Evidence viewsCompliance readinessNIS2, BSI, ISO 27001, GDPR, DORA, TISAX and other frameworks mapped to source facts.
EUNIS2 Article 21(2)Risk-management measures are mapped to asset evidence, findings and declarations.
GermanyBSI IT-GrundschutzEvidence views, declaration readiness, Word drafts and audit working papers support preparation.
ISOISO/IEC 27001Annex A-aligned evidence covers inventory, access control, backup, crypto and vulnerability handling.
PrivacyGDPR Article 32Security, lifecycle, encryption, access and supplier evidence support technical measures review.
FinanceDORA supplier reviewProvider register, contracts and supplier assurance evidence support DORA-oriented reviews.
AutomotiveTISAX ISA readinessInformation-security, access, operations, continuity and supplier signals support assessment preparation.
Security baselineCIS Controls v8Inventory, secure configuration, access, vulnerability, logging, backup and incident controls.
FrameworkNIST CSF 2.0Govern, identify, protect, detect, respond and recover views reuse the same evidence layer.
AustraliaEssential EightPatch, MFA, admin restriction, application hardening and backup readiness mappings.
AssuranceSOC 2 readinessTrust Services Criteria preparation views for access, monitoring, change and availability evidence.
PaymentsPCI DSS preparationNetwork, endpoint, patching, access and logging evidence supports PCI-oriented preparation.
HealthcareHIPAA Security RuleRisk, access, awareness, backup, media and technical safeguard evidence views.
InsuranceCyber insuranceMFA, backup, patching, endpoint protection and incident-readiness evidence packs.
SustainabilityGreen IT lifecycleLifecycle, reuse, retirement, cloud waste and carbon signals support sustainable IT review.
ReportsAudit bundlesDocument evidence, compliance reports, BSI declaration packs and audit-room work items stay traceable.
Durable workDiscovery operationsTask leases, checkpoints and retry state make failed work visible and recoverable.
High volumeInventory at scaleServer-side search, saved views, cursor pagination and asynchronous CSV export.
CoverageFreshness and gapsTrack expected scope, observations, failures and blind spots instead of relying on a single percentage.
ReportingReports from evidenceManagement, technical, NIS2, BSI, cyber-insurance and custom reports use source facts.
RemediationAction workflowsAction boards, campaigns, owners, due dates and accepted-risk exceptions turn findings into work.
RenewalsRenewal operationsContracts, certificates, warranties, software licenses and supplier decisions share a review queue.
SAMSAM and SaaS governanceSoftware licenses, SaaS subscriptions, OAuth apps and governance alerts support spend and risk review.
FinOpsCost optimizationCloud costs, contracts and idle-resource findings support allocation and optimization decisions.
Customer healthWorkspace healthCoverage, plan limits, support view and customer health signals help operate multiple workspaces.
MSPPartner portfolioPartner views roll up customer posture, governance and operational follow-up.
AutomationNotifications and webhooksEmail alerts, security contacts and outbound webhooks keep events actionable outside the console.
LifecycleWorkspace export and deletionWorkspace data export and irreversible deletion workflows support access requests and lifecycle control.
Learn more about AssetObserve
Compare plans and limits
See asset, agent and scan limits across every published plan.
See plansRead the full FAQ
Get clear answers on rollout, sources, credentials, limits and scale.
Read the FAQFind the next step
Use practical setup, operations and troubleshooting guides when you need an answer quickly.
Open Help centerRequest a company trial
Share rollout scope, asset count and package needs before access is assigned.
Request accessStart free
Create a workspace and enroll your first scanner today.
Start free trialTake the next step
Explore a live demo workspace
Walk a fully-populated dashboard -- assets, topology, findings, compliance and reports -- with no signup and nothing to install.
Explore the live demoStart building on AssetObserve free
Create a workspace, enroll a scanner and run your first discovery scan today.
Try AssetObserve for freeTalk to our team
Ask about rollout, MSP usage or a customer-specific security requirement.
Request accessAssetObserve Updates
A running log of what we've recently shipped -- the platform keeps moving.
Help center and NIS2 readiness reporting
A searchable in-app help center, plus a dedicated NIS2 readiness report that maps discovered assets and findings to NIS2 obligations.
Track hardware the scanner can't reach
Add spare, decommissioned or offline IT assets by hand, via CSV bulk import, or by uploading a purchase invoice PDF for auto-filled fields.
OT/industrial device recognition (Modbus)
A read-only Modbus identification probe now flags industrial control devices and reports them as a dedicated finding, no coils or registers ever written.
AWS joins the cloud collector line-up
EC2 instance inventory via signed API requests rounds out coverage across Azure, Microsoft 365, GCP, OCI, OTC and now AWS.
Frequently asked questions
Quick answers for a first rollout. The full FAQ and Help center go deeper.
01/What is AssetObserve for?
AssetObserve is an authorized IT asset discovery, risk and reporting platform. It builds a current inventory, highlights coverage gaps, turns evidence into findings, and produces management, technical and compliance reports from one workspace.
02/Is AssetObserve a hacking, brute-force or remediation tool?
No. Discovery is read-only and must be explicitly scoped. It does not exploit systems, guess or brute-force passwords, or silently change, disable or fix anything.
03/Do we install an agent on every computer?
No. One scanner collects authorized network evidence from a reachable position and can document Windows, Linux, macOS, printers, switches, hypervisors and more. Persistent endpoint mode is optional, mainly for roaming or rarely-connected devices.
04/Which discovery sources can we connect?
Depending on the approved configuration: network discovery, optional endpoint inventory, read-only AD LDAPS, SNMPv3, DHCP/DNS HTTPS snapshots, VMware, and cloud collectors for Azure, Microsoft 365/Entra ID, AWS, Google Cloud, OCI and Open Telekom Cloud.
05/How does vulnerability (CVE) matching work?
Installed-software evidence is matched against a locally-mirrored NVD corpus, enriched with CISA KEV (known-exploited) and FIRST.org EPSS (exploit probability). Matches are labeled "possible match, not confirmed" so they inform triage rather than overstate certainty.
06/Does the NIS2 report make us compliant?
It prepares you. The NIS2 readiness report and the guided compliance assessment map your evidence to frameworks like NIS2, ISO 27001 and GDPR and show a readiness score with the open questions that remain. It supports preparation and does not replace legal advice.
07/Do you store our admin passwords in the cloud?
No. The platform is built around a local credential boundary. Scan credentials stay in the customer-controlled agent or server vault and are never written to the database; only normalized evidence is uploaded to your workspace.
08/Can MSPs and partners manage multiple customers?
Yes. The partner center creates separated customer workspaces, keeps reports, tickets and billing per customer, and offers a portfolio risk board across tenants -- with customer authorization recorded per workspace.
09/How are duplicate assets handled?
Source observations stay separate from the resolved asset, and stable identifiers (serial number, SMBIOS UUID, managed-device ID, directory GUID, MAC address) are preferred. Ambiguous matches go to review instead of being silently merged.
10/Can a large inventory stay usable in the browser?
Yes. Server-side search, filters, cursor pagination, saved views and asynchronous CSV exports mean you never load every asset into one page at once.