NIS2 and IT-Grundschutz evidence from your own inventory

Know your IT assets without an enterprise-first rollout

Start with one approved scanner, build a reliable inventory, understand coverage, review evidence and findings, and create useful operational reports from one console.

Platform

See it, trust it, act on it.

AssetObserve is designed for growing IT and security teams that need a clear rollout, controlled discovery boundaries and evidence they can explain to colleagues and auditors.

01See assets

Network, directory, endpoint and snapshot evidence can resolve into one inventory.

02Know coverage

Coverage and agent health show what was expected, observed, stale or unreachable.

03Act on evidence

Findings and source provenance provide a focused work queue instead of raw scan output.

Persistent endpoint fleet

Endpoint mode records heartbeats, inventory deltas, queue state and the requested update version.

Credential boundary

Cloud stores credential profiles and audit metadata. Secrets stay local to the agent or operating system vault.

Authorized scope

Large scans require explicit confirmation and stay limited to internal, loopback or link-local networks.

Operational evidence

Discovery tasks, source observations, exports and administrative actions remain attributable.

Operating views

Move from discovery to day-to-day operations

The inventory is the evidence layer. AssetObserve adds the workflows teams need to keep sources, coverage, findings and reporting current.

01 / 06

Live posture dashboard

Assets, open critical findings, compliance readiness and network coverage on one operational home screen, updated from the latest evidence baseline.

Playing story
Home / Dashboard Search Nordwind GmbH
Assets1,284Documented
Open critical734 active findings
Compliance82%NIS2 readiness
Coverage91%3 sites / 12 segments
Risk snapshot34 active
Critical7
High11
Medium13
Low3
30 daysrisk score trending down
Needs attentionQueue
AssetActionPriority
WEB-PRD-02Patch OpenSSLP1
DC-BER-01Rotate certP2
FIN-WS-042Enable BitLockerassigned
Evidence-grounded AI

Evidence-grounded AI

Turn collected evidence into clear answers, business context and safe investigations. Every result stays tenant-scoped, cites its inputs and respects explicit AI controls.

Explore every AI capability
Capabilities

Controlled discovery, evidence and operations

Combine approved sources, keep identity and coverage visible, and operate large inventories from one console. Open any card to read what that source or workflow collects and what it is worth once it is connected.

Browse all capabilities
Connector foundationMicrosoft Azure

Subscription-scoped resource inventory through an approved cloud collector.

Connector foundationMicrosoft 365

Entra ID device inventory through an approved Microsoft Graph connection.

Connector foundationAWS

EC2 instance inventory through signed API requests.

Persistent agentEndpoint fleet

Optional local inventory, heartbeats, offline replay and HMAC-signed agent requests.

Read-onlyWindows

WinRM-based inventory, hardware, software and hotfix evidence.

Read-onlyLinux / macOS

SSH-based package, service, FileVault, firewall and system inventory.

Read-onlyVMware

Hypervisor and virtual machine inventory via an approved vSphere connection.

SNMPv3Network devices

Read approved switch, router, printer and device inventory without configuration changes.

HTTPS snapshotDHCP and DNS

Record authorized DHCP and DNS state through a read-only snapshot connector.

Read-onlyOT / Modbus

Read Device Identification probing for authorized industrial controllers.

Read-only LDAPSActive Directory

Directory inventory uses a read-only AD LDAPS connector and keeps source provenance.

ReconciliationAsset identity

Stable identifiers resolve source observations while uncertain matches remain reviewable.

MarketplaceConnector catalog

ITSM, risk, endpoint, RMM, firewall, SIEM, BI and collaboration connectors with release-state labels.

Evidence viewsCompliance readiness

NIS2, BSI, ISO 27001, GDPR, DORA, TISAX and other frameworks mapped to source facts.

Durable workDiscovery operations

Task leases, checkpoints and retry state make failed work visible and recoverable.

High volumeInventory at scale

Server-side search, saved views, cursor pagination and asynchronous CSV export.

Plans

Choose the AssetObserve plan that's right for you

Every plan keeps the same operational model: reusable agent tokens, scheduled scans, reports and an audit trail. Limits scale without changing the rollout.

free trial

Free Trial

Start with one scanner, PDF reports and limited asset discovery.

  • Asset inventory
  • Agent scans
  • AD-lite
  • PDF reports
  • 250 Assets
  • 1 Agent
  • 20 scans per trial
  • Reports kept for 30 days

Included once with a new workspace: 30 days, up to 20 scans, no card required. A paid plan is needed afterwards.

Start free trial
professional

Professional

Multi-site visibility, AD-lite collection and longer retention.

Planned capabilities · coming soon

  • Asset inventory
  • Agent scans
  • AD-lite
  • PDF reports
  • API access
  • 5000 Assets
  • 25 Agents
  • 500 scans / month
  • Reports kept for 365 days
Request access
Resources

Learn more about AssetObserve

Updates

AssetObserve Updates

A running log of what we've recently shipped -- the platform keeps moving.

Aug 2026

Durable discovery jobs and task tracking

Large discovery runs are now split into bounded tasks with checkpoints, retry state and progress events, so users can follow long scans instead of waiting on a single opaque run.

Aug 2026

Account security with MFA and recovery codes

Users can protect sign-in with TOTP-based multi-factor authentication and hashed one-time recovery codes, while secrets stay in the encrypted credential vault.

Aug 2026

Digital IT Asset Passports

Assets now get stable passport IDs, customer asset numbers, aliases, lifecycle events, document evidence and hashed snapshots for audit-ready asset history.

Aug 2026

Exploit-aware vulnerability prioritization

CVE matching now uses the NVD CPE dictionary plus CISA KEV and FIRST EPSS mirrors, making finding scores explainable by known exploitation and probability signals.

FAQ

Frequently asked questions

Quick answers for a first rollout. The full FAQ and Help center go deeper.

Browse all questions
01/What is AssetObserve for?

AssetObserve is an authorized IT asset discovery, risk and reporting platform. It builds a current inventory, highlights coverage gaps, turns evidence into findings, and produces management, technical and compliance reports from one workspace.

02/Is AssetObserve a hacking, brute-force or remediation tool?

No. Discovery is read-only and must be explicitly scoped. It does not exploit systems, guess or brute-force passwords, or silently change, disable or fix anything.

03/Do we install an agent on every computer?

No. One scanner collects authorized network evidence from a reachable position and can document Windows, Linux, macOS, printers, switches, hypervisors and more. Persistent endpoint mode is optional, mainly for roaming or rarely-connected devices.

04/Which discovery sources can we connect?

Depending on the approved configuration: network discovery, optional endpoint inventory, read-only AD LDAPS, SNMPv3, DHCP/DNS HTTPS snapshots, VMware, and cloud collectors for Azure, Microsoft 365/Entra ID, AWS, Google Cloud, OCI and Open Telekom Cloud.

05/How does vulnerability (CVE) matching work?

Installed-software evidence is matched against a locally-mirrored NVD corpus, enriched with CISA KEV (known-exploited) and FIRST.org EPSS (exploit probability). Matches are labeled "possible match, not confirmed" so they inform triage rather than overstate certainty.

06/Does the NIS2 report make us compliant?

It prepares you. The NIS2 readiness report and the guided compliance assessment map your evidence to frameworks like NIS2, ISO 27001 and GDPR and show a readiness score with the open questions that remain. It supports preparation and does not replace legal advice.

07/Do you store our admin passwords in the cloud?

No. The platform is built around a local credential boundary. Scan credentials stay in the customer-controlled agent or server vault and are never written to the database; only normalized evidence is uploaded to your workspace.

08/Can MSPs and partners manage multiple customers?

Yes. The partner center creates separated customer workspaces, keeps reports, tickets and billing per customer, and offers a portfolio risk board across tenants -- with customer authorization recorded per workspace.

09/How are duplicate assets handled?

Source observations stay separate from the resolved asset, and stable identifiers (serial number, SMBIOS UUID, managed-device ID, directory GUID, MAC address) are preferred. Ambiguous matches go to review instead of being silently merged.

10/Can a large inventory stay usable in the browser?

Yes. Server-side search, filters, cursor pagination, saved views and asynchronous CSV exports mean you never load every asset into one page at once.

Take the next step

Explore a live demo workspace

Walk a fully-populated dashboard -- assets, topology, findings, compliance and reports -- with no signup and nothing to install.

Explore the live demo

Start building on AssetObserve free

Create a workspace, enroll a scanner and run your first discovery scan today.

Try AssetObserve for free

Talk to our team

Ask about rollout, MSP usage or a customer-specific security requirement.

Request access