Answers

Frequently asked questions

01/

Starting safely

What the platform is for and how a first rollout stays controlled.

01/ What is AssetObserve for?

AssetObserve is an authorized IT asset discovery, risk and reporting platform. It builds a current inventory, highlights coverage gaps, turns evidence into findings, and produces management, technical and compliance reports from one workspace.

02/ Is AssetObserve a hacking, brute-force or remediation tool?

No. Discovery is read-only and must be explicitly scoped. It does not exploit systems, guess or brute-force passwords, or silently change, disable or fix anything.

03/ Can I scan any IP range from the internet?

No. Use only networks you own or are explicitly authorized to assess. Scanner placement, routing, firewall policy and discovery limits stay under the operator's control.

04/ What is the safest first rollout?

Start with an owned lab or a small approved internal segment. Enroll one scanner, confirm its heartbeat, run a limited discovery, review coverage and evidence, then expand deliberately.

02/

Discovery sources and coverage

How network, endpoint, directory, cloud and snapshot evidence enters the inventory.

01/ Do we install an agent on every computer?

No. One scanner collects authorized network evidence from a reachable position and can document Windows, Linux, macOS, printers, switches, hypervisors and more. Persistent endpoint mode is optional, mainly for roaming or rarely-connected devices.

02/ Which discovery sources can we connect?

Depending on the approved configuration: network discovery, optional endpoint inventory, read-only AD LDAPS, SNMPv3, DHCP/DNS HTTPS snapshots, VMware, and cloud collectors for Azure, Microsoft 365/Entra ID, AWS, Google Cloud, OCI and Open Telekom Cloud.

03/ Can one scanner see every VLAN and subnet?

Only where routing, firewall rules and permissions allow it. Coverage shows blind spots so the team knows where another scan point or import path is needed.

04/ What does coverage actually show?

Coverage records the expected scope, which source last observed it, freshness and visible gaps. It keeps reachable, unreachable, excluded, credential-failed and unknown outcomes explicit instead of letting a target quietly disappear.

03/

Findings, risk and compliance

How raw evidence becomes prioritized risk and compliance-ready reporting.

01/ How does AssetObserve turn evidence into findings?

A rule engine generates findings per asset from evidence against configurable thresholds, then weights them by business context. Findings store language-neutral keys, so the same finding renders in English, German or Turkish.

02/ How does vulnerability (CVE) matching work?

Installed-software evidence is matched against a locally-mirrored NVD corpus, enriched with CISA KEV (known-exploited) and FIRST.org EPSS (exploit probability). Matches are labeled "possible match, not confirmed" so they inform triage rather than overstate certainty.

03/ Does the NIS2 report make us compliant?

It prepares you. The NIS2 readiness report and the guided compliance assessment map your evidence to frameworks like NIS2, ISO 27001 and GDPR and show a readiness score with the open questions that remain. It supports preparation and does not replace legal advice.

04/ Can we accept or defer a risk?

Yes. An accepted-risk decision documents why a finding is not being fixed now, with a scope (this asset, site or workspace), a business reason and an optional expiry date, and it can be reopened later.

04/

Data, privacy and security

Where credentials and evidence live and how requests are protected.

01/ Do you store our admin passwords in the cloud?

No. The platform is built around a local credential boundary. Scan credentials stay in the customer-controlled agent or server vault and are never written to the database; only normalized evidence is uploaded to your workspace.

02/ What data is actually uploaded to the workspace?

Normalized inventory and evidence -- hostnames, IPs, open ports, software, hardware, coverage and findings -- not raw secrets. Credentials remain local, and passwords or tokens should never be placed in tickets, reports or source code.

03/ How are endpoint-agent requests protected?

Agent API requests carry token-derived HMAC signatures over the method, path, timestamp, nonce and body hash, which protects request integrity. Production installer code-signing is a separate release control.

04/ Where is our data hosted?

Your workspace runs on the AssetObserve Cloud service; hosting, data-processing and residency specifics are set out in the service agreement. For a specific deployment or a self-managed option, contact us.

05/

Plans, trial and partners

How licensing, limits, trials and MSP/partner use work.

01/ How are plans and limits structured?

Plans differ by asset, agent and monthly-scan limits and by feature access, checked before agents, scans, ingestion and PDF generation. The commercial Enterprise asset limit is 50,000. Current plans and prices are shown on the Billing page.

02/ Is there a trial?

Yes. You can start on a trial and move to a paid plan from the Billing center. Plan and trial changes are managed there rather than by editing limits directly.

03/ Can MSPs and partners manage multiple customers?

Yes. The partner center creates separated customer workspaces, keeps reports, tickets and billing per customer, and offers a portfolio risk board across tenants -- with customer authorization recorded per workspace.

04/ How does invoicing work?

Billing details drive hosted checkout and German invoice PDFs, and invoices are downloadable per row. Payments and plan changes happen in hosted checkout, not by AssetObserve staff editing your account.

06/

Operating at scale

How the platform stays reliable, deduplicated and usable as inventory grows.

01/ How are duplicate assets handled?

Source observations stay separate from the resolved asset, and stable identifiers (serial number, SMBIOS UUID, managed-device ID, directory GUID, MAC address) are preferred. Ambiguous matches go to review instead of being silently merged.

02/ Can a large inventory stay usable in the browser?

Yes. Server-side search, filters, cursor pagination, saved views and asynchronous CSV exports mean you never load every asset into one page at once.

03/ What happens if a worker or agent disconnects?

Discovery uses durable leases, checkpoints and retry states. Expired work is reassigned safely and signed agent batches can be replayed without creating duplicate evidence.

04/ What should we do if a network is not reachable?

Check scanner placement, routing, firewall policy and credentials, then the last task outcome. Coverage and Operations show whether it is unreachable scope, failed authentication, stale data or an unassigned scan point.

Need a guided answer?

Use the Help center for the next step.

Help turns the answers here into practical workflows for first discovery, source setup, findings, reports, operations and troubleshooting.

Open Help center