Security
Read-only, scoped, and inspectable.
AssetView reads inventory data from systems you already trust. This page states what is requested, what is stored, how long it stays, and where the program currently is — including the parts that are not finished.
Current posture
Where the program stands today
SOC 2 Type II
In progressObservation window underway with an independent auditor. The report is not issued yet, and we will not claim it before it is. Type I controls documentation is available under NDA now.
Penetration testing
AnnualThird-party application and infrastructure test, with a summary letter available to customers and prospects under NDA.
Data residency
US, EU on requestWorkspaces are pinned to a region at creation. Cross-region replication is off unless you ask for it.
Subprocessors
PublishedThe current list is provided during evaluation and changes are notified 30 days ahead of taking effect.
Access
What each connector asks for
| Source | Access | Read | Never requested |
|---|---|---|---|
| Jamf Pro | API role, read | Device inventory, hardware attributes, enrollment state | Remote commands, policy or profile changes, wipe |
| Workday | Integration system user | Worker ID, department, cost center, hire and end dates | Compensation, performance, personal contact detail |
| CrowdStrike | OAuth client, read | Host inventory, sensor version, last check-in | Detections content, response actions, quarantine |
| Okta | API token, read | Users, groups, application assignments | Password or factor material, session control |
| Coupa | OAuth, read | Purchase order lines, asset descriptions, cost centers | Payment initiation, banking detail, approvals |
Data handling
What is stored and for how long
Stored
Asset attributes, the identifiers used to match them, worker identifiers with name, department and dates, and the source and timestamp behind every field.
Not stored
Screen contents, keystrokes, file listings, browsing history, location beyond the site or building recorded in your own systems, and any HR field outside the list above.
Encryption
TLS 1.2 or better in transit. AES-256 at rest. Source credentials held in a managed secrets store with per-workspace keys, never in application tables.
Retention
Live data for the life of the contract. On termination, workspace data is deleted within 30 days and backups age out within 35. A shorter schedule can be set per workspace.
Access by our staff
Support access to a customer workspace is time-boxed, requires an approved reason, and appears in your own audit log.
Audit log
Every sync, rule change, manual merge, and export is recorded with actor and timestamp, and is exportable.
Next step
Find out how far apart your systems are.
We run a read-only reconciliation across your MDM, HR system, endpoint agent, and procurement records, then walk you through where they disagree and why.