Security

Read-only, scoped, and inspectable.

AssetView reads inventory data from systems you already trust. This page states what is requested, what is stored, how long it stays, and where the program currently is — including the parts that are not finished.

Current posture

Where the program stands today

SOC 2 Type II

In progress

Observation window underway with an independent auditor. The report is not issued yet, and we will not claim it before it is. Type I controls documentation is available under NDA now.

Penetration testing

Annual

Third-party application and infrastructure test, with a summary letter available to customers and prospects under NDA.

Data residency

US, EU on request

Workspaces are pinned to a region at creation. Cross-region replication is off unless you ask for it.

Subprocessors

Published

The current list is provided during evaluation and changes are notified 30 days ahead of taking effect.

Access

What each connector asks for

SourceAccessReadNever requested
Jamf ProAPI role, readDevice inventory, hardware attributes, enrollment stateRemote commands, policy or profile changes, wipe
WorkdayIntegration system userWorker ID, department, cost center, hire and end datesCompensation, performance, personal contact detail
CrowdStrikeOAuth client, readHost inventory, sensor version, last check-inDetections content, response actions, quarantine
OktaAPI token, readUsers, groups, application assignmentsPassword or factor material, session control
CoupaOAuth, readPurchase order lines, asset descriptions, cost centersPayment initiation, banking detail, approvals

Data handling

What is stored and for how long

Stored

Asset attributes, the identifiers used to match them, worker identifiers with name, department and dates, and the source and timestamp behind every field.

Not stored

Screen contents, keystrokes, file listings, browsing history, location beyond the site or building recorded in your own systems, and any HR field outside the list above.

Encryption

TLS 1.2 or better in transit. AES-256 at rest. Source credentials held in a managed secrets store with per-workspace keys, never in application tables.

Retention

Live data for the life of the contract. On termination, workspace data is deleted within 30 days and backups age out within 35. A shorter schedule can be set per workspace.

Access by our staff

Support access to a customer workspace is time-boxed, requires an approved reason, and appears in your own audit log.

Audit log

Every sync, rule change, manual merge, and export is recorded with actor and timestamp, and is exportable.

Next step

Find out how far apart your systems are.

We run a read-only reconciliation across your MDM, HR system, endpoint agent, and procurement records, then walk you through where they disagree and why.

Request a data accuracy assessment

Read-only access. No agent to deploy. Nothing written back to your systems.