IT asset register for NIS2, ISO 27001 and ZInfV-1

Every IT asset in one register, with proof nobody changed it

Workstations, servers, network devices, applications, people and licences in one table, filled automatically from the systems you already run, with a hash-chained audit trail that shows any tampering.

Book a demo See what it does

The Evidenta assets table with counts per type

Fills itself from what you already run

  • Microsoft Intune
  • Microsoft 365
  • Active Directory
  • Entra ID, Okta, Google, Keycloak
  • Prometheus
  • SNMP, LLDP and ARP
  • Excel and CSV
  • SCIM 2.0
  • JSON ingest API

One place for everything IT

Evidenta replaces the spreadsheet, the Intune export and the licence list with one register that stays current on its own.

One register

Devices, applications, people, licences and any asset type you add, in one searchable table and linked to each other: who has which laptop, what runs on which server, which switch a device hangs off.

Data comes in by itself

Intune, Microsoft 365, Active Directory, Prometheus and a network scan without nmap sync every 15 minutes. Records are matched by serial number, MAC address, hostname or UPN.

Start from your spreadsheet

Import Excel or CSV with columns mapped from Slovenian or English headers, and a preview of every row before anything is written.

Licences under control

Seats bought versus in use, over-allocation and upcoming renewals. Licence keys are refused, so secrets never end up in the permanent history.

Access that fits your company

Sign in with Active Directory, single sign-on or an email link, with two-step sign-in. Roles limited to asset categories, locations or departments, mapped to directory groups.

Warnings before things end

One mail digest before licences, warranties and supplier contracts run out, when sources fail, deletions wait for approval or critical CVEs appear.

See where every record came from

The Sources page shows each connector's health, last sync and errors, with a Sync now button. When sources disagree, a priority order decides, and a change made by hand always wins.

Sources page with health and errors per connector

Know who did what, and when

Every add, edit and delete, and every view, search and export, lands in the audit log with who, when and from which IP address. Expand an entry to see each field before and after, then export it as CSV or JSON.

Audit log with an edit expanded to show each field before and after

Bring in the spreadsheet you already have

Most companies start with a spreadsheet. Upload it, check the column mapping, and see what every row would do before anything is written. Each import is recorded with the file's SHA-256.

Import preview with new, updated and error rows

Follow the links between records

Open a person to see their laptop, phone, licences and direct reports. Links come from Intune, Microsoft 365 and Active Directory, and you can set them by hand too.

A person's assigned devices and direct reports

Your own asset types and fields

Add the asset types your company keeps track of, such as phones, printers or vehicles, and choose the fields each type has: text, numbers, dates, choice lists or links to other records, named in Slovenian and English. Export the fields as JSON and import them into another installation. A type you no longer use can be deleted once it has no records, and its audit trail stays intact.

Metadata page with the fields of one asset type

An audit trail you can prove, not just show

Most tools keep a change log. Evidenta makes it impossible to rewrite one without being caught.

Append-only history

Every change is a new version. The database itself refuses edits and deletes of the history, even from its owner.

Hash chain

Each version carries a SHA-256 hash of its contents and the version before it. Verification finds the first broken link.

Signed checkpoints

Every hour the heads of the chains are signed with Ed25519 and copied to S3 with Object Lock, a folder or a webhook.

Checked offline

Auditors download signed exports and verify them on their own computer, without the server or the database.

GDPR erasure that keeps the chain

Personal data in the history is encrypted with a key per person. Erasing the person deletes the key, and the chain still verifies.

Deletions need a reason

Every delete takes a reason, and anyone but an admin needs an admin's approval first.

Activity page with a verified audit chain and signed checkpoints

Evidence for NIS2, ZInfV-1 and ISO 27001

Package L adds a Compliance page that turns the register into evidence. Whether a control is met is for you and your auditor to decide; Evidenta gives you the proof.

  • An owner, a criticality and a confidentiality, integrity and availability rating on every asset, with a list of what is missing
  • A supplier register with contracts, data processing agreements and assessments
  • A leaver report: devices, licences and applications still linked to people who left
  • CVE matching from the NVD, with CISA's known exploited list and risk acceptance with a reason
  • Signed evidence packs per ISO 27001 and NIS2 control that auditors check offline
Compliance overview with owners, ratings, vulnerabilities, suppliers and leavers

Packages

Every package keeps a versioned, hash-chained history underneath, so after an upgrade the full history is already there. Nothing is removed at a limit.

SML
Users3510
Assets (employees do not count)401001000
Active Directory, Prometheus, network discovery, manual entry✓Included✓Included✓Included
Import from Excel and CSV✓Included✓Included✓Included
Your own asset types and metadata templates, with JSON import and export✓Included✓Included✓Included
GDPR erasure and subject access export✓Included✓Included✓Included
Microsoft Intune and Microsoft 365–Not included✓Included✓Included
History of each asset–Not included✓Included✓Included
Prometheus enrolment–Not included✓Included✓Included
Mail notifications–Not included✓Included✓Included
Full audit trail: audit log, verification, signed checkpoints, exports–Not included–Not included✓Included
Generic ingest API–Not included–Not included✓Included
Custom mail templates–Not included–Not included✓Included
Compliance: owners, CIA ratings, suppliers, leavers, CVEs, evidence packs–Not included–Not included✓Included

Ask for pricing

Runs on your own server

Your asset data stays in your network. Evidenta is one Docker Compose setup with Postgres and nothing else to run.

A pilot in half a day

A Linux VM with 2 vCPU and 4 GB RAM handles tens of thousands of assets. The pilot guide walks through HTTPS, Intune and Active Directory step by step.

In English and Slovenian

Every page in both languages, chosen by each person. Works on phones, where tables become cards.

Ready for the Cyber Resilience Act

Every release comes with a signed SBOM, a vulnerability scan and Sigstore signatures, and gets security updates for at least five years.

Made in Slovenia

Built for IT teams that need one trustworthy register and proof of it for NIS2, ISO 27001 and ZInfV-1 audits.

Questions

Is Evidenta a cloud service?

No. You run it on your own server with Docker Compose, so asset data and personal data never leave your network. The installation checks in with our licence server once a week, sending only the licence, the installation ID, the version and how many users and assets are in use.

What if we only have a spreadsheet today?

Import it. Columns are mapped from Slovenian or English headers, and you see what every row would do before anything is written. Connectors can be added later; they fill in what they know without losing what you imported.

Can an administrator quietly change the history?

Not without it showing. The database refuses edits to the history, every version is hash-chained, and hourly signed checkpoints are copied somewhere the server cannot change them. A rewrite no longer matches the copies.

How does erasure under GDPR work with an append-only history?

Personal data in the history is encrypted with a key per person. Erasing the person deletes the key, so their data reads [erased] while the chain still verifies. This is in every package.

What happens if we hit a package limit?

Nothing is removed. New users and assets are refused and existing ones keep updating. Upgrading to a larger package lifts the limit, with the full history already there.

See Evidenta on your own data

Write to us for a demo or a pilot licence. We answer in Slovenian or English.

Write to us

info@izibiznis.net