Skip to content

Platform · Integrations

Our own agents. Twenty integrations. One security picture.

Cybermatic brings its own agents — device posture, mobile enrollment, and network discovery — and connects to what you already run. Every connector is read-only by construction — it can list and describe, never create, modify, or delete — and every integration has a step-by-step guide showing the exact permissions before you approve anything.

Least-privileged credentials · Revocable from your console at any time

Cybermatic agents

First-party coverage, included on every plan. Report-only — agents send posture in; nothing reaches back into your devices.

Cybermatic Device Agent

Signed installer for Windows, macOS, and Linux — hourly device posture, software inventory, and native end-of-life and CVE detection, with verified self-updates.

Setup guide

Cybermatic Device Trust (mobile)

Enroll phones and tablets with one-time, individually revocable enrollments by QR code or email — built for corporate and BYOD devices.

Setup guide

Cybermatic Discovery Agent

One per network segment — passively finds every device that answers, listing printers, IoT, and unenrolled computers as unmanaged assets. Active probing is admin opt-in.

Setup guide

Cloud

Read-only roles you approve in your own console.

AWS

IAM read-only role via CloudFormation — inventory, misconfigurations, exposure across your accounts.

Setup guide

Microsoft Azure

Built-in Reader role on your subscriptions — resources, network exposure, storage posture.

Setup guide

Google Cloud

Viewer role, keyless via Workload Identity Federation or a service-account key — projects, IAM, storage.

Setup guide

Microsoft 365

App registration with read-only Graph permissions — tenant posture and identity risks like mailboxes without MFA.

Setup guide

Identity providers

Read-only API scopes. Every user, one identity inventory.

Microsoft Entra ID

Directory users, admin roles, and MFA registration state through read-only Graph permissions.

Setup guide

Okta

Read-only API token — users, admin roles, and factor enrollment.

Setup guide

JumpCloud

Read-only API key — users, sudo and console admins, MFA status.

Setup guide

OneLogin

Read-only API credential pair — users, privileges, registered MFA devices.

Setup guide

Ping Identity

Worker app with read-only scopes — users, admin role assignments, MFA.

Setup guide

Google Cloud Identity

Custom read-only admin role, keyless (WIF) or key-based — users, admins, 2-Step Verification.

Setup guide

Security & asset platforms

Least-privileged read credentials from tools you already run.

Microsoft Defender for Endpoint

Two read permissions — onboarded devices with Microsoft's exposure levels, plus real CVE data per device.

Setup guide

Rapid7 InsightVM

Insight Platform API key — scanned hosts and their vulnerabilities, grouped by CVE with solutions.

Setup guide

Qualys VMDR

Dedicated Reader account — host detections resolved to CVEs through the Qualys KnowledgeBase.

Setup guide

Lansweeper

Personal Access Token — your on-prem device inventory, with end-of-life and missing-device findings.

Setup guide

runZero

Export-only token (read-only by design) — every device that answers on your network, agent or not.

Setup guide

Everything else

No API required.

CSV asset import

Upload your asset list from any inventory system — a guided wizard maps your columns and de-duplicates.

Setup guide

Manual asset entry

Add individual machines, devices, or systems so your inventory and compliance paperwork stay complete.

Setup guide

Missing a tool you run?

Enterprise plans include custom options built around your environment — including custom connector development for the tools your business depends on.