Platform · Integrations
Our own agents. Twenty integrations. One security picture.
Cybermatic brings its own agents — device posture, mobile enrollment, and network discovery — and connects to what you already run. Every connector is read-only by construction — it can list and describe, never create, modify, or delete — and every integration has a step-by-step guide showing the exact permissions before you approve anything.
Least-privileged credentials · Revocable from your console at any time
Cybermatic agents
First-party coverage, included on every plan. Report-only — agents send posture in; nothing reaches back into your devices.
Cybermatic Device Agent
Signed installer for Windows, macOS, and Linux — hourly device posture, software inventory, and native end-of-life and CVE detection, with verified self-updates.
Setup guideCybermatic Device Trust (mobile)
Enroll phones and tablets with one-time, individually revocable enrollments by QR code or email — built for corporate and BYOD devices.
Setup guideCybermatic Discovery Agent
One per network segment — passively finds every device that answers, listing printers, IoT, and unenrolled computers as unmanaged assets. Active probing is admin opt-in.
Setup guideCloud
Read-only roles you approve in your own console.
AWS
IAM read-only role via CloudFormation — inventory, misconfigurations, exposure across your accounts.
Setup guideMicrosoft Azure
Built-in Reader role on your subscriptions — resources, network exposure, storage posture.
Setup guideGoogle Cloud
Viewer role, keyless via Workload Identity Federation or a service-account key — projects, IAM, storage.
Setup guideMicrosoft 365
App registration with read-only Graph permissions — tenant posture and identity risks like mailboxes without MFA.
Setup guideIdentity providers
Read-only API scopes. Every user, one identity inventory.
Microsoft Entra ID
Directory users, admin roles, and MFA registration state through read-only Graph permissions.
Setup guideGoogle Cloud Identity
Custom read-only admin role, keyless (WIF) or key-based — users, admins, 2-Step Verification.
Setup guideSecurity & asset platforms
Least-privileged read credentials from tools you already run.
Microsoft Defender for Endpoint
Two read permissions — onboarded devices with Microsoft's exposure levels, plus real CVE data per device.
Setup guideRapid7 InsightVM
Insight Platform API key — scanned hosts and their vulnerabilities, grouped by CVE with solutions.
Setup guideQualys VMDR
Dedicated Reader account — host detections resolved to CVEs through the Qualys KnowledgeBase.
Setup guideLansweeper
Personal Access Token — your on-prem device inventory, with end-of-life and missing-device findings.
Setup guiderunZero
Export-only token (read-only by design) — every device that answers on your network, agent or not.
Setup guideEverything else
No API required.
CSV asset import
Upload your asset list from any inventory system — a guided wizard maps your columns and de-duplicates.
Setup guideManual asset entry
Add individual machines, devices, or systems so your inventory and compliance paperwork stay complete.
Setup guideMissing a tool you run?
Enterprise plans include custom options built around your environment — including custom connector development for the tools your business depends on.