Skip to content

Support

How-to guides for everything.

Step-by-step instructions for connecting your clouds, deploying Cybermatic's agents, adding assets, and getting the most from every service — written for people who don't have a security team.

Getting started

Frequently asked questions

Is the cloud connection safe? What exactly can Cybermatic access?

Every connection is read-only by construction — that principle holds across all twenty integrations. Cloud accounts use read-only roles (an AWS IAM read-only role, Azure's built-in Reader, GCP's Viewer). Identity providers use read-only API scopes. Security and asset platforms use their least-privileged read credentials — runZero's export-only token, a Qualys Reader account, two read permissions for Defender. Cybermatic can list and describe, but cannot create, modify, or delete anything, anywhere. You can review the exact permissions before approving (every setup guide shows them), and revoke access at any time from your own console — you stay in control.

Do I need to install agents or software on my computers or servers?

No — Cybermatic itself never installs anything. Discovery runs entirely through read-only APIs. For machines that aren't in the cloud — office computers, on-prem servers, network gear — connect a tool that already sees them: Microsoft Defender for Endpoint, Lansweeper, runZero, Rapid7, or Qualys, and those devices join your inventory with their vulnerabilities. No such tool? Import your asset list from a CSV, or add machines manually — either way your inventory, risk conversation, and compliance paperwork stay complete.

I'm not technical. Can I actually use this?

That's exactly who it's built for. Findings are explained in plain English with business impact, Cybermatic Copilot answers questions the way a patient security engineer would, and reports are written for leadership. The one technical moment — applying a fix — comes as exact copy-paste instructions you can forward to your IT person or MSP.

How long does setup really take?

Connecting a cloud account takes about five minutes. Your asset inventory appears within minutes of connecting, and the first full risk analysis completes within the hour. There's no proof-of-concept project, no onboarding call required.

What if we use multiple clouds, or mostly aren't in the cloud at all?

Connect any mix — AWS accounts, Azure subscriptions, Google Cloud projects, Microsoft 365 tenants, your identity provider (Entra ID, Okta, JumpCloud, OneLogin, Ping, or Google Cloud Identity), and your device or vulnerability tools (Defender, Lansweeper, runZero, Rapid7, Qualys) — everything lands in one inventory with one risk picture. Microsoft 365 is worth connecting even for cloud-light businesses, since identity risks like mailboxes without MFA are the leading cause of SMB breaches. If most of your footprint is laptops and on-prem hardware, a device tool connection or a CSV import keeps your inventory complete (CIS Control 1 requires a full asset inventory).

Which tools and platforms does Cybermatic connect to?

Twenty integrations across four families. Cloud: AWS, Microsoft Azure, Google Cloud, Microsoft 365. Identity providers: Microsoft Entra ID, Okta, JumpCloud, OneLogin, Ping Identity, Google Cloud Identity. Security & asset platforms: Microsoft Defender for Endpoint, Lansweeper, runZero, Rapid7 InsightVM, Qualys VMDR. Plus CSV import and manual entry for everything else. Every connection is read-only, takes minutes with a step-by-step guide, and feeds the same dashboard, risk scoring, and compliance reports.

What's the difference between Risks and Vulnerabilities in the dashboard?

Risks are configuration and identity problems Cybermatic finds in how things are set up — a public storage bucket, an admin without MFA, a never-expiring password. You fix these once by changing the setting, and many come with ready-to-apply remediation code. Vulnerabilities are software flaws (CVEs) and end-of-life systems reported by your connected security tools — Defender, Rapid7, Qualys, or your asset platforms. These close automatically when the source stops reporting them, typically after patching. Different problems, different fixes, one combined picture in your reports and compliance scores.

Where is my data stored and who can see it?

Your configuration and findings data is stored encrypted in our AWS environment in the United States, isolated per customer workspace. We don't sell data, and we never use your environment data to train AI models without your express written authorization — see our Privacy Policy for the full commitments. Access within Cybermatic is limited to what's needed to operate the service and support you.

How accurate is the AI? Can I trust the fixes and documents?

The AI is grounded in your actual environment data — it reasons over your real assets and findings rather than inventing them. That said, you're always the reviewer: fixes are never auto-applied, and compliance documents are generated for your review and approval. Treat it like a very fast junior security engineer whose work you sanity-check.

Can my MSP or IT provider use Cybermatic on our behalf?

Yes — many customers invite their MSP to run it for them. On Growth and Enterprise, invite them from Settings → Team: as a viewer they can monitor everything and generate reports; on Enterprise you can make them an administrator to manage connections and remediation directly. Invited members sign in with their own credentials and are never asked for a card.

What happens when my trial ends?

If you subscribed with a card, billing simply starts. If not, the workspace pauses at day 14: scans stop and the dashboard shows a single choice — pick a plan. Nothing is deleted when the trial ends: your connections, findings, reports, and settings are preserved for a limited period as described in our Privacy Policy, and choosing a plan resumes everything exactly where you left off. We email you at 3 days, 1 day, and when the trial ends — no surprises. You can request earlier deletion any time by emailing info@cybermatic.ai with the subject "Account Closure or Privacy Request."

How often does Cybermatic scan, and can I trigger a scan myself?

Your very first scan starts the moment you connect a cloud account — on every plan — with assets and findings appearing within minutes. After that, scans run automatically on your plan's schedule: weekly on Starter, daily on Growth, and continuously on Enterprise. You can also press Scan now (on the Assets page or in Settings) any time your plan's cadence allows; if a scan isn't available yet, the button tells you exactly when the next one unlocks.

How do I get help from a human?

Fastest: submit a ticket in the portal (Support → New ticket) — it arrives with your workspace context and you can track the whole conversation there, with email notifications on every reply. Email info@cybermatic.ai works too. We respond within one business day (faster for Growth and Enterprise customers). Enterprise plans include a dedicated support channel.

Still stuck? Talk to a human.

Email us what you were trying to do — a screenshot helps — and we'll respond within one business day.