kombine.work

ISO/IEC 27001NIS2DORAGDPR

Turn your controls into evidence.

Kombine connects to your cloud accounts, Microsoft 365, endpoints, scanners and code. It builds your asset register, links findings to the right assets, and re-checks controls on a schedule you choose. When an auditor asks for proof, it is already there, with a source and timestamp.

From 166 EUR per month. One price for the whole company. No per-user or per-asset fees.
Hosted in the EU, or run on your own hardware.

Evidence received in the last 20 minutesRECORDING
Live evidence from connected systems
14:22:07azuredefender.recommendations, 312SYNCED
14:21:55endpointWS-4471, collector 2.6.1 heartbeatOK
14:20:18m365config.purview, retention policy changedDRIFT
14:19:40controlA.8.8 re-evaluated against 4 sourcesMET
14:18:02openvasscan 2291, 216 hosts, 41 new findingsDONE
14:16:44sonarqubebilling-api, 2 high severityRAISED
14:15:09entra4 privileged accounts without MFARISK
14:13:31wazuhagents reporting, 214 of 216OK

Example data shown to illustrate how an evidence record looks.

The problemwhy compliance goes stale

A compliance tool can record that a control works. It cannot see when that stops being true.

That is why compliance becomes a yearly scramble. Someone checks a system, writes down the result, attaches a file and sets a reminder to do it again next year. The register is accurate on the day it is filled in, then it starts to age. When the auditor arrives, weeks disappear into rebuilding evidence that was once correct.

Kombine closes that gap by reading the systems directly.Every control shows which sources support it and when each source last reported.If a setting changes or an agent stops reporting, the control changes state and the owner gets a notification.

The recordone control, two realities

The same control, with manual evidence and live evidence.

Control recordManual

A.8.8

Management of technical vulnerabilities

Status
ASSERTED
Evidence
vuln_tracker_v4_FINAL.xlsx
Last updated
94 days ago
Owner
left the company in March

Verified by

Nobody. The file says the control is met, but it contains no supporting evidence.

Control recordAutomatic

A.8.8

Management of technical vulnerabilities

Status
MET
Evidence
Collected from 4 connected systems
Last verified
6 minutes ago
Re-checks
every 6 hours

Verified by

Defender for Cloud312 findings, 0 critical open14 min
OpenVASscan 2291, 216 hosts in scope2 h
Wazuh agents214 of 216 reporting6 min
SonarQube4 repositories, SAST clean3 h

Also satisfies

NIS2 Art. 21(2)(e)
DORA Art. 9(4)
NKSC baseline 4.3

Methodfrom collection to evidence

Four steps. You configure the first one.

  1. Connect the systems you already use

    Use read-only credentials for cloud and SaaS, a signed agent for Windows and Linux, and an API token for scanners. Most customers start collecting evidence within one working day.

    AzureAWSGCPMicrosoft 365DefenderIntuneEntra IDActive DirectoryESETWazuhOpenVASOWASP ZAPGitHubGitLabSonarQubeLansweeperSARIFNetwork sweep

  2. One record for every asset

    A server seen in Azure, Defender, your EDR and a vulnerability scan is still one asset, not four. Ownership, classification and audit scope stay with that asset. A sync never overwrites a decision made by a person.

    Asset registerAsset profilesDependency mapAttack paths

  3. Controls re-check themselves

    Each control is evaluated against the current asset register on your schedule. AI can draft a risk entry for a real finding and reduce noise, but a person approves it. When something drifts, Kombine creates a ticket with an owner and a deadline.

    Control monitoringRisk registerNon-conformancesSLA tickets

  4. Reports use the same source data

    No last-minute evidence hunt. Auditor exports, regulatory filings and management reports all use the same records, and every number can be traced back to the system that produced it.

    Auditor exportNKSC filingDORA registerVDAI notificationBoard report

Contentswhat is available today

Everything below is already in Kombine.

No tiers. No feature gates. Open a group to see the modules. A teal dot means the data comes from a connected system, not from manual entry.

Governance

registers and records

Modules 9Live connected 0

  • Risk registers by type
  • Control catalogues
  • Statement of Applicability
  • Compliance goals
  • Improvement plan
  • ISMS document register
  • Non-conformances
  • Approval workflows
  • KPIs

Estate

what you own

Modules 9Live connected 5

  • Asset register with sync
  • Device compliance
  • Active Directory objects
  • Network discovery
  • Cloud resource inventory
  • Business capability view
  • Dependency and topology map
  • Asset profiles
  • Supplier register

Detection

continuous

Modules 9Live connected 8

  • Vulnerabilities from every scanner
  • Cloud misconfigurations
  • Microsoft 365 posture
  • Security incidents from EDR
  • Code and dependency scanning
  • Attack paths
  • Threat intelligence feeds
  • Consequence graph
  • AI triage and prioritisation

Evidence and reporting

on demand

Modules 9Live connected 1

  • Continuous control monitoring
  • Evidence store
  • Auditor export pack
  • NIS2 and NKSC filings
  • DORA Register of Information
  • GDPR breach register
  • Report builder and scheduler
  • Full change audit log
  • Regulatory clocks and reminders

Operations

day to day

Modules 9Live connected 0

  • Service requests with SLA
  • Turn email into tickets
  • Vendor management
  • Vendor questionnaires
  • Recurring vendor reviews
  • Security awareness training
  • Training groups
  • Kombi, AI assistant for your data
  • Scheduled notifications

Deployment

how you run it

Modules 9Live connected 0

  • EU hosted
  • Self-hosted on your hardware
  • Entra ID single sign-on
  • Company IP allow-list
  • English and Lithuanian
  • Encrypted company backups
  • Signed collector agents
  • Role and scope based access
  • Instant session revocation

Scopewhat you enable

No default framework. Enable only what applies to you.

NIS2

Directive (EU) 2022/2555

Use the Article 21 measures as a live control catalogue, with incident reporting in the format NKSC expects. The 24 and 72 hour deadlines become tickets with reminders and a named owner, instead of a note in someone's calendar.

Art. 21 measures
Art. 23 reporting
NKSC filing export

ISO/IEC 27001

2022 revision

Track all 93 Annex A controls with scores and evidence in the same record. The Statement of Applicability is generated from that data, so it stays aligned with what your controls actually say.

93 Annex A controls
Statement of Applicability
Internal audit trail

DORA

Regulation (EU) 2022/2554

Build the Article 28 Register of Information from the ICT provider and contract records you already keep, then export it as xBRL-CSV for the Lietuvos bankas Regata submission.

Art. 28 register
xBRL-CSV export
ICT third-party risk

GDPR

Regulation (EU) 2016/679

A personal data incident starts its 72 hour clock to VDAI. If a notification is late, record why. If you decide not to report an incident, keep the justification in the register.

Art. 33 notification
VDAI form
Non-reportable register

Walkthroughwe reply within two working days

See Kombine running on your own systems.

A 30-minute walkthrough with your frameworks enabled and one of your real systems connected. You will see what Kombine collects, how controls are checked, and what your next audit could look like.

We use this only to arrange the walkthrough. We do not share it with third parties. See ourprivacy notice.