kombine.work

Integrations

Read-only wherever the vendor supports it. Every integration is included in the price, and each one is configured once and then runs on the schedule you give it. Nothing is collected that a control does not use.

Every sync leaves an audit entry naming the integration and the moment it ran, so a number on a control can always be traced back to the system it came from.

Identity

Microsoft Entra for single sign on and for user, guest and licence sync. Active Directory on-premises through a domain-joined agent, which is how an AD that never faces the internet still ends up in the register.

Endpoint

Microsoft Intune for managed device inventory, Microsoft Defender for machines, vulnerabilities and alerts, and ESET PROTECT cloud for device inventory. A machine seen by two of them is still one asset.

Cloud

Microsoft Azure subscription resources, Amazon AWS across EC2, RDS, S3 and IAM, and Google Cloud project resources, all landing in the same asset register as everything else.

Code

GitHub repositories, workflows and SAST alerts, GitLab projects, and SonarQube or SonarCloud findings. SAST scanning can also be triggered across the repositories you have configured rather than waiting for a pipeline.

Vulnerability scanning

OpenVAS scanner reports, OWASP ZAP dynamic web application scans on a schedule, and Wazuh manager events as alerts. Results file against the asset they concern, not into a separate console.

Asset import

Lansweeper, from the cloud product or by CSV, for estates already inventoried somewhere else.

Regulatory

The NKSC incident reporting API for Lithuanian entities, and a regulatory profile holding the entity code, sector and data protection officer details that filings ask for.

AI assistant

Off by default. A company that switches it on chooses and configures its own model provider, and nothing is processed through a provider you have not configured.