ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Asset Management

Most breaches start
with an asset nobody
knew existed

Alvor builds a living inventory across every environment, with an extensible set of built-in asset types plus custom types you define. Every asset is connected to the risks, policies, and compliance controls that depend on it.

Explore CapabilitiesRequest Demo
prod-api-07Cloud service · AWSOWNERPlatform TeamCRITICALITYCriticalDATAPII · PHIENCRYPTIONAES-256LIFECYCLEOperateSCOPESOC 2Risk3 open risksPolicy5 enforcedCompliance11 controls

Who it is for

You cannot protect what nobody has written down.

The security team

The register the rest of the program stands on.

  • The types and relationships your estate actually uses, plus your own
  • Vulnerability findings from your scanners attach to the asset they belong to
  • Risks name the assets they affect, chosen by live search at intake

The engineering lead

The register fills itself from the tools you already run.

  • Integration adapters pulling inventory in automatically
  • GitHub and GitLab bring repositories in with their vulnerability findings
  • AWS brings accounts, instances, databases, buckets, clusters and IAM principals

The asset owner

Ownership with a cadence, not a one-off spreadsheet exercise.

  • Certification policies by type, criticality or department
  • Campaigns with bulk certify, reminders and scheduled escalation
  • A Continuity tab inheriting the strictest recovery objectives, with attribution

The product

What that looks like on screen.

01 · The register

One inventory, across every environment you run

Cloud, code, endpoints and the things nobody automated, each with its type, business criticality, status, location and a named owner. Built-in types cover the usual estate and you can define your own when they do not fit.

app.alvor.io/assets
One inventory, across every environment you run

02 · A single asset

What it is, who owns it, and what breaks if it stops

Criticality and status up front, then a tab per question worth asking. Dependencies draws what this asset relies on and what relies on it, so the blast radius of an outage is something you can look at rather than reconstruct from memory.

app.alvor.io/assets/detail
What it is, who owns it, and what breaks if it stops

The asset record

An asset is not a row. It's a six-dimensional record.

Most platforms have an asset inventory. Alvor has an asset record: one entity with six dimensions, each cross-linked, each evidencing a different part of the security program.

alvor.io / platform / assets / app.example.com

app.example.com

Web ApplicationMedium criticalityActive
Overview
Dependencies
Components
Security
Continuity
Data

Dimensions

6

Cross-linked into

Risk, Continuity, Compliance

Source of truth

One record

Overview

Status, criticality, ownership, and lifecycle. The header every other dimension reads from.

Dependencies

Deep dive

Upstream and downstream service and data dependencies, classified by type and criticality-scored. Drives blast radius.

Explore

Components

Deep dive

A software bill of materials plus the technical components the asset runs on. Libraries by ecosystem and version, databases and services with environment and status.

Explore

Security

Vulnerability findings from integrations and manual assessments. CWE references, severity, integration source, lifecycle state.

Continuity

Deep dive

RTO, RPO, business impact analysis, and recovery procedures. Plan inherits the asset's criticality and dependencies.

Explore

Data

Deep dive

Classification, retention, ownership, encryption, geographic scope, and structured PII / PHI / PCI tracking.

Explore

Four dimensions get dedicated landing pages because their categories warrant standalone consideration: dependency mapping, components, business continuity, and data governance. The other two live on the asset itself, where they belong.

Core capabilities

See every asset, with no blind spots

01

Continuous Discovery

Find every asset - managed or shadow, cloud or closet. Ingest via API integrations, CSV/JSON import, or manual entry.

02

Intelligent Classification

Tag each asset with criticality, data sensitivity, regulatory scope, and encryption status. Dual ownership baked in.

03

Full Lifecycle Tracking

Follow every asset from Plan through Acquire, Deploy, Operate, and Retire. No stale spreadsheet rows.

04

Data Governance

Attach governance records: data types (PII, PHI, PCI), retention periods, encryption, processing justification.

05

Automated Recertification

Campaigns on your schedule. Owners notified at 7, 3, and 1 day before deadlines. Overdue assets auto-escalate.

06

Dependency Mapping

Map upstream and downstream relationships between assets, services, and data flows.

How it works

Discover, classify, and certify.

01

DISCOVER

Find every asset, managed or shadow

Four ingestion paths ensure nothing hides. API integrations pull from Veracode, AWS, Azure, and GCP. Bulk CSV/JSON import handles legacy data. The REST API lets you build custom connectors.

  • Veracode integration live - SAST, DAST, SCA findings auto-linked
  • HMAC-SHA-256 authenticated sync with configurable schedules
  • Extensible built-in asset types plus custom types you define, with rich field schemas
000090180270030060120150210240300330255075100SRV-01API-01DB-03APP-V2K8SSCANNING · LIVE1,247 ASSETS · 4 SOURCES · 99.8% COVERAGE
02

CLASSIFY

Context that outlives the person who entered it

Criticality levels, data classification tiers, encryption tracking, regulatory scope, dual ownership, and a flexible EAV architecture for custom fields.

  • Criticality: Low, Medium, High, Critical
  • Data classification: Public, Internal, Confidential, Restricted
  • Lifecycle phases: Plan → Acquire → Deploy → Operate → Retire
Asset Detailprod-db-primaryPostgreSQL | i-0a1b2c3d4e5fCRITICALITYCriticalDATA CLASSIFICATIONConfidentialPCIPIILIFECYCLEPlanAcquireDeployOperateRetireOWNERSJDJane DoeTechnical OwnerMSMike SmithBusiness OwnerENCRYPTIONAt rest + In transitLast scanned 2 min agoCustom FieldsBCPRTO: 4 hoursRPO: 1 hourCOMPLIANCESOC2ISOHIPAARETENTION7 yearsLegal hold activeDEPENDENCIESapi-gatewayredis-cache-01auth-service+9 more
03

CERTIFY

Recertification on your schedule

Certification campaigns run on your schedule - monthly, quarterly, annual, or custom. Owners are notified at 7, 3, and 1 day before the deadline. Overdue assets auto-escalate.

  • Immediate or scheduled campaigns with configurable grace periods
  • Auto-escalation after N days overdue to specified roles
  • Full certification history: created, completed, extended, cancelled
Certification CampaignQ1 Access RecertificationQuarterly | 47 assets | 12 owners68% certified32 of 47prod-db-primaryCertified by J. Doe | 2 days agoDoneapi-gateway-prodDue in 3 days | NotifiedDue!legacy-app-v2Overdue 5d | Escalated to VPOverduecloud-k8s-clusterPending | Due in 18 daysPendingNotificationsCADENCEQuarterlyGRACE PERIOD7 daysSCHEDULE7 days beforeSent3 days beforeSent1 day beforeTodayAuto-escalation+5 daysAUDIT TRAILEvery action timestamped

The connective tissue

One asset record, linked to every module

In Alvor, every asset is natively linked to the modules that depend on it. A vulnerability flows to a risk, maps to a compliance control, triggers an action plan - all traced back to one record.

Active
PostgreSQL · RDS

prod-db-primary

AWS RDS · us-east-1 · vpc-0a1b2c3d

CriticalConfidentialOperatePCI
JD
Tech Owner
MS
Biz Owner
Risk 87/100

3

linked risks

Risk

Criticality informs risk scoring. Impact analysis auto-links to affected assets.

12

controls mapped

Compliance

Evidence campaigns target asset groups. Scoring weighs inventory completeness.

5

design reviews

Secure by Design

Architecture diagrams reference asset nodes. Findings create linked risks.

8

active policies

Policy

Policies scope by asset type. Exceptions and acknowledgments target custodians.

Connects to your stack

Bring your tools and keep one inventory

Veracode
AWS
Azure
GCP
Qualys
CrowdStrike
Okta
Splunk
ServiceNow
Jira
GitHub
GitLab
Veracode
AWS
Azure
GCP
Qualys
CrowdStrike
Okta
Splunk
ServiceNow
Jira
GitHub
GitLab
Datadog
PagerDuty
Terraform
Kubernetes
Snowflake
Cloudflare
SentinelOne
Tenable
Carbon Black
Rapid7
MongoDB
REST API
Datadog
PagerDuty
Terraform
Kubernetes
Snowflake
Cloudflare
SentinelOne
Tenable
Carbon Black
Rapid7
MongoDB
REST API

Encrypted credential storage · Configurable sync schedules · Full audit trails

What it replaces

A register that maintains itself.

Asset inventories do not fail because nobody built one. They fail because nobody could keep it current.

Instead of

A CMDB nobody updates

Accurate the week it was built, and a work of fiction six months later.

In Alvor

Eight adapters pulling inventory from the tools you already run, plus certification campaigns that force a human check on a schedule.

Instead of

An asset list with no owner column

Everyone assumes somebody else is looking after it, so nobody is.

In Alvor

A named owner per asset, with reminders and escalation when a certification goes unanswered.

Instead of

Inventory that stops at the asset

You know the server exists. You do not know what would break without it.

In Alvor

Risks that name their affected assets, and continuity requirements inherited from the processes that depend on them.

How it connects

These are the exact links in the data model.

Named precisely, because “everything connects to everything” is not a claim anyone can check.

Risk Management

A risk names the assets it affects, many to many, chosen by live asset search at intake.

Explore
Business Continuity

Process dependencies point at assets, and each asset shows the strictest recovery objectives inherited from what relies on it.

Explore
Secure by Design

A threat-model element can be identified as a register asset, by real foreign key.

Explore

Asset Management

Complete asset visibility - across every environment, automatically

Alvor builds a living inventory across an extensible set of built-in asset types, plus custom types you define. Every asset is automatically linked to the risks it carries, the policies that govern it, and the compliance controls that depend on it.

See your inventoryExplore the platform
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Learn
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyVulnerability Disclosure