Kervo AI
Platform/Know/Asset Discovery
Kervo AI · Know

One live inventory of everything you have.

Connect the tools you already run: your EDR, vulnerability scanners, code scanners and cloud accounts. Kervo AI merges what each one knows into one record per asset, with the relationships between them mapped.

platform.kervo.ai / know / inventory
Know / Inventoryliveacme-prodINVENTORY1,288 assetsASSETTYPESEEN BYOWNERprod-db-01serverAWS · CrowdStrikedatacrown jewelfin-laptop-114endpointDefenderfinancepayments-apirepoGitHub · Semgreppaymentsk8s-node-14containerGoogle Cloudplatformsvc-deployidentityJumpCloudinfracore-sw-02switchNessusnetwork10.0.4.12serverRapid7—no EDRDEDUPLICATIONEDR 1,402Scanners 1,120Cloud 812Code 5701,288 unique3,904 raw records resolved to one asset eachSOURCES · YOUR INTEGRATIONSEDR / XDR614Vuln scanners431Cloud387Code218Identity187RELATIONSHIPScriticality · highsvc-deployk8s-node-14payments-apivpc-prodprod-db-01
Built on your integrations
EDR, vulnerability scanners, code, cloud and identity
One record per asset
the same server from five tools counted once
Coverage gaps surfaced
devices your scanner sees but your EDR doesn't
[ The problem ]

The problem with asset inventories

Every security tool keeps its own list. Your EDR knows the machines its agent is on. Your scanner knows the subnets it was pointed at. Your cloud console knows its own accounts, and your code scanners know the repositories. Each list uses a different identifier (hostname, IP, instance ID, repo name), and nobody finishes reconciling them.

So "how many assets do we have" gets a range, and the machines missing from one list, like a server with no EDR agent or a subnet the scanner never covered, are exactly where breaches start.

[ What Kervo AI does ]

What Kervo AI does

You connect the tools you already run through read-only APIs. Kervo AI pulls endpoints and servers from your EDR (CrowdStrike, Microsoft Defender, Palo Alto Cortex XDR, Sophos), hosts and network devices from your vulnerability scanners (Nessus, Rapid7, OpenVAS or the Kervo AI Network Scanner), repositories and applications from your code tools (GitHub, GitLab, SonarQube, Semgrep, Mend.io), and workloads from AWS, Azure, Google Cloud and Oracle Cloud.

It resolves them into one deduplicated inventory with the relationships mapped, then shows where the tools disagree: a server your scanner sees that has no EDR agent, a cloud workload no scanner has touched, a repository deployed to production that nobody scans. Tag assets by criticality and that context flows into everything downstream.

[ Capabilities ]6 capabilities
01

Integration-based discovery

EDR and XDR platforms, vulnerability scanners, code and repository tools, cloud accounts and your identity provider, all connected read-only. Each source adds the assets it knows about and the attributes only it has.

02

Deduplication and asset resolution

The same machine reported by your EDR, your scanner and your cloud account resolves to one record, matched across hostnames, IPs, instance IDs and agent IDs. Counts are real, and findings from every tool attach to the right asset.

03

Coverage gap detection

Every asset shows which tools see it and which don't. Servers without an EDR agent, subnets no scanner covers and repositories nothing scans are listed as gaps to close, not left for an attacker to find.

04

Relationship mapping

Network reachability, IAM trust, credential validity and dependencies between services, recorded as edges between assets. This is the structure attack path analysis walks.

05

Criticality and ownership

Set criticality manually, inherit it from cloud tags, or let Kervo AI derive it from connectivity and data classification. Assign owners and scope, and both flow into every downstream report.

06

Change detection

A new asset, a decommissioned one, an agent that stops reporting or a change of owner, detected as each source syncs.

[ How it works ]

How it works

Each integration connects through a read-only API or key and syncs on a schedule. Kervo AI normalises what comes back, matches records that describe the same asset, and keeps one current record per asset with the history of what each source reported.

The internet-facing side, meaning domains, subdomains and exposed services found from the outside, is covered by External Attack Surface Management and lands in the same inventory.

[ One data model ]

Why the inventory has to be the same graph

A CAASM tool that only aggregates other inventories stops at the list. Kervo AI writes the merged inventory into the same data model that scanning, prioritisation and compliance use. That is why criticality set here changes Evaluate's ranking, why a finding from any tool lands on the right asset, and why Validate's evidence can cite an asset by name.

See how this fits into Know
[ FAQ ]Asset Discovery
What is CAASM?

Cyber Asset Attack Surface Management: one current inventory of every asset an organisation has, built from the tools it already runs, with the relationships between them.

Which tools can we connect?

EDR and XDR platforms such as CrowdStrike, Microsoft Defender, Palo Alto Cortex XDR and Sophos. Vulnerability scanners such as Nessus, Rapid7 and OpenVAS. Code tools such as GitHub, GitLab, SonarQube, Semgrep and Mend.io. AWS, Azure, Google Cloud and Oracle Cloud, and your identity provider. See the full integrations list.

Do we need to provide an asset list?

No. The inventory is built from the tools you connect. Most teams find machines one tool knew about and another didn't.

Does it need new agents?

No. Kervo AI reads from the agents and tools you already run, through read-only APIs.

What counts as an asset for pricing?

Any monitored entity: a server, an endpoint, a cloud workload, a network device, a repository. Excluded assets don't count, and you see the exact number before committing.

[ More in Know ]
Get started

See what's actually in your environment.

Connect a few of your tools during the demo and we'll walk through the merged inventory, including the gaps between them.