Every feature, edition by edition

Start free with Community. Pro adds everything below it - and you can try any Pro edition free for 60 days.

Community37 features

Free, on GitHub:

Risk-based prioritization

  • Risk Score from consequence × probability (asset tier) × risk factors
  • Weighted by CMDB business criticality and data sensitivity
  • One headline Risk Score KPI plus a breakdown per domain, in email and Log Analytics
  • Editable scoring matrix (1–5 or 1–10) and weights, no code changes

Asset profiling across four engines

  • Servers classified from installed software, roles, tags, subnet and naming (500+ known apps)
  • Clients inherit their tier from the most-privileged users who log on
  • Identities tiered from the permissions they actually hold, including nested PIM-for-Groups chains
  • MFA, SSPR and passwordless registration per identity
  • Azure resources profiled, with tags inherited from resource group, subscription and management group
  • Public IPs scanned with Shodan for open ports and CVEs, mapped to the owning asset
  • Defender for Cloud recommendations and CVEs collected directly
  • 700+ fields in one queryable Log Analytics table per engine; new fields picked up without a redeploy

Dynamic detection and classification

  • 540+ detection rules and 20+ detection methods - no manual tagging
  • Tier 0–3 model with traceable verdicts: see why every asset got its tier
  • Opt-in AI tiering for unknown Microsoft roles and permissions
  • Your own override rules survive upgrades
  • Broken or unknown rules are reported, never silently skipped
  • Exclude devices by tag, with a report of every excluded asset

Risk Analysis reports

  • 124 ready-made reports across Identity, Azure, Endpoint and Public IP
  • Attack-path reports on Exposure Graph, ranked by the business impact of the target
  • Every finding with tier, risk factors, CMDB context, portal links and MITRE ATT&CK
  • Add, override, narrow or exclude reports per tenant
  • A report that suddenly finds less than last run is flagged

Inputs and enrichment

  • Read-only and agentless: Defender for Endpoint, Exposure Graph, Defender for Identity, Entra, on-prem AD, Azure Resource Graph, Sentinel sign-ins
  • Connector framework: pluggable providers, with Entra and a CMDB CSV import built in
  • CMDB enrichment from a CSV, with a report of unmatched CIs and unmatched assets

Outputs and trend

  • Ranked Excel workbook and an AI-written executive summary email
  • Log Analytics tables, JSON files, and upload to Azure blob or file share
  • Daily Trend rollup, kept for years
  • Azure Monitor Workbook and Power BI dataset refresh (Power BI dashboard in beta)
  • Run-health alerting and a transcript per run

Setup, hosting and operations

  • Browser-based Setup Wizard, or unattended JSON-driven setup; every step safe to re-run
  • Least privilege: Reader plus Contributor on the target subscription, never Owner
  • Runs on a Windows VM or as Azure Container Apps Jobs with auto-scaling
  • Certificate or managed identity - no secrets in config
  • One-command update; optional asset tagging with a WhatIf mode
  • Evidence for NIS2, DORA, ISO 27001 and GDPR Art. 32

Pro10 features

Everything in Community, plus:

One view of every asset

  • Cross-engine correlation: one object id per asset across every engine, stored in SQL
  • Asset properties: a full property pull per asset - opt-in, with a dry run

Connectors

  • ServiceNow CMDB connector: match CIs, and create them behind two explicit switches
  • Plan mode only reports; apply mode writes. ServiceNow credentials stay in Key Vault
  • Vulnerability close-loop to ServiceNow or a SQL database: open, update, close with a reason, reopen
  • Close reasons Remediated, AssetRetired or NoLongerMonitored - a merely missing machine stays open
  • Safety brakes: nothing closes unless the run was complete; caps on closes per run
  • The SQL target keeps an event table of every change

Managed updates and support

  • Ring-based updates: VMs through the private sync; containers built nightly in your own registry, verified, rolled back on failure
  • Support at portal.invardia.com

Coming next

On the roadmap, not in the current release:

  • Management GUI with dashboards and AI trend (planned for v3.1)
  • ServiceNow Vulnerability Response connector
  • ServiceNow incident connector