1. Home
  2. Cybersecurity, Privacy & Compliance
  3. CMDB & IT Asset Discovery Tools

Category · Cybersecurity, Privacy & Compliance Software

CMDB & IT Asset Discovery Tools

Configuration Management Database (CMDB) Tools are designed for IT professionals and organizations looking to streamline their IT infrastructure management. These tools are central to managing and tracking the configuration of IT assets and their relationships within an organization, such as hardware, software, and network components.

3 rankings26 products scored6 criteria eachUpdated Sep 2, 2026
01

Top picks across CMDB & IT Asset Discovery Tools

The highest scorer from each vendor across all 3 rankings. Six little boxes show each one against its ranking average, and the full review sits under each card.

1

ServiceNow

servicenow.com · ServiceNow Configuration Management Database #1 of 6 in Configuration Management Database (CMDB) Tools for Recruitment Agencies

ServiceNow implementation can cost 3 to 5 times the license.

Best forLarge enterprises needing deep ITIL compliance and asset mapping

Quote only enterpriseSOC 2ISO 27001
Top of its ranking

The enterprise CMDB behind the ServiceNow platform, mapping IT assets and services for large organizations.

Standout factHolds over 50% of the global ITSM market, more than double its closest rival businesswire.com
Biggest catchImplementation services often cost 3 to 5 times the annual license fee. rezolve.ai
50%+global ITSM market sharebusinesswire.com
9 yearsGartner Leader streakeesel.ai

Standout number

50%+global ITSM market share

Source: businesswire.com

True monthly cost

Typical total cost, annual license vs implementation

Annual license1x
Implementation and training3x-5x
Total3x-5x license fee

Implementation is separate from license cost

Upside

  • 50%+ global ITSM market share
  • Gartner Leader for 9 years
  • Service Graph plug-and-play connectors

Catch

  • Implementation costs 3-5x license
  • Charges for approver-only roles
  • Steep learning curve for admins
Pick it ifLarge enterprises needing deep ITIL compliance and asset mapping
Skip it ifSMBs without dedicated administrators to maintain data
PricingCustom quote, implementation typically 3-5x annual license

Editor's takeServiceNow's CMDB holds more than half the global ITSM market, over double its nearest competitor, and Gartner has named it a Leader nine years running. Service Graph Connectors turned what used to be custom-coded data ingestion into a certified, plug-and-play process across hundreds of third-party tools. The real cost sits in implementation, though. Consultants and training commonly run 3 to 5 times the annual license fee, and the platform even charges for stakeholder roles that only approve requests.

How much does ServiceNow CMDB implementation typically cost?

Implementation, consultants, and training often cost 3 to 5 times the annual software license fee, according to pricing guide sources, on top of the license itself, which requires a custom quote.

Does ServiceNow charge for approval-only users?

Yes. ServiceNow often charges for Business Stakeholder licenses, meaning users who only approve requests but don't work tickets still incur a cost, unlike many competitors.

The evidence: 5 criteria, 3 penalties
9.6
Product Capability & DepthLooked for: We evaluate the database's ability to automatically discover assets, map complex dependencies, and maintain a single source of truth for IT infrastructure.ServiceNow CMDB offers industry-leading automated discovery, service mapping, and a standardized Common Service Data Model (CSDM) that connects infrastructure to business outcomes.servicenow.comfaddom.complat4mation.com
9.9
Market Credibility & Trust SignalsLooked for: We assess market share, analyst recognition, and adoption rates among large enterprises to determine the product's reliability and industry standing.ServiceNow is the undisputed category leader, holding over 50% market share and recognized as a Gartner Magic Quadrant Leader for ITSM for nine consecutive years.gartner.comeesel.aibusinesswire.com
8.8
Usability & Customer ExperienceLooked for: We examine the user interface, ease of configuration, and the learning curve required to effectively manage and visualize complex data.While powerful, the platform has a steep learning curve; however, the new CMDB Workspace and 'Intelligent Search' features have significantly modernized the user experience.docs.servicenow.comassetloom.comcrm.org
8.2
Value, Pricing & TransparencyLooked for: We analyze pricing structures, hidden costs, and the total cost of ownership relative to the features provided.Pricing is opaque and expensive, with high implementation costs (3x-5x license fees) and extra charges for 'approver' roles, making it viable primarily for large enterprises.rezolve.airezolve.ai
9.5
Data Integrity & Health ManagementLooked for: We look for the breadth of third-party connectors and the ease of ingesting data from external monitoring, security, and cloud tools.The Service Graph Connector program offers hundreds of certified, 'plug-and-play' integrations that standardize external data ingestion, solving a major legacy CMDB pain point.kanini.comkanini.comdev-hd.com

Score adjustments−0.17 points in total

−0.06Implementation costs are exceptionally high, often ranging from 3x to 5x the annual software license fee.rezolve.ai · severity 85/100
−0.07The platform has a steep learning curve and can become an 'administrative nightmare' if not actively maintained by skilled professionals.crm.org · severity 65/100
−0.04The licensing model includes an 'approver tax,' charging for business stakeholders who only need to approve requests but do not work on tickets.rezolve.ai · severity 50/100
2

Armis

armis.com · Armis CMDB Enrichment #1 of 10 in Configuration Management Database (CMDB) Tools for SaaS Companies

Armis finds hidden devices, ServiceNow buys it for $7.75B

Best forEnterprises with IoT, OT, or medical devices needing agentless asset visibility.

Quote only FedRAMPSOC 2IL authorized
Top of its ranking

Agentless discovery that enriches CMDBs like ServiceNow with real-time IT, OT, and IoT asset data.

Standout factServiceNow agreed to acquire Armis for $7.75 billion in cash. investor.servicenow.com
Biggest catchPricing is sold in opaque Asset Blocks, and add-on modules can raise costs fast. intuitionlabs.ai
$7.75BServiceNow acquisition priceinvestor.servicenow.com
up to 48 hrsSupport response timeg2.com
9.0/10Overall score

Standout number

$7.75BServiceNow acquisition price

Source: investor.servicenow.com

Compliance

✓ FedRAMP✓ IL authorized✓ SOC 2? HIPAA? GDPR

Source: media.armis.com

Upside

  • Agentless discovery of IT, OT, and IoT
  • Real-time ServiceNow CMDB enrichment
  • FedRAMP and IL authorized

Catch

  • Asset Block pricing stays unpublished
  • Add-on modules raise total cost
  • Setup and integration can be complex
Pick it ifEnterprises with IoT, OT, or medical devices needing agentless asset visibility.
Skip it ifSmall businesses wanting a simple helpdesk or basic asset tracker.
PricingEnterprise pricing, sold in Asset Blocks, quote required.

Editor's takeServiceNow agreed to acquire Armis for $7.75 billion in cash, validating its asset discovery technology. Armis finds managed, unmanaged, and IoT devices without agents, then deduplicates and pushes clean data into CMDBs like ServiceNow. Pricing is sold in undisclosed Asset Blocks, and add-on modules can raise the total cost.

How much does Armis CMDB Enrichment cost?

Pricing is not published. Armis sells subscriptions in 'Asset Blocks' and requires a custom quote, with add-on modules adding to the total cost.

Is Armis being acquired by ServiceNow?

Yes. ServiceNow agreed to acquire Armis for $7.75 billion in cash to expand cyber exposure and security coverage across IT, OT, and medical devices.

The evidence: 6 criteria, 3 penalties
9.2
Product Capability & DepthLooked for: We evaluate the solution's ability to discover, classify, and enrich asset data across diverse environments (IT, OT, IoT) without relying on agents.Armis provides agentless, passive discovery that identifies managed, unmanaged, and IoT devices, automatically normalizing and deduplicating data to enrich CMDBs like ServiceNow in real-time.armis.comarmis.cominsider.govtech.com
9.8
Market Credibility & Trust SignalsLooked for: We look for industry recognition, acquisition interest from major players, and validation from top analyst firms.ServiceNow has agreed to acquire Armis for $7.75 billion, and Gartner named it a Leader in the 2025 Magic Quadrant for CPS Protection Platforms.investor.servicenow.comarmis.com
8.8
Usability & Customer ExperienceLooked for: We assess ease of deployment, interface intuitiveness, and the quality of customer support based on user feedback.Users praise the intuitive interface and visibility but note that initial setup and integration configuration can be complex and sometimes difficult.armis.comg2.comg2.com
8.2
Value, Pricing & TransparencyLooked for: We look for clear pricing models, transparent costs, and value justification for the investment.Pricing is opaque, enterprise-focused, and based on 'Asset Blocks', with users noting that add-on modules can make it expensive for smaller organizations.armis.comintuitionlabs.aig2.com
9.5
Integrations & Ecosystem StrengthLooked for: We evaluate the depth and breadth of integrations with ITSM, SIEM, and other security tools.Armis features a robust Service Graph Connector for ServiceNow and integrates with hundreds of IT and security tools (Splunk, Jira, etc.) to fetch and push context.armis.comarmis.comgartner.com
9.3
Security, Compliance & Data ProtectionLooked for: We check for certifications (FedRAMP, etc.) and capabilities that support regulatory compliance (HIPAA, GDPR).The platform is FedRAMP and IL authorized, supports HIPAA/GDPR compliance, and includes vulnerability prioritization to reduce risk exposure.armis.commedia.armis.comintuitionlabs.ai

Score adjustments−0.14 points in total

−0.04Users report that add-on modules and the base cost can be prohibitively expensive, particularly for smaller organizations.gartner.com · severity 60/100
−0.05Multiple reviews cite difficulties with initial setup and integration configuration, describing them as complex or 'clunky'.g2.com · severity 50/100
−0.05Some users experience delays in support response times, noting it can take up to 48 hours for email responses.g2.com · severity 45/100
3

Atlassian Assets

atlassian.com · Atlassian CMDB #2 of 6 in Configuration Management Database (CMDB) Tools for Recruitment Agencies

Atlassian Assets caps unique constraints at 2 per object

Best forTeams already using Jira Service Management wanting flexible asset tracking.

Quote only SOC 2HIPAAJira integration
#2 in its ranking

Open-structure CMDB built into Jira Service Management, with 30+ native import adapters.

Standout factIncludes 50,000 free Assets objects on JSM Premium plans. stratacominc.com
Biggest catchA new limit of 2 unique constraints per object type restricts complex data modeling. community.atlassian.com
50,000Free objects includedstratacominc.com
30+Import adaptersatlassian.com
45,000+ITSM customersaety.io

Standout number

50,000free Assets objects on JSM Premium

Source: stratacominc.com

The thing people get wrong

Atlassian Assets has no limits on custom data modeling

A 2024 update capped unique constraints at 2 per object type

Source: community.atlassian.com

Upside

  • Open, flexible data structure
  • 30+ native import adapters
  • 50,000 free objects on Premium

Catch

  • Steep learning curve for admins
  • Only 2 unique constraints allowed
  • Not sold as a standalone tool
Pick it ifTeams already using Jira Service Management wanting flexible asset tracking.
Skip it ifOrganizations needing a standalone CMDB outside Jira Service Management.
PricingIncluded in JSM Premium; objects over 50,000 cost $0.05/object/mo.

Editor's takeAtlassian Assets breaks from rigid legacy CMDBs with an open data structure that tracks hardware, software, or even office furniture. JSM Premium plans include 50,000 objects free, with overage priced at $0.05 per object monthly. The tradeoff is complexity. Reviewers consistently describe a steep learning curve, and a new limit of 2 unique constraints per object type restricts some data models.

Is Atlassian Assets a standalone CMDB?

No. It ships inside Jira Service Management Premium and Enterprise plans and is not sold as a separate product.

How many free objects does Atlassian Assets include?

JSM Premium plans include 50,000 objects at no extra cost. Objects beyond that limit cost $0.05 per object per month.

The evidence: 6 criteria, 3 penalties
9.0
Product Capability & DepthLooked for: We evaluate the flexibility of the data model, asset discovery features, and the ability to map complex dependencies within the CMDB.Atlassian Assets provides an open data structure allowing teams to track any resource type (hardware, software, people) with unlimited custom attributes, though recent updates have placed limits on unique constraints.atlassian.comatlassian.comatlassian.com
9.4
Market Credibility & Trust SignalsLooked for: We look for industry analyst recognition, market share, and adoption rates among enterprise organizations.Atlassian is recognized as a Leader in the Gartner Magic Quadrant for IT Service Management Platforms and serves over 45,000 customers with its ITSM solutions.aety.ioaety.io
8.4
Usability & Customer ExperienceLooked for: We assess the ease of setup, user interface intuitiveness, and the learning curve for new administrators.While powerful, the platform is frequently cited in reviews for having a steep learning curve and a complex user interface that requires training to navigate effectively.atlassian.comg2.comg2.com
8.7
Value, Pricing & TransparencyLooked for: We analyze the pricing model, inclusion of features in specific plans, and any hidden costs for scaling.Assets is included in JSM Premium and Enterprise plans with a generous free limit of 50,000 objects, though consumption-based pricing applies for objects exceeding this limit.atlassian.comstratacominc.comstratacominc.com
9.5
Integrations & Ecosystem StrengthLooked for: We examine the availability of import adapters, API quality, and native connections to other IT tools.The platform boasts over 30 native import adapters for major tools like AWS, Azure, and SCCM, and offers seamless integration with the broader Atlassian suite (Jira, Confluence).atlassian.comconfluence.atlassian.com
9.6
Security, Compliance & Data ProtectionLooked for: We verify certifications like SOC 2, ISO 27001, and HIPAA compliance capabilities for enterprise data.Atlassian maintains rigorous compliance standards including SOC 2 Type II, ISO 27001, and supports HIPAA compliance with a Business Associate Agreement (BAA) on Enterprise plans.atlassian.comkeragon.com

Score adjustments−0.16 points in total

−0.06Users consistently report a steep learning curve and complex UI, requiring significant training for effective use.g2.com · severity 60/100
−0.04Consumption-based pricing applies after 50,000 objects, costing $0.05 per object monthly, which can impact scalability for large enterprises.stratacominc.com · severity 50/100
−0.06A hard limit of 2 unique constraints per object type was introduced, restricting complex data modeling capabilities.community.atlassian.com · severity 45/100
4

Device42

device42.com · Device42 CMDB #3 of 6 in Configuration Management Database (CMDB) Tools for Recruitment Agencies

Freshworks paid $230M for it, pricing gets modular

Best forEnterprises with complex hybrid IT needing granular dependency mapping and discovery.

From $1,449 per year SOC 2enterpriseagentless discovery
#3 in its ranking

Agentless CMDB with deep dependency mapping across hybrid IT, recently acquired by Freshworks.

Standout factFreshworks acquired Device42 for $230 million in May 2024. cmswire.com
Biggest catchCore features like Application Dependency Mapping and Power Monitoring cost extra on top of the base license. g2.com
$230MAcquisition price by Freshworkscmswire.com
800+ in 70+ countriesCustomers servedfaddom.com
~$1,449/yrEntry pricing, 1-100 devicesvirima.com

Standout number

$230MFreshworks acquisition price, May 2024

Source: cmswire.com

Starting price

$1,449/yrCore license, 1-100 devices, add-ons priced separately

Upside

  • Agentless discovery for hybrid IT
  • Deep application dependency mapping
  • High-quality support, rated 9.5/10 on G2

Catch

  • Steep learning curve for beginners
  • Performance lag with large datasets
  • Modular pricing increases total cost
Pick it ifEnterprises with complex hybrid IT needing granular dependency mapping and discovery.
Skip it ifSmall organizations with simple, cloud-only environments needing basic asset tracking.
PricingFrom ~$1,449/yr for 1-100 devices, add-ons cost extra

Editor's takeDevice42 converges CMDB, IPAM, and DCIM into one agentless discovery platform covering physical, virtual, and cloud assets. Freshworks validated its enterprise value by acquiring it for $230 million in May 2024, and it counts UCLA and Coca-Cola as customers. Base licensing starts near $1,449 a year for 100 devices, but features like dependency mapping and power monitoring are priced as separate add-ons, which can complicate budgeting.

How much does Device42 cost?

Core licensing starts around $1,449 a year for up to 100 devices, per Virima's pricing breakdown. Add-on modules like Application Dependency Mapping and Power Monitoring are priced separately from the Core license, according to G2's pricing page, which can raise total cost.

Why did Freshworks acquire Device42?

Freshworks bought Device42 for $230 million in May 2024 to strengthen its IT asset management capabilities, according to CMSWire's coverage of the deal. It signals a strategic move by Freshworks toward deeper backend infrastructure tools.

The evidence: 6 criteria, 3 penalties
9.4
Product Capability & DepthLooked for: We evaluate the comprehensiveness of asset discovery, dependency mapping, and the ability to manage hybrid infrastructure (on-prem, cloud, and virtual) in a single view.Device42 delivers a unified platform combining CMDB, IPAM, and DCIM capabilities with agentless discovery that covers physical, virtual, and cloud assets. It features advanced application dependency mapping, power monitoring, and SSL certificate management, providing a granular 'single source of truth' for complex IT estates.device42.comdevice42.comnetworkworld.com
9.3
Market Credibility & Trust SignalsLooked for: We assess the vendor's market standing, acquisition history, customer base quality, and third-party validation from major industry analysts or platforms.Device42 was acquired by Freshworks for $230 million in 2024, validating its technology and market value. It serves over 800 customers in 70+ countries, including major enterprises like Coca-Cola and UCLA, and maintains high ratings (4.7/5) on major review platforms.cmswire.comfaddom.com
8.7
Usability & Customer ExperienceLooked for: We examine user feedback regarding interface design, ease of implementation, learning curve, and the quality of technical support.While users praise the depth of data and excellent support (rated 9.5/10 on G2), the platform is frequently cited as having a steep learning curve and complex interface. Some users report performance latency when processing very large datasets.virima.comg2.com
8.6
Value, Pricing & TransparencyLooked for: We analyze pricing structures, transparency of costs, and the balance between price and features compared to market alternatives.Device42 operates on a tiered annual subscription model based on device count, starting at ~$1,449 for up to 100 devices. While base tiers are known, the modular pricing strategy (extra costs for dependency mapping or power monitoring) can complicate budget forecasting.device42.comvirima.comg2.com
9.1
Integrations & Ecosystem StrengthLooked for: We evaluate the breadth of pre-built connectors, API quality, and compatibility with major ITSM, automation, and DevOps tools.The platform boasts a robust ecosystem with native integrations for major tools like Jira, ServiceNow, Ansible, Chef, and Puppet. It offers a comprehensive RESTful API and webhooks, allowing it to serve as a central data engine for automation workflows.device42.comdevice42.comdocs.device42.com
9.0
Security, Compliance & Data ProtectionLooked for: We look for security certifications (SOC2), deployment flexibility (on-prem vs. cloud), and features that support governance and audit readiness.Device42 supports both on-premise and cloud deployments, catering to high-security environments. It holds SOC2 attestation, performs annual penetration tests, and includes enterprise password management features with granular permission controls.device42.comvendr.comgoworkwize.com

Score adjustments−0.14 points in total

−0.06Users report performance latency and system slowdowns when processing large datasets or extensive requests.g2.com · severity 60/100
−0.05New users frequently cite a steep learning curve due to the complex interface and depth of features.virima.com · severity 50/100
−0.03Core features such as Application Dependency Mapping and Power Monitoring are sold as separate add-on modules, increasing total cost of ownership.g2.com · severity 40/100
5

Alloy Navigator

alloysoftware.com · Alloy CMDB Software #2 of 10 in Configuration Management Database (CMDB) Tools for SaaS Companies

Alloy Navigator publishes pricing at $19-$86 per tech monthly

Best forOrganizations needing combined ITSM and network inventory in one tool.

From $19 per user/mo SOC 2FIPS 140-2free trial
#2 in its ranking

Unified ITSM and ITAM platform with agentless network discovery and a built-in CMDB.

Standout factPricing is published openly, from $19 to $86 per technician monthly. alloysoftware.com
Biggest catchThe mobile app is functional but limited, according to user reviews. g2.com
$19/tech/moExplorer plan pricealloysoftware.com
$86/tech/moEnterprise plan pricealloysoftware.com
3,000+Zapier app connectionsalloysoftware.com

Plans

Explorer$19/tech/mo
Professional$49/tech/mo

Source: alloysoftware.com

In their words

“Users found the initial setup confusing, but customer support ultimately resolved the issues for a better experience.”

g2.com

Upside

  • Published pricing, $19-$86/tech/mo
  • Agentless network discovery included
  • SOC 2 Type II, FIPS 140-2

Catch

  • Steep learning curve to set up
  • Mobile app called limited
  • Slower with large data sets
Pick it ifOrganizations needing combined ITSM and network inventory in one tool.
Skip it ifTeams wanting a lightweight, purely cloud-native modern SaaS tool.
PricingFrom $19/tech/month (Explorer) to $86/tech/month (Enterprise).

Editor's takeAlloy Navigator publishes its pricing outright, from $19 to $86 per technician monthly, a rarity among CMDB tools that usually require a sales call. It combines ITSM, ITAM, and CMDB with agentless SNMP and WMI discovery, and holds SOC 2 Type II plus FIPS 140-2 certification. Setup is the rough patch. Reviewers describe initial configuration as confusing, and the mobile app trails the desktop experience.

Does Alloy Navigator publish its pricing?

Yes. Tiers run from $19 per technician monthly for the Explorer plan up to $86 for Enterprise, listed directly on the pricing page.

Does Alloy Navigator require agents for discovery?

No. It uses agentless network discovery over SNMP and WMI protocols to inventory hardware and software without installing anything on each device.

The evidence: 6 criteria, 3 penalties
8.9
Product Capability & DepthLooked for: We evaluate the breadth of configuration management features, including asset discovery, dependency mapping, and integration with ITSM workflows.Alloy Navigator combines ITSM and ITAM with a robust CMDB that features agentless network discovery, automatic dependency mapping, and comprehensive asset lifecycle management from procurement to retirement.alloysoftware.comalloysoftware.comalloysoftware.com
9.2
Market Credibility & Trust SignalsLooked for: We assess the vendor's industry standing, years in operation, third-party validations, and customer sentiment regarding reliability.Established in 2002, Alloy Software has achieved SOC 2 Type II certification and consistently ranks as a High Performer in G2 reports, demonstrating long-term stability and verified security practices.alloysoftware.comalloysoftware.comalloysoftware.com
8.7
Usability & Customer ExperienceLooked for: We analyze user feedback on interface design, ease of setup, mobile accessibility, and the quality of customer support.While users praise the desktop interface and responsive support, there are documented complaints regarding a steep learning curve for initial setup and limitations within the mobile application interface.g2.comg2.com
9.5
Value, Pricing & TransparencyLooked for: We examine the availability of public pricing, contract terms, and the overall cost-to-value ratio compared to industry standards.Alloy Software provides exceptional transparency by publicly listing per-technician pricing tiers ($19, $49, $86/month) and offering a free trial, which is rare for enterprise-grade CMDB solutions.alloysoftware.comalloysoftware.comalloysoftware.com
8.8
Integrations & Ecosystem StrengthLooked for: We evaluate the availability of APIs, pre-built connectors, and compatibility with standard IT infrastructure tools.Alloy offers a comprehensive REST API, native integrations for Microsoft Endpoint Manager and AD, and connectivity via Zapier to over 3,000 apps.alloysoftware.comalloysoftware.comalloysoftware.com
9.3
Security, Compliance & Data ProtectionLooked for: We verify the presence of critical security certifications, data encryption standards, and compliance with regulations like GDPR and HIPAA.The platform is SOC 2 Type II certified and compliant with FIPS 140-2, HIPAA, and GDPR, utilizing AWS data centers with AES-256 encryption.alloysoftware.comalloysoftware.com

Score adjustments−0.15 points in total

−0.06Multiple reviews indicate a steep learning curve and complex initial setup process that often requires extensive customization or training.g2.com · severity 60/100
−0.05Users report the mobile application interface is limited, lacks desired AI features, and can be difficult to navigate compared to the desktop version.g2.com · severity 50/100
−0.04Some users have experienced performance slowdowns when pulling up large ticket histories or reports.g2.com · severity 30/100
6

FNT Command

fntsoftware.com · FNT's CMDB Solution #3 of 10 in Configuration Management Database (CMDB) Tools for SaaS Companies

FNT's CMDB models 75,000 parts, prices per module

Best forData centers and telecoms needing a physical infrastructure digital twin

From $100 per user/mo Digital Twinmodular licensingdata center visualization
#3 in its ranking

Visual CMDB and Digital Twin platform with a library of 75,000+ components and modular, pay-for-what-you-use licensing.

Standout factFNT's component library includes more than 75,000 predefined devices in photorealistic representation. fntsoftware.com
Biggest catchUsers report having to right-click every time to perform actions, and top-level icons are not well labeled. gartner.com
75,000+Component libraryfntsoftware.com
1,600+API function callstotaltele.com

Standout number

75,000+predefined components in FNT's library

Source: fntsoftware.com

Starting price

€100/userModular licensing; subscription or perpetual options

Upside

  • 75,000+ component library, photorealistic
  • Modular, pay-for-what-you-use licensing
  • 2D/3D Digital Twin visualization

Catch

  • UI needs frequent right-clicking
  • Icons reported as poorly labeled
  • Lower market mindshare than leaders
Pick it ifData centers and telecoms needing a physical infrastructure digital twin
Skip it ifPure SaaS companies with no physical infrastructure to manage
PricingModular pricing, from about €100/user

Editor's takeFNT Command's standout is its Digital Twin approach, modeling racks, cabling, and cooling in 2D and 3D with a library of over 75,000 predefined, photorealistic components. Licensing is modular, so buyers pay only for the modules they use, with third-party listings suggesting an entry point near €100 per user. The interface draws specific complaints, with reviewers noting they have to right-click for actions and that top icons aren't well labeled.

How is FNT Command priced?

Licensing is modular, so customers pay only for the functions they select, with both subscription and perpetual license options. Third-party listings suggest an entry price around €100 per user.

What is FNT's Digital Twin feature?

It's a 2D and 3D visualization of racks, rooms, and floor space, which can integrate with thermal simulation tools like 6SigmaDCX to model heat flow and air circulation.

The evidence: 6 criteria, 2 penalties
9.2
Product Capability & DepthLooked for: We evaluate the breadth of configuration item (CI) management, relationship mapping, and the ability to handle complex hybrid infrastructures.FNT Command offers a comprehensive 'Digital Twin' approach with a library of over 75,000 predefined components, supporting full signal tracing and 2D/3D visualization of assets.fntsoftware.comfntsoftware.comfntsoftware.com
8.8
Market Credibility & Trust SignalsLooked for: We assess the vendor's longevity, customer base, and reputation among enterprise clients in the IT infrastructure space.FNT has over 25 years of experience and serves major enterprise clients like Audi, Fraport, and Colt, though it holds a smaller market mindshare compared to mass-market leaders.fntsoftware.comfntsoftware.comfntsoftware.com
8.4
Usability & Customer ExperienceLooked for: We examine user interface design, ease of navigation, and the efficiency of daily workflows for IT administrators.While generally regarded as user-friendly and easy to configure, specific user feedback highlights interface inefficiencies like frequent right-clicking and unclear icon labeling.fntsoftware.comgartner.comg2.com
8.6
Value, Pricing & TransparencyLooked for: We look for flexible licensing models, modularity, and transparent cost structures that align with usage.FNT offers a highly modular pricing model where customers only pay for needed functions, with both subscription and perpetual license options available.fntsoftware.comfntsoftware.comgetapp.com
9.1
Integrations & Ecosystem StrengthLooked for: We evaluate the ability to ingest data from diverse sources and connect with external IT management systems.The FNT IntegrationCenter and StagingArea provide powerful graphical ETL capabilities, supported by a REST API with over 1,600 function calls.fntsoftware.comtotaltele.comtotaltele.com
9.3
Data Center Visualization & Digital TwinLooked for: We assess the depth of physical infrastructure visualization, including 2D/3D modeling and environmental monitoring.FNT Command excels with 2D/3D footprint views and integration with thermal simulation tools like 6SigmaDCX for predictive modeling.fntsoftware.comfntsoftware.comdcimnews.wordpress.com

Score adjustments−0.08 points in total

−0.05Users have reported interface inefficiencies, specifically the need to 'right-click every time' to perform actions and that top-level icons are not well labeled, leading to navigation friction.gartner.com · severity 45/100
−0.03FNT Command holds a lower market mindshare (approx. 2.9%) in the DCIM/CMDB space compared to dominant competitors, which may impact the availability of community resources.peerspot.com · severity 30/100
02

Every ranking in CMDB & IT Asset Discovery Tools

Each card shows the top three. The eye opens a quick look. Open a ranking for every product, the evidence and the comparison table.

1 ServiceNowServiceNow implementation can cost 3 to 5 times the license. 9.1/10
Visit ↗
2 Atlassian AssetsAtlassian Assets caps unique constraints at 2 per object 8.9/10
Visit ↗
3 Device42Freshworks paid $230M for it, pricing gets modular 8.9/10
Visit ↗
See all 6 ranked
1 ArmisArmis finds hidden devices, ServiceNow buys it for $7.75B 9.0/10
Visit ↗
2 Alloy NavigatorAlloy Navigator publishes pricing at $19-$86 per tech monthly 8.9/10
Visit ↗
3 FNT CommandFNT's CMDB models 75,000 parts, prices per module 8.8/10
Visit ↗
See all 10 ranked
1 ServiceNowServiceNow CMDB renews at 98%, implementation costs 3-5x 9.0/10
Visit ↗
2 Alloy NavigatorAlloy Navigator prices transparently, but the learning curve is steep 8.8/10
Visit ↗
3 Atlassian AssetsAtlassian Assets charges $0.05 per object past 50,000. 8.8/10
Visit ↗
See all 10 ranked
03

About CMDB & IT Asset Discovery Tools

What the category is, how it developed, and what to look for. Two minutes, or the long read.

This category covers software designed to identify, catalog, and map the relationships between an organization's technology assets, creating a centralized "system of record" for IT infrastructure. It focuses on two distinct but interlocking functions: Discovery, which automatically scans networks to detect hardware, software, and cloud instances; and the Configuration Management Database (CMDB), which stores this data and maps the dependencies (relationships) between these items. It sits between IT Service Management (ITSM) (which consumes this data for incident and change management) and IT Asset Management (ITAM) (which focuses on the financial and contractual lifecycle of these assets). This category includes both general-purpose enterprise platforms and specialized discovery tools for niche environments like cloud infrastructure, operational technology (OT), or remote endpoints.

Read the full category guide

What Is CMDB & IT Asset Discovery?

Organizations use these tools to solve the "visibility gap"—the operational blindness that occurs when IT teams do not know what assets they own, how they are configured, or how they interact. Without a functional CMDB, a server failure is an isolated event; with one, it is an immediate signal that a specific business service, payroll application, or customer portal is at risk. It transforms raw inventory lists into a multidimensional map of the IT estate, enabling teams to assess the downstream impact of changes, resolve incidents faster, and prove compliance with regulatory frameworks.

History of CMDB & IT Asset Discovery Tools

The modern concept of the CMDB emerged in the late 1990s and early 2000s, driven largely by the widespread adoption of the IT Infrastructure Library (ITIL) framework. In this era, IT environments were predominantly on-premise and static. The gap that created this category was the inability of simple spreadsheet-based inventory tracking to handle the increasing complexity of client-server architectures. Early tools were essentially static repositories—digital filing cabinets where IT staff manually entered configuration items (CIs). The expectation was simple: "Give me a database where I can log my servers."

By the late 2000s, virtualization shattered the static model. Servers became files that could move or duplicate instantly, rendering manual updates impossible. This forced a market consolidation where large ITSM platform vendors acquired specialized discovery technologies to automate data ingestion. The buyer expectation shifted from "give me a database" to "give me automated visibility."

The 2010s introduced the cloud and DevOps era, which fundamentally broke traditional CMDB models again. Assets became ephemeral—spinning up and down in minutes. The rise of vertical SaaS further fragmented data, as critical configuration data now lived outside the corporate firewall. Today, the market has evolved into "Cyber Asset Attack Surface Management" (CAASM) and real-time observability. Modern buyers no longer want just a repository; they demand actionable intelligence that correlates infrastructure data with security risks, costs, and business outcomes in near real-time.

What to Look For

Evaluating CMDB and asset discovery tools requires looking beyond the sheer number of features to the quality and context of the data they provide. The primary criterion is the breadth and depth of discovery methods. A robust tool must offer agentless scanning (for minimal friction) and agent-based options (for deep, continuous monitoring of remote endpoints), alongside API integrations for cloud resources. If a tool relies solely on one method, it will likely leave blind spots in hybrid environments.

Reconciliation capabilities are equally critical. In modern environments, a single asset might be reported by a hypervisor, a security scanner, and a cloud console. A superior tool uses a sophisticated identification and reconciliation engine (IRE) to merge these conflicting inputs into a single "golden record," preventing duplicate entries that corrupt data integrity. Look for tools that allow you to define hierarchy rules—for instance, trusting the cloud provider for the IP address but the endpoint agent for the software version.

Red flags include vendors who promise "instant" implementation without discussing data governance. A tool that ingests everything without filtering creates a "data swamp"—a noisy, unusable mess of irrelevant data (like individual printer queues or temporary browser files). Another warning sign is a lack of support for custom configuration items (CIs). Every business has unique assets, whether they are medical devices or proprietary manufacturing equipment; rigid data models that cannot accommodate these are a liability.

Key questions to ask vendors include:

  • "How does your system handle ephemeral assets that exist for less than an hour—are they purged or archived, and how does that impact license counts?"
  • "Can you demonstrate how the system maps a dependency between an on-premise database and a cloud-based front-end application without manual intervention?"
  • "What is the mechanism for retiring stale assets, and can we automate the decommissioning workflow based on inactivity?"

Industry-Specific Use Cases

Retail & E-commerce

For retailers, the CMDB must manage a highly distributed edge environment. The critical assets here are not just datacenter servers, but thousands of Point of Sale (POS) terminals, kiosks, handheld scanners, and digital signage players spread across hundreds of physical locations. Bandwidth at these edge locations is often limited, so discovery tools must be optimized to transmit low-volume differential updates rather than full scans that clog the network [1]. Evaluation priorities include robust offline capabilities—tracking assets that may drop off the network frequently—and the ability to map logical groupings by store ID or region to support rapid field service responses.

Healthcare

Healthcare organizations face the unique challenge of the Internet of Medical Things (IoMT). Standard IT discovery scans can be dangerous here; an active probe pinging a connected infusion pump or MRI machine could disrupt its operation, posing patient safety risks. Therefore, healthcare buyers prioritize passive network monitoring tools that listen to traffic to identify devices without querying them directly. Security is paramount, with a specific focus on identifying devices running outdated operating systems (common in medical hardware) to mitigate ransomware risks. According to Cynerio, 53% of connected medical devices contain critical vulnerabilities, making visibility a patient safety issue [2].

Financial Services

In financial services, the CMDB is a compliance engine. The focus is heavily on regulatory audit trails (e.g., SOX, PCI-DSS, DORA) and managing "configuration drift" in high-frequency trading platforms or core banking systems. These buyers need tools that snapshot configurations at precise points in time to prove that a specific server was patched and secure during a specific transaction window. Integration with Governance, Risk, and Compliance (GRC) platforms is a non-negotiable requirement, allowing the CMDB to automatically flag assets that fall out of compliance with encryption or access control standards [3].

Manufacturing

Manufacturers deal with the convergence of IT and Operational Technology (OT). Their environment includes Programmable Logic Controllers (PLCs), SCADA systems, and industrial robots that communicate over proprietary protocols like Modbus or Profibus [4]. A generic IT discovery tool will fail to interpret these devices or, worse, crash a production line. Consequently, manufacturing buyers look for specialized OT discovery capabilities that understand industrial protocols and can map the physical relationship between a controller and the machinery it operates, bridging the gap between the factory floor and the corporate network.

Professional Services

For law firms, consultancies, and agencies, the asset landscape is dominated by high-mobility end-user devices and software licenses. The priority is software license optimization and sensitive data tracking on laptops that rarely connect to a corporate VPN. These firms need strong integration with mobile device management (MDM) solutions to track assets regardless of location. The CMDB here often serves as the backbone for client-billable asset allocation, ensuring that software subscriptions or dedicated hardware purchased for a specific client project are accurately tracked and billed back to that engagement [5].

Subcategory Overview

Configuration Management Database (CMDB) Tools for SaaS Companies SaaS companies operate in a "born-in-the-cloud" environment where traditional infrastructure concepts often don't apply. Unlike general tools that focus on physical servers, this niche prioritizes the mapping of microservices, containers, and API dependencies. A generic tool might see a Kubernetes cluster as a single black box, whereas specialized tools for SaaS environments decompose that cluster into pods, services, and ingress controllers, mapping them dynamically to the customer-facing applications they support. The specific pain point driving buyers here is the need for SOC 2 and ISO 27001 compliance in a fluid environment; auditors require proof of change management across ephemeral assets that exist for minutes. For a deeper look at how these tools handle compliance in cloud-native stacks, see our guide to Configuration Management Database (CMDB) Tools for SaaS Companies.

Configuration Management Database (CMDB) Tools for Staffing Agencies Staffing agencies face a logistical nightmare: a high volume of hardware being constantly shipped to and retrieved from temporary remote workers. Generic tools typically assume an asset belongs to a corporate network, but staffing tools must handle remote lifecycle logistics—tracking a laptop from a warehouse to a contractor's home, monitoring it over the public internet without a VPN, and triggering retrieval workflows upon contract termination. The unique workflow here is "zero-touch" provisioning and reclamation, ensuring that assets are locked or wiped automatically when a placement ends. Buyers choose this niche to avoid the "ghost asset" problem, where unrecovered equipment from short-term contracts creates massive financial leakage. Learn more about these specialized logistics features in our guide to Configuration Management Database (CMDB) Tools for Staffing Agencies.

Configuration Management Database (CMDB) Tools for Recruitment Agencies While similar to staffing, recruitment agencies deal primarily with data assets and candidate information security rather than just hardware logistics. These tools focus heavily on the security posture of the devices accessing the Applicant Tracking System (ATS). The differentiator is the ability to correlate device health (e.g., is the OS patched?) with access privileges to sensitive candidate data (PII/GDPR data). A generic tool might report a vulnerability, but specialized tools for this sector can automatically revoke access to the candidate database until the device is compliant. The specific pain point is the regulatory risk of data breaches via unsecured recruiter endpoints, which can lead to massive fines under GDPR or CCPA. For details on securing candidate data workflows, read our guide to Configuration Management Database (CMDB) Tools for Recruitment Agencies.

Integration & API Ecosystem

The Reality: A CMDB is only as good as the data it ingests. In a modern stack, "discovery" is often less about scanning IP addresses and more about querying APIs from other systems—hypervisors, cloud consoles, MDM platforms, and DevOps pipelines. A robust API ecosystem is the lifeline of a functional CMDB.

Statistic: According to MuleSoft's Connectivity Benchmark Report, the average enterprise now uses 991 different applications, yet only 28% are integrated, creating massive data silos that blind IT teams [6].

Expert Insight: Gartner analysts warn that "80% of data and analytics governance initiatives will fail" by 2027 if they do not focus on business outcomes, highlighting the risk of integrations that pipe in data without a clear purpose or standardization strategy [7].

Scenario: Consider a mid-sized logistics firm with 500 employees using a generic ITSM tool. They integrate their AWS account, their on-premise vCenter, and a separate monitoring tool. Without a sophisticated reconciliation engine, the integration creates three separate records for the same server: one with an AWS instance ID, one with a vCenter VM name, and one with a monitoring agent ID. When that server fails, the Service Desk searches for the VM name but finds no alerts because the monitoring tool is linked to a different record. The integration "worked" technically, but operationally, it broke the incident management workflow, extending the outage by four hours as teams scrambled to correlate the data manually.

Security & Compliance

The Reality: Security teams are increasingly the primary power users of CMDBs. The emergence of the Software Bill of Materials (SBOM) requirement has transformed asset inventory from a "nice to have" to a federal mandate for many sectors. Discovery tools must now peer inside applications to catalog open-source libraries and dependencies.

Statistic: A report by Cynerio found that 53% of connected medical devices in hospitals have known critical vulnerabilities, a stat that directly reflects the failure of asset discovery tools to adequately identify and flag risky endpoints in sensitive environments [2].

Expert Insight: The Cybersecurity and Infrastructure Security Agency (CISA) explicitly positions SBOMs as a "key building block in software security," mandating that organizations move beyond high-level asset lists to granular component inventories to mitigate supply chain risks [8].

Scenario: A SaaS provider for the financial sector undergoes a SOC 2 audit. Their discovery tool identifies all 200 production servers but fails to scan the Docker containers running on them. When a new "Log4j"-style vulnerability hits, the security team queries the CMDB for the vulnerable Java library. The CMDB returns zero results because it only tracks the host OS, not the containerized libraries. The auditor identifies this gap, resulting in a "Qualified Opinion" on the audit report—a red flag that causes two major bank clients to suspend their contracts, costing the firm over $2 million in delayed revenue.

Pricing Models & TCO

The Reality: CMDB pricing is notoriously opaque and complex. The two dominant models are per-node/asset (charging for every discovered device) and per-user/admin (charging for the IT staff managing the tool). Cloud discovery often introduces a third variable: consumption-based pricing, where costs scale with the number of cloud resources (like S3 buckets or Lambda functions) managed.

Statistic: Flexera's State of the Cloud Report consistently highlights that organizations waste an estimated 32% of their cloud spend, a figure that often mirrors the "shelfware" waste in CMDB tooling where companies pay for asset licenses they never actively manage or enrich [9].

Expert Insight: BillingPlatform experts note that enterprise pricing is shifting from simple subscription models to "monetization models" that blend tiered features with usage metrics, warning buyers that a mismatch between the pricing model and their actual usage patterns (e.g., high asset count but low user count) can inflate TCO by 50% or more [10].

Scenario: An IoT startup with 30 employees but 50,000 deployed smart sensors evaluates two vendors. Vendor A charges $50/user/month. Vendor B charges $0.50/asset/month. Vendor A TCO: 5 IT admins * $50 * 12 months = $3,000/year. Vendor B TCO: 50,000 assets * $0.50 * 12 months = $300,000/year. The startup almost signs with Vendor B, seduced by the low per-asset price, until a TCO analysis reveals the massive disparity. Conversely, a law firm with 1,000 lawyers (users) but only 2,000 assets (laptops + servers) would go bankrupt with Vendor A's per-user model if "users" included all employees accessing the service portal, rather than just admins. The devil is in the definition of a "billable unit."

Implementation & Change Management

The Reality: The primary cause of CMDB failure is not software bugs, but "boil the ocean" implementation strategies. Organizations try to map every attribute of every asset from day one, leading to data fatigue and abandonment.

Statistic: Gartner research indicates that 70-80% of CMDB initiatives fail to deliver the expected business value, largely due to a lack of governance and over-ambitious scoping rather than technical deficiencies [11].

Expert Insight: The "Crawl, Walk, Run" maturity model is widely cited by experts at firms like Plat4mation, who advise starting with just "factual data" (hardware/OS) in the Crawl phase before attempting to map complex "services" (business capabilities) in the Walk phase. Skipping directly to service mapping is a recipe for disaster [12].

Scenario: A manufacturing company decides to implement a new CMDB. The project lead insists on importing data from 12 different sources immediately, including spreadsheets, the old legacy ERP, and a new discovery tool. They do not set up reconciliation rules. On Day 1, the CMDB is flooded with 10,000 duplicate records. The server team sees the "garbage data," loses trust in the system, and secretly goes back to maintaining their own Excel sheet. Six months and $150,000 later, the CMDB is accurate but abandoned—a "technical success" but a total functional failure.

Vendor Evaluation Criteria

The Reality: Selecting a vendor is a risk management exercise. The shiniest UI often hides a brittle data model. Buyers must evaluate the vendor's ecosystem sustainability (will they exist in 5 years?) and the flexibility of their data model (can you add a custom field without hiring a consultant?).

Statistic: Poor data quality costs organizations an average of $12.9 million annually, according to Gartner. Vendors must be evaluated not just on how they find data, but on the tools they provide to clean it (deduplication, normalization, and archiving workflows) [13].

Expert Insight: McKinsey warns that legacy system architecture and weak data governance are primary contributors to poor data quality, advising buyers to prioritize vendors that offer "agile, data-centric" approaches to data management rather than rigid, monolithic structures [14].

Scenario: A global retailer evaluates Vendor X. During the demo, Vendor X shows impressive dashboards. However, the buyer asks to see the "normalization" process for software titles. Vendor X admits they rely on raw string matching (e.g., "Adobe Acrobat" and "Acrobat Pro" are treated as different software). The buyer calculates that their team would spend 20 hours a week manually normalizing license data. They pivot to Vendor Y, who demonstrates a built-in content library that automatically standardizes 95% of software titles, saving the equivalent of 0.5 FTE annually.

Emerging Trends and Contrarian Take

Emerging Trends 2025-2026: We are seeing a convergence of FinOps and CMDB. As cloud bills spiral, the CMDB is becoming the financial ledger for IT, correlating technical assets with cloud billing data to provide "unit economics" (e.g., cost per transaction). Additionally, Sustainability Metrics are entering the CMDB schema. Organizations are beginning to track the carbon footprint of individual CIs, with discovery tools estimating energy consumption based on hardware models and utilization rates [15].

Contrarian Take: The "Single Source of Truth" is a dangerous myth. For decades, vendors have sold the CMDB as the one place where all data should live. This is wrong. A modern enterprise is too complex for one database to hold everything. The most successful organizations treat the CMDB as a "Source of Reference," not a source of truth. It should act as a pointer system—telling you that a server exists and linking you to the specialized tools (like the hypervisor or security console) that hold the deep, granular truth. Trying to replicate every byte of data into the CMDB is a fool's errand that guarantees data staleness and performance degradation. As Forrester analyst Charles Betz provocatively stated, "The CMDB is dead; long live the IT management graph," acknowledging that federated data graphs are the only viable future [16].

Common Mistakes

Over-Discovery (The "Data Swamp"): Turning on every possible discovery probe often floods the CMDB with useless data—IP phones, guest Wi-Fi devices, and print queues—that obscure critical infrastructure. Start with server infrastructure and critical network gear; add the rest only when a specific process requires it.

Ignoring the "Human" CI: A server with no owner is an unmanageable risk. A common failure is populating technical data (RAM, CPU) but failing to enforce an "Owner" or "Support Group" field. When that server has a vulnerability, the Service Desk has the data but no one to call.

Set-and-Forget Mentality: Treating discovery as a one-time project rather than a daily operational discipline. Discovery rules need constant tuning as network topologies change. If you don't have a "CMDB Librarian" or equivalent role dedicating time to health checks, the data will degrade by ~2% per month until it is unusable.

Questions to Ask in a Demo

  • Handling Duplicates: "Show me exactly what happens when I deploy a new agent to a server that was already discovered via agentless scan. Does it create a duplicate? How do I merge them?"
  • Cloud Ephemerality: "If an auto-scaling group spins up 50 servers for 2 hours and then terminates them, how does that appear in the CMDB tomorrow? Do I see 50 'retired' records cluttering my view?"
  • Service Mapping: "Do not just show me a pre-built map. Let me give you an entry point (e.g., a web URL) and show me how the tool traverses the network to find the database backend right now."
  • Customization Impact: "If I add 10 custom fields to the 'Server' class today, will that break or complicate the upgrade path for the next version of your software?"
  • API Limits: "Does your cloud discovery respect API rate limits, or will it trigger throttling alerts from AWS/Azure/Google Cloud?"

Before Signing the Contract

Final Decision Checklist:

  • Scope Verification: Does the license count cover non-production environments? Many vendors charge for test/dev assets.
  • Data Retention: Ensure the contract specifies how long historical data is kept. For compliance, you may need 12+ months of history, while standard plans might only offer 90 days.
  • Exit Strategy: If you leave, in what format do you get your data back? A proprietary "backup" file is useless; ensure you can export relationships (not just flat lists) in a standard format like CSV or JSON.

Common Negotiation Points:

  • Asset Buffers: Negotiate a "buffer" of ~10% overage on asset counts so you aren't penalized during seasonal spikes or temporary migrations.
  • Sandbox Environments: Demand a full-feature sandbox environment included in the price for testing discovery updates before they hit production.

Deal-Breakers:

  • No API Access: If you cannot programmatically query the CMDB, walk away. You will eventually need to integrate a custom tool.
  • Proprietary Agents Only: If the tool requires its own agent for everything and cannot ingest data from existing tools (like SCCM or Jamf), deployment will be a nightmare.

Closing

The difference between a failed CMDB implementation and a successful one is rarely the software itself—it is the discipline of the team managing it. Focus on data governance, start small, and prioritize value over volume. If you have specific questions about your environment or need a sounding board for your strategy, feel free to reach out.

Email: albert@whatarethebest.com

04

Research

Original reporting on this corner of the market.

All research

Support centers face 40% annual turnover—more than double the 16% industry average

May 21, 2026

Organizations only recover 57% of data after ransomware attacks hit 41% of systems

May 4, 2026

Only 3% of all published vulnerabilities frequently result in impactful exposure

Apr 22, 2026
05

Questions people ask

Which CMDB & IT Asset Discovery Tools is best?

ServiceNow holds the highest score in the category at 9.1, in Configuration Management Database (CMDB) Tools for Recruitment Agencies. The right pick depends on the ranking that matches your use case, so start with the ranking list above.

Why are there 3 separate rankings?

Buyers in CMDB & IT Asset Discovery Tools have different jobs, so each ranking is scoped to one of them and weights the six criteria for that job. The same product can hold different ranks in different rankings.

How are the scores produced?

Documentation, pricing pages, security pages and third-party reviews are reviewed against six criteria. Each criterion records what was found and links its sources. Penalties pull the score down and are shown with their evidence. Rank follows the score. Full methodology.

06

More in Cybersecurity, Privacy & Compliance

The whole group