Built for IT teams that answer to auditors
AssetPilot works standalone with its own local login, or delegates identity to your provider; either way it reads only what it needs and keeps a signed record of who did what.
Local login or single sign-on
Sign in with a local AssetPilot account out of the box, or delegate authentication to your identity provider so there are no separate passwords to store and your existing MFA and access policies apply.
Read-only by default
Directory, device and license integrations are read-only by default. AssetPilot never writes back to your source systems unless you explicitly enable it.
Role-based access control
Configurable roles gate every action across your team. End users get a self-service portal scoped to only their own equipment.
Signature-backed audit trail
Check-outs and returns capture an on-screen signature tied to the user, asset and timestamp, a defensible record of custody for audits and disputes.
Least-privilege access
Access is granted explicitly and scoped to exactly what each integration needs, nothing broader.
Self-hosted option
Enterprise can run AssetPilot privately on a Postgres data layer, keeping all asset, license and spend data inside your own boundary.
Your data, your boundary
AssetPilot stores your asset, license and purchasing records in a SQLite or Postgres data layer. Enterprise customers can run the whole platform self-hosted, keeping every record inside their own infrastructure.
- Local login built in, or delegate authentication to your identity provider
- Read-only access to directory, devices and licenses by default
- Role-based controls on every action
- Signed custody records for assets and accessories
- Self-hosted deployment on Postgres for Enterprise
- Secrets (client secrets, API keys) stored server-side only