Corporate asset inventory — managed, monitored, proven

Every asset, provable.

CASSI is a complete inventory management and monitoring platform for corporate assets — laptops, licenses, vehicles, racks and office equipment. Know what you own, who holds it, and prove it all with signed QR counts and an immutable audit trail.

What is CASSI?

One system of record for everything the company owns.

CASSI — Corporate Asset Inventory — replaces spreadsheets and tribal knowledge with a monitored, permissioned, fully audited register of every asset from purchase to disposal.

Know

Every laptop, software license, vehicle and rack in one register — tagged, categorised, and placed by department and location, with purchase value, warranty and end-of-life dates on record.

Prove

Physical counts run against a frozen scope with HMAC-signed QR labels. Discrepancies are classified — missing, moved, condition-changed, unexpected — and export to CSV as auditor-ready evidence.

Act

Assign, return, maintain and retire assets through race-proof transactions. Live analytics surface portfolio value, value-at-risk and warranty windows before they become surprises.

Capabilities

Built for audits, not just storage.

Every feature exists because a spreadsheet failed at it once.

Custody lifecycle

In stock → assigned → maintenance → retired → disposed, with a lost state. Every handover is a transaction with history — never a stale column.

Assign · Return · Retire

Signed QR labels

Every asset carries an HMAC-SHA256-signed label verified in constant time. Forged or tampered scans are rejected on the spot — and rotating the secret retires every printed label instantly.

Tamper-proof

Sweep scanning

Count at warehouse speed: the phone camera stays live, each verified code records instantly with haptic feedback, and duplicate scans are idempotent by design.

Field-first

Blind counts

Anti-fraud mode hides the expected list from counters while they work. What's missing is only revealed after the count closes — the classic control, finally enforced by software.

Anti-fraud

Immutable audit trail

Every mutation writes an append-only log entry with actor, IP and before/after state — protected from deletion even when assets are removed.

SOC 2 friendly

Independence engine

A custodian can count their own asset — but it's flagged self-verified, and CASSI ranks the best independent auditor to re-check it, by department, role and conflicts.

Segregation of duties

Portfolio analytics

Total value, assigned rate, value-at-risk, warranty and end-of-life windows, custody concentration and six months of activity — one dashboard, computed server-side.

Monitoring

Race-proof by test

Row-level locking prevents double-assignment, duplicate tags and custody races — proven by an automated concurrency suite, not promised in a slide.

111 tests green

How a count works

From scope freeze to signed evidence.

  1. 01

    Freeze the scope

    Define the count by location, department or category. On start, the expected asset set is snapshotted — results stay reproducible for auditors even if records change mid-count.

  2. 02

    Sweep with the phone

    Field counters scan continuously — green counts, blue duplicates, amber out-of-scope. Condition and actual location can be captured on the spot. Progress is live for managers.

  3. 03

    Classify every gap

    After close, discrepancies are automatically classified: not found, location mismatch, condition change, unexpected finds and self-verified sightings — colour-coded, exceptions first.

  4. 04

    Export the evidence

    Filter the results any way an auditor asks, then export a CSV with every sighting, flag and outcome — the whole count, signed, sealed and reproducible.

Security & compliance

Designed for the auditors, trusted by IT.

Soft-delete everywhere, RESTRICT-protected audit logs, and no silent logins — the controls SOC 2 and ISO 27001 assessors ask for, shipped as defaults.

Two-factor everywhere

TOTP enrolment with encrypted secrets, single-use recovery codes, and password-plus-code required to switch it off.

Rotating sessions

30-minute access tokens, single-use refresh tokens with replay rejection, and server-side revocation that takes effect on the very next request.

Four-role RBAC

Admins, asset managers, IT admins and read-only viewers — enforced server-side on every route, with viewer scope locked to their own custody.

Lockout & limits

Five failed logins locks the account-and-IP pair for ten minutes. Password changes sign out every other device automatically.

Soft delete, hard evidence

Nothing is ever really erased: deleted assets are tombstoned, and their audit history is protected from removal by database constraint.

Biometric, not careless

Fingerprint or face unlock opens the phone's own session — the server still authorises every request with real tokens. Sign-out removes the enrolment.

Who uses it

One register, four perspectives.

ADMIN

Owns the system: users and roles, departments, locations, soft-delete and the final say on disposals.

ASSET MANAGER

Runs the register day to day: assignments, returns, lifecycle transitions, stocktake sessions and analytics.

IT ADMIN

Keeps hardware and licenses healthy: provisioning, maintenance windows, warranty and end-of-life tracking.

VIEWER

Field counters and asset holders: scan, verify and look up — with their view scoped to their own custody.

Platforms

A console for control. A phone for the field.

Web admin console

Collapsible dark-shell console with the analytics dashboard, full asset CRUD, custody modals, QR label sheets (58×28 mm, 24 per A4), user administration and the stocktake audit dashboard with CSV export.

Android field app

Deliberately audit-only: sweep scanner with live HUD, asset lookup, verify-any-label, biometric unlock and a profile hub for 2FA and sessions. It counts and inspects — it never mutates records.

Put every asset on the record.

See CASSI run a live blind count, sign a QR label, and export auditor evidence — in one walkthrough.