Physical asset audit, v0

Audits shouldn’t take a week
and a clipboard.

Veracrat verifies racks and asset tags with a phone camera, checks them against your existing DCIM in real time, and builds an exportable audit trail as the tech walks the floor. No barcode scanners. No RFID rollout. No new hardware.

AI-assisted — findings are generated by an AI model and must be reviewed by a person before use in an audit. Veracrat is not a certified audit and does not replace one.

~4×
Faster than manual walk
0
New hardware required
SOC 2 · ISO · PCI
Helps assemble your evidence pack
9:41VERACRAT · SCAN◐
U42SVR-4B0
U40SVR-4B1
U38SVR-4B2
U36SVR-4B3
U34R7-A · UNEXPECTED
U32SVR-4B5
U30SVR-4B6
U28SVR-4B7
U26SVR-4B8
U24SVR-4B9
U22SVR-4BA
U20SVR-4BB
Mismatch · U34
RACK R7 · AISLE C 11 / 12 verified
Close-up of a server chassis with status LEDs, cabling, and asset tag
01 · The problem

Physical audits are still done by hand.

SOC 2, ISO 27001, and PCI DSS each expect evidence that the assets in your records are the assets on your floor. In most facilities, that means a tech walking aisles with a spreadsheet, ticking serials, and hoping nothing has moved since the last inventory.

Records drift. Decommissioned hardware lingers. New gear gets racked without a ticket. Auditors flag the discrepancies, remediation takes weeks, and the whole cycle repeats next quarter.

  • Manual walkthroughs, per rack
  • Serial numbers keyed twice
  • Discrepancies found weeks late
  • No audit trail until the report
02 · How it works

A walkthrough, verified as it happens.

No new sensors, no RFID retrofit, no barcode replacement program. The camera does the reading; your DCIM stays the source of truth.

01

Point the phone at a rack

The tech opens Veracrat and frames a rack, an asset tag, or a full aisle. Works with the phone you already carry.

02

AI matches what it sees against your DCIM

Veracrat reads tags, serials, and rack positions and compares them to your records in real time. No batch upload later.

03

Mismatches get flagged in the moment

An unexpected unit, a missing serial, a device in the wrong U — surfaced on the phone before the tech walks away.

04

The audit trail builds itself

Every scan is timestamped and attributed to the technician who ran it. Exportable — clearly labelled as AI-assisted — to support your SOC 2, ISO 27001, or PCI DSS evidence pack.

Wide view of a data center hall, symmetrical aisles of black server cabinets under overhead lighting
Field view

“An auditable floor isn’t a spreadsheet. It’s a timestamped walk through the aisle, signed by the person who did it.”

— Design principle 01

03 · Who it’s for

Built for the people who own the floor.

Colocation operators

Prove tenant asset integrity across cages and suites without a truck roll of scanners.

Enterprise IT

Reconcile your DCIM against reality between quarterly audits, not just at the end.

Managed service providers

Standardize physical verification across every client site with one phone workflow.

ITAD firms

Chain-of-custody evidence from the rack to the shred, captured as the asset moves.

04 · Compliance

Evidence you can assemble as you walk.

Physical asset verification is a named control in SOC 2 (CC6.1), ISO 27001 (A.7.9, A.7.10), and PCI DSS (9.5). Veracrat helps you assemble a timestamped, attributed, exportable trail for those controls — without a separate documentation pass.

Veracrat is not a certification, an attestation, or an auditor. Findings are AI-generated and require human review and sign-off before they are submitted as audit evidence. Acceptance of any artefact is always at your auditor's discretion.

SOC 2ISO 27001PCI DSS
BeforeSpreadsheet · updated Q2
  • SVR-1204 · unverified
  • SVR-1205 · unverified
  • SVR-1206 · unverified
  • SVR-1207 · unverified
  • SVR-1208 · unverified
AfterSigned audit trail
  • SVR-1204 · 09:41:22 · JT
  • SVR-1205 · 09:41:29 · JT
  • SVR-1206 · 09:41:34 · JT
  • SVR-1207 · flagged · JT
  • SVR-1208 · 09:41:47 · JT
Layered on top
Your DCIM
Nlyte · Sunbird · Device42 · Netbox · CSV export
mapped import + reconcile
Veracrat
Phone-camera verification · audit trail
export
Your GRC / ticketing
Vanta · Drata · Jira · ServiceNow
05 · Integration

Sits on your DCIM. Doesn’t replace it.

Veracrat reads the DCIM you already run — Nlyte, Sunbird, Device42, Netbox, or a spreadsheet — through a mapped CSV export, and never writes back to it. Nothing to rip out, nothing to grant write access to. Live two-way connectors are on the roadmap, not shipping today.

Export flows into Vanta, Drata, Jira, or ServiceNow. If it can receive a signed JSON payload, it’s in scope.

06 · Pricing

Priced per facility. Cancel at 30 days.

Pilot pricing is fixed and public. Growth and enterprise scale with sites, not seats. Technicians are unlimited on Growth and above, and every feature listed below ships in the product today unless it says roadmap.

Pilot
$900/ month

One facility. 90-day pilot, cancel anytime.

  • Up to 1 site
  • Up to 5 technicians
  • CSV DCIM import (mapped)
  • Labelled evidence export (CSV)
  • Shared Slack support
Request a pilot
Most common
Growth
$4,900/ month

Multi-site operators running quarterly audits.

  • Up to 8 sites
  • Unlimited technicians
  • Team invites & role control
  • Full audit log & human sign-off
  • Named implementation lead
Request a pilot
Enterprise
Custom

Colo operators, MSPs, and ITAD firms at scale.

  • Unlimited sites
  • Human sign-off & review trail
  • Private cloud deployment (roadmap)
  • Live DCIM connectors (roadmap)
  • MSA · DPA · security review
Talk to us
Auto-renewal terms

Pilot and Growth plans are billed monthly in advance and renew automatically every 30 days at the price shown above until you cancel. Annual billing renews every 12 months. We email a renewal reminder 7 days before every charge. You can cancel in one click from Console → Settings — no email, phone call, or retention flow. Cancelling stops the next charge and you keep access until the end of the period you already paid for. Prices are in USD, exclusive of applicable tax.

08 · Request a pilot

One facility. Thirty days. Real audit evidence at the end of it.

Tell us a little about your environment. We reply within one business day with a read-only connector and a scoped pilot plan — not a sales deck.

  • Mapped CSV import — Veracrat never writes to your DCIM
  • Runs on techs’ existing phones
  • Exportable evidence pack from day one

We’ll only use this to reply about a pilot. No newsletter.