Mosaic — asset intelligence
Mosaic brings together the assets and the processes of your IT from over 20 sources into one auditable graph. With a built-in AI layer for correlation and compliance statements. Apache 2.0 foundation, exit-ready, on-premise-capable.

One picture from over 20 sources. Mosaic brings together what usually lives apart: the assets of your IT (systems, applications, owners) and the processes on top of them (tickets, changes, incidents). The data foundation for security and compliance processes — not the processes themselves.
Mosaic is the open-source asset intelligence platform from datatactics. An asset inventory without its processes is just a list; processes without asset context are noise. Mosaic joins both in one graph — searchable from business level down to the single server, every statement traceable to its source. Your security, compliance and risk tools work on reliable data; none of them gets replaced.
What Mosaic does
All sources, one picture. Connects the source systems you already run — inventories, scanners, rating and ticketing systems. New sources are added by configuration, not by a development project; more than 20 standard source types are covered.
Answers in minutes, not task forces. Which applications does this unit run? Who is responsible? What is affected by this incident? In the graph everything is connected — one query instead of three weeks of spreadsheet reconciliation.
Findings reach the right person. The AI layer links processes to assets: vulnerabilities are delivered as tickets to the responsible owner automatically; recurring problems and creeping drift become visible.
Not just IT assets. The graph is not limited to IT: an asset is whatever matters to your operation — machines, vehicles, locations, contracts, certificates. New asset types are configuration, not a development project — and every type gets connected to the processes that belong to it.
A cross-cutting property across all capabilities: configuration over codebase. New data sources, new asset types, new scoring logic come via configuration in Apache Camel routes — no code deployment, no release cycle.
In productive use
The productive implementation has been running for several years in a group-wide security programme in 24/7 operation. Mosaic is the group-wide asset master for IT security and IT asset management there, the data foundation for the Cyber Defence Center and all ISO teams, middleware between vulnerability scanners, ticketing system and risk-management tools — and the source for compliance statements in DORA, NIS-2 and ISO 27001 audits. The lessons learned from this program have flowed into the current platform structure.
Open source and entry
Mosaic runs on Apache Camel and JanusGraph — both open-source standards with active communities. No platform licenses, no vendor lock-ins, exit-ready in standard formats. You operate on-premise, in any cloud or hybrid. The asset graph stays yours: data in open formats, integration logic in Apache Camel routes, visualization in a React frontend.
The entry runs through the Tactical Assessment: 30 minutes online, an experienced engineering lead listens and gives the read still in the call. If it fits, the Architecture Sprint follows with a validated implementation plan plus a fixed-price proposal for the engineering phase.

