Your CSV and JSON exports become metrics. You drop, we import.
A scanner that only produces reports, a console that exports to CSV, an isolated site: the data already exists. DropPoint is an S3-compatible drop-off space reserved for your organization, with one space per tool. Push your exports by hand or from a scheduled script, and OverView imports them on the next synchronization.
- HTTPS and AWS Signature Version 4 (SigV4) on every request
- A drop-off space isolated per organization
- Credentials revocable at any time
- Why it is safe ↓
THEY DID IT
The City of Lille consolidated 10 tools and 5,000 devices, through APIs or flat files
After the 2023 cyberattack and under NIS 2 pressure, the City of Lille, Lomme and Hellemmes chose to build on what it had: AD, ITSM, MDM, EDR, scanners and CMDB were collected automatically, through APIs or flat files, with no data re-entered and no migration project.
Read the case study →
Jean-François Rosendo
IT Director — City of Lille, Lomme & Hellemmes

“What drew us in from the start wasn’t adding yet another security tool — we already had plenty. We were looking instead for the ability to federate the information we already had. The goal was simple: create a single source of truth.”
THE PROBLEM
Not all data comes through an API
Tools with no usable API
A scanner that only produces reports, a console that exports to CSV, a home-grown CMDB: the data exists, but no API lets you read it.
Networks you do not open
Sensitive sites, isolated environments, contractors: sometimes the only thing allowed out is a file.
Manual imports that do not last
Emailing an export every month works once. Then someone forgets, the format changes, and the metric freezes.
HOW IT WORKS
One space per tool, one file per export
DropPoint speaks S3, the standard your scripts, backups and tools already know. No proprietary client to install, nothing for your security team to vet.
- 01
Generate your credentials
In OverView: Settings, Security, S3 Credentials. An Access Key / Secret Key pair scoped to your organization, revocable at any time.
- 02
Pick your client
AWS CLI, rclone, boto3, PowerShell, Cyberduck or WinSCP: any S3 client works. Point it at s3.oversoc.com.
- 03
Drop your exports
Each connector has its own space, an S3 bucket (sentinelone, vmware, azure…). Copy your CSV or JSON files to its root.
- 04
OverView imports
New files are detected and ingested on the next synchronization. Automate with cron, launchd or Windows Task Scheduler, and the metric refreshes with every export.
WHICH ROUTE FOR WHICH TOOL
Three routes, one inventory
Cloud, on-prem, file: every source has a route into OverView. Most customers combine two of them.
| Your situation | Recommended route |
|---|---|
| SaaS tool with a public API (EDR, Entra ID, Intune, ServiceNow) | Cloud API |
| Internal tool with an API (GLPI, vCenter, Active Directory, Nessus, Centreon) | OverView OutPost |
| Several internal tools behind the same firewall | OutPost, one VM for all of them |
| Tool with no API, or that only produces exports (scanner report, antivirus console, home-grown CMDB) | OverView DropPoint |
| Isolated site or a network you do not open | DropPoint, a file goes out, nothing comes in |
| Both cases in the same infrastructure | OutPost + DropPoint, same inventory |
Isolated by design
Isolated per organization
Each organization has its own drop-off spaces (buckets). Your credentials open only your own connector buckets, nothing else.
Revocable credentials
The Secret Key is shown only at generation time. Disable or regenerate a key at any time from OverView.
SigV4 signing
Every request is signed. A request is rejected if the key is unknown, the signature invalid or the bucket wrong.
HTTPS only
TLS endpoint, no cleartext transfer. SSL inspection breaks the request signature, so exclude this endpoint from your outbound proxy.
No inbound connections
Your systems push to DropPoint. OverView never needs to reach your network.
Standard S3, nothing new to approve
You keep your usual tools, scripts and audit procedures. No proprietary OverView client for your security team to vet.
Recommended reading before your security review
HAND THIS TO YOUR ADMIN
Five lines to automate the first export
Paste this block into the ticket. The getting started guide ships ready-to-paste cron, launchd and PowerShell scripts.
- 01Create the credentials in OverView: Settings, Security, S3 Credentials (the Secret Key is shown only once)
- 02Configure an AWS CLI profile: endpoint https://s3.oversoc.com, path-style addressing, SigV4
- 03Export from the source tool to CSV or JSON into a dedicated local folder
- 04Schedule “aws s3 sync ./exports s3://<connector>/” with cron, launchd or Windows Task Scheduler
- 05Exclude s3.oversoc.com from the outbound proxy’s SSL inspection, and check the system clock (NTP)
TECH SHEET
What to know
- Protocol
- S3 API, SigV4, path-style addressing
- Endpoint
- https://s3.oversoc.com
- Formats
- CSV, JSON
- Size per request
- 500 MB per request; larger files switch to multipart automatically with AWS CLI or rclone
- Quota
- No per-organization quota enforced today
- Tested clients
- AWS CLI v2.13+, AWS Tools for PowerShell, rclone, boto3, Cyberduck, WinSCP
- Automation
- cron, launchd, Windows Task Scheduler
- Layout
- One bucket per connector type, files at the root
WHAT YOU UNLOCK
Every connector has its own drop-off space
60+ OverView connectors support file import. Export from your tool, drop it in the connector’s space, and metrics compute just like with an API.
Examples of metrics unlocked
- Antivirus coverage by device typeSources: ESET or Kaspersky console export
- Obsolete servers with High vulnerabilitiesSources: Nessus or OpenVAS report
- Patch status per deviceSources: SCCM or WSUS export
- Percentage of VMs backed upSources: Veeam export
- Devices seen on the network but missing from the CMDBSources: Nmap scan + CMDB export
FREQUENTLY ASKED
What your team will ask
Ready to take back control?
Plug in your sources, see for yourself in 14 days. Free access, no commitment, 45-minute setup.
Start for free