attack-surface management for NIS2 · European teams
Become NIS2-compliant without a security team.
We find what your company exposes to the internet, show you the few risks an attacker could actually use, and turn your monitoring into the evidence NIS2 expects. All hosted in the EU.
*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.
- Continuous, passive monitoring
- Ranked by real-world exploitation
- NIS2 evidence on demand
signal, not noise
Stop fixing everything. Fix what attackers are actually using.
Most scanners bury you in hundreds of findings, all marked urgent. We watch everything you expose to the internet and surface the handful attackers are exploiting right now, so your team fixes what matters instead of chasing a backlog, and stays audit-ready.
512 findings a scanner marks urgent
The 3 in red are the ones attackers can actually use.
3 that could get you breached this week
Illustrative example. Figures and findings are not from a real scan.
how it works
Set up in one step. No security team needed.
- 01
Point us at your domain.
Tell us your company's web address. That's the whole setup.
- 02
We map what you expose.
We find every server, login page, and forgotten subdomain facing the internet, the way an attacker would.
- 03
You get the short list and the evidence.
The handful of risks worth acting on, plus the monitoring log and reports NIS2 asks for.
the temnir platform
One platform for your entire attack surface.
Find what you expose, fix it, and build your NIS2 evidence, all in one place.
To be straight with you: module scry, module ward and module sigil are live today. Module hex, our automated penetration testing, is still in development.
scry
see what you are exposing
Continuous attack-surface discovery. Know every internet-facing asset before an attacker finds it first.
Read morehexsoon
prove it can’t be broken into
Automated penetration testing, still in development. It will safely try the attacks that matter, so you find the hole before someone else does.
Read moreward
fix it, and confirm it’s gone
We turn each exposure into a tracked task in the tools you already use (Jira, GitHub, GitLab, and more), then close it automatically when a re-scan confirms it is gone.
Read moresigil
turn it into compliance evidence
Audit-ready NIS2 reports generated from what we actually monitored, not screenshots gathered the night before the audit.
Read moreattack-surface discovery
Everything you expose, before an attacker maps it.
We watch your whole internet-facing surface, every server, login page and forgotten subdomain, and keep watching, so a new exposure surfaces the day it appears, not the week after a breach.
capabilities
Continuous discovery
Passive and active scans find every internet-facing asset, subdomains, servers and forgotten login pages, and keep finding them.
Exposed services
We flag the open ports and running services that hand an attacker a way in.
TLS and email hygiene
Expiring or weak certificates, and domains missing SPF and DMARC that let anyone spoof your email.
Exploit-aware ranking
Findings are ordered by what an attacker can actually use, so the exploitable ones sit at the top.
NIS2 mapping
Each exposure is tied to the risk it creates, in the terms your NIS2 report needs.
Scheduled re-scans
Set a cadence per domain, so a new exposure surfaces the day it appears, not the week after.
automated penetration testing
soonProof it holds, not a checklist that says so.
We are building module hex to safely run the attacks that matter against your live surface, the moves a real intruder would try, and hand you proof of what got through, so you can close the hole before someone else finds it.
Module hex is still in development and not available yet. The rest of the platform, module scry, module ward and module sigil, is live today.
integrations
We send every fix to the tools your team already uses.
We open a ticket for each finding and close it when a re-scan confirms the fix, so nothing gets copy-pasted into a spreadsheet or lost.
capabilities
Routing rules
Rules route each finding by type and severity: a ticket, a chat message, or muted. Set them once and every new exposure follows them.
Ownership rules
Rules assign each item to the right owner automatically, or you assign one by hand, so nothing sits unowned.
SLA due dates
Every item gets a due date from the rule that caught it, so the urgent work is obvious.
Auto-close
We close an item automatically once a re-scan confirms the exposure is gone, and reopen it if it returns.
Two-way ticket sync
Close the ticket in Jira, GitHub or GitLab and the item closes with it; reopen the ticket and it reopens.
Posture metrics
Open and overdue counts, mean time to remediate and SLA compliance, tracked week over week.
Webhooks post to your own endpoint; email is sent from our EU infrastructure.
- Webhooks
- Emailsoon
European
European vendors and open-source projects.
- YouTrack
- Forgejo
- OpenProject
- Matrix
- ntfy
Non-EU, self-hostable
Open source you run yourself, so your data can still stay in the EU.
- GitLab
- Gitea
- Mattermost
- Redminesoon
- Grafanasoon
Non-EU
Global SaaS. Data goes to the provider you connect.
- Jira
- GitHub
- Slack
- Microsoft Teams
compliance reporting
NIS2 evidence built from what we actually watched.
Every report is generated from the surface we monitored and the fixes we confirmed, mapped to the NIS2 measures, so your audit rests on a continuous record, not screenshots gathered the night before.
capabilities
Built from real data
Generated from the surface we monitored and the fixes we confirmed, not screenshots gathered the night before.
Mapped to NIS2
Every finding is tied to the technical measures in the NIS2 implementing regulation, so an auditor can follow it.
Your entity details
The registration details a NIS2 authority asks for, filled in from your account.
White-label ready
Providers can put their own logo and colours on the report and hand it to a client as their own.
PDF and CSV export
A clean PDF for the auditor and a CSV of the findings for your own tracking.
A continuous record
Each report rests on the running history of what we watched, so an auditor sees a timeline, not one afternoon.
powered by grimoire
From the world’s registries to your audit.
grimoire weaves the world’s threat sources into one canonical graph where every fact traces back to its origin, so your compliance rests on all of it, not one country’s slice.
- vulnerability registries across the world*
- the dark web(coming soon)
national registries worldwide, plus the global open-source ecosystems
questions
NIS2 compliance, answered.
Does NIS2 apply to my company?
NIS2 pulled in far more organizations than the first directive. Many mid-sized firms in energy, manufacturing, healthcare, digital services, and their suppliers now qualify. Not sure? Get a free scan and we will help you check.
Do I need a security specialist to use temnir?
No, that is the point. We do the watching and the paperwork, and hand you a short list a non-specialist can act on.
Where is my data stored?
Built and hosted in the EU. Our servers are Hetzner (Germany), our content delivery is Bunny.net (Slovenia), and our email is Scaleway (France). All three are EU companies under EU law, so no provider under US jurisdiction processes your data. We name them in our privacy notice.
How long does setup take?
You point us at your company's web address. That is the setup, and discovery starts automatically.
What is grimoire?
grimoire is our public threat knowledge graph: the world’s vulnerability, exploitation, and advisory registers unified in one place. It is free to browse, and every risk we report links back to it for provenance. Module scry, module hex, and module sigil are the products that apply that intelligence to your own attack surface.
How does this help with an actual audit?
Module sigil turns what we continuously monitored into audit-ready NIS2 evidence: the monitoring log and reports on demand, not screenshots gathered at the last minute.
The NIS2 deadline isn't moving. Your setup can start today.
See what your company exposes to the internet, free and EU-hosted, with no security team required.
*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.