temnir/

attack-surface management for NIS2 · European teams

Become NIS2-compliant without a security team.

We find what your company exposes to the internet, show you the few risks an attacker could actually use, and turn your monitoring into the evidence NIS2 expects. All hosted in the EU.

*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.

  • Continuous, passive monitoring
  • Ranked by real-world exploitation
  • NIS2 evidence on demand
Built & hosted in the EUEvery provider is an EU companyMapped to NIS2 requirements

signal, not noise

Stop fixing everything. Fix what attackers are actually using.

Most scanners bury you in hundreds of findings, all marked urgent. We watch everything you expose to the internet and surface the handful attackers are exploiting right now, so your team fixes what matters instead of chasing a backlog, and stays audit-ready.

512 findings a scanner marks urgent

The 3 in red are the ones attackers can actually use.

3 that could get you breached this week

Forgotten admin panel, wide openexploited now
Out-of-date VPN gatewayknown exploit
Expired cert on your payment hosthigh risk
Always watching · continuous, passive monitoringRanked by real-world exploitation, not CVSS aloneNIS2-ready evidence on demand

Illustrative example. Figures and findings are not from a real scan.

how it works

Set up in one step. No security team needed.

  1. 01

    Point us at your domain.

    Tell us your company's web address. That's the whole setup.

  2. 02

    We map what you expose.

    We find every server, login page, and forgotten subdomain facing the internet, the way an attacker would.

  3. 03

    You get the short list and the evidence.

    The handful of risks worth acting on, plus the monitoring log and reports NIS2 asks for.

the temnir platform

One platform for your entire attack surface.

Find what you expose, fix it, and build your NIS2 evidence, all in one place.

To be straight with you: module scry, module ward and module sigil are live today. Module hex, our automated penetration testing, is still in development.

scry

see what you are exposing

Continuous attack-surface discovery. Know every internet-facing asset before an attacker finds it first.

Read more

hexsoon

prove it can’t be broken into

Automated penetration testing, still in development. It will safely try the attacks that matter, so you find the hole before someone else does.

Read more

ward

fix it, and confirm it’s gone

We turn each exposure into a tracked task in the tools you already use (Jira, GitHub, GitLab, and more), then close it automatically when a re-scan confirms it is gone.

Read more

sigil

turn it into compliance evidence

Audit-ready NIS2 reports generated from what we actually monitored, not screenshots gathered the night before the audit.

Read more

attack-surface discovery

Everything you expose, before an attacker maps it.

We watch your whole internet-facing surface, every server, login page and forgotten subdomain, and keep watching, so a new exposure surfaces the day it appears, not the week after a breach.

your domainyour live attack surfacethe exposures that matter

capabilities

Continuous discovery

Passive and active scans find every internet-facing asset, subdomains, servers and forgotten login pages, and keep finding them.

Exposed services

We flag the open ports and running services that hand an attacker a way in.

TLS and email hygiene

Expiring or weak certificates, and domains missing SPF and DMARC that let anyone spoof your email.

Exploit-aware ranking

Findings are ordered by what an attacker can actually use, so the exploitable ones sit at the top.

NIS2 mapping

Each exposure is tied to the risk it creates, in the terms your NIS2 report needs.

Scheduled re-scans

Set a cadence per domain, so a new exposure surfaces the day it appears, not the week after.

Run a free scan

automated penetration testing

soon

Proof it holds, not a checklist that says so.

We are building module hex to safely run the attacks that matter against your live surface, the moves a real intruder would try, and hand you proof of what got through, so you can close the hole before someone else finds it.

Module hex is still in development and not available yet. The rest of the platform, module scry, module ward and module sigil, is live today.

a safe attackproof of impactthe exact fix

integrations

We send every fix to the tools your team already uses.

We open a ticket for each finding and close it when a re-scan confirms the fix, so nothing gets copy-pasted into a spreadsheet or lost.

capabilities

Routing rules

Rules route each finding by type and severity: a ticket, a chat message, or muted. Set them once and every new exposure follows them.

Ownership rules

Rules assign each item to the right owner automatically, or you assign one by hand, so nothing sits unowned.

SLA due dates

Every item gets a due date from the rule that caught it, so the urgent work is obvious.

Auto-close

We close an item automatically once a re-scan confirms the exposure is gone, and reopen it if it returns.

Two-way ticket sync

Close the ticket in Jira, GitHub or GitLab and the item closes with it; reopen the ticket and it reopens.

Posture metrics

Open and overdue counts, mean time to remediate and SLA compliance, tracked week over week.

Webhooks post to your own endpoint; email is sent from our EU infrastructure.

  • Webhooks
  • Emailsoon

European

European vendors and open-source projects.

  • YouTrack
  • Forgejo
  • OpenProject
  • Matrix
  • ntfy

Non-EU, self-hostable

Open source you run yourself, so your data can still stay in the EU.

  • GitLab
  • Gitea
  • Mattermost
  • Redminesoon
  • Grafanasoon

Non-EU

Global SaaS. Data goes to the provider you connect.

  • Jira
  • GitHub
  • Slack
  • Microsoft Teams

compliance reporting

NIS2 evidence built from what we actually watched.

Every report is generated from the surface we monitored and the fixes we confirmed, mapped to the NIS2 measures, so your audit rests on a continuous record, not screenshots gathered the night before.

continuous monitoringconfirmed fixesyour NIS2 report

capabilities

Built from real data

Generated from the surface we monitored and the fixes we confirmed, not screenshots gathered the night before.

Mapped to NIS2

Every finding is tied to the technical measures in the NIS2 implementing regulation, so an auditor can follow it.

Your entity details

The registration details a NIS2 authority asks for, filled in from your account.

White-label ready

Providers can put their own logo and colours on the report and hand it to a client as their own.

PDF and CSV export

A clean PDF for the auditor and a CSV of the findings for your own tracking.

A continuous record

Each report rests on the running history of what we watched, so an auditor sees a timeline, not one afternoon.

What NIS2 requires

powered by grimoire

From the world’s registries to your audit.

grimoire weaves the world’s threat sources into one canonical graph where every fact traces back to its origin, so your compliance rests on all of it, not one country’s slice.

  • vulnerability registries across the world*
  • the dark web(coming soon)

national registries worldwide, plus the global open-source ecosystems

many sourcesone provenanced graphcompliance-ready evidence
Open grimoire

questions

NIS2 compliance, answered.

Does NIS2 apply to my company?

NIS2 pulled in far more organizations than the first directive. Many mid-sized firms in energy, manufacturing, healthcare, digital services, and their suppliers now qualify. Not sure? Get a free scan and we will help you check.

Do I need a security specialist to use temnir?

No, that is the point. We do the watching and the paperwork, and hand you a short list a non-specialist can act on.

Where is my data stored?

Built and hosted in the EU. Our servers are Hetzner (Germany), our content delivery is Bunny.net (Slovenia), and our email is Scaleway (France). All three are EU companies under EU law, so no provider under US jurisdiction processes your data. We name them in our privacy notice.

How long does setup take?

You point us at your company's web address. That is the setup, and discovery starts automatically.

What is grimoire?

grimoire is our public threat knowledge graph: the world’s vulnerability, exploitation, and advisory registers unified in one place. It is free to browse, and every risk we report links back to it for provenance. Module scry, module hex, and module sigil are the products that apply that intelligence to your own attack surface.

How does this help with an actual audit?

Module sigil turns what we continuously monitored into audit-ready NIS2 evidence: the monitoring log and reports on demand, not screenshots gathered at the last minute.

Read our NIS2 guide →

The NIS2 deadline isn't moving. Your setup can start today.

See what your company exposes to the internet, free and EU-hosted, with no security team required.

*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.