Finding an exposure was never the hard part. Getting it fixed, and keeping it fixed, is.
Most mid-sized teams newly in scope for NIS2 do not have a security specialist. Someone in IT or development ends up holding the exposure list on top of their regular work, and without a clear owner and a deadline, items sit in a spreadsheet until the next audit surfaces them again. We turn each exposure we find in module scry into one tracked item, in the tools your team already uses, with an owner, a due date, and a re-scan that confirms it is actually fixed.
integrations
We send every fix to the tools your team already uses.
We open a ticket for each finding and close it when a re-scan confirms the fix, so nothing gets copy-pasted into a spreadsheet or lost.
capabilities
Routing rules
Rules route each finding by type and severity: a ticket, a chat message, or muted. Set them once and every new exposure follows them.
Ownership rules
Rules assign each item to the right owner automatically, or you assign one by hand, so nothing sits unowned.
SLA due dates
Every item gets a due date from the rule that caught it, so the urgent work is obvious.
Auto-close
We close an item automatically once a re-scan confirms the exposure is gone, and reopen it if it returns.
Two-way ticket sync
Close the ticket in Jira, GitHub or GitLab and the item closes with it; reopen the ticket and it reopens.
Posture metrics
Open and overdue counts, mean time to remediate and SLA compliance, tracked week over week.
Webhooks post to your own endpoint; email is sent from our EU infrastructure.
- Webhooks
- Emailsoon
European
European vendors and open-source projects.
- YouTrack
- Forgejo
- OpenProject
- Matrix
- ntfy
Non-EU, self-hostable
Open source you run yourself, so your data can still stay in the EU.
- GitLab
- Gitea
- Mattermost
- Redminesoon
- Grafanasoon
Non-EU
Global SaaS. Data goes to the provider you connect.
- Jira
- GitHub
- Slack
- Microsoft Teams
How module ward works
- 01
Set the routing rule once
You decide how each severity is handled: a critical exposure opens a ticket in your tracker and pings a chat channel, a low one just sends a notification. Set the rule once, and we apply it to every new exposure from module scry. Nobody has to decide, each time, who should hear about this.
- 02
One owned item per exposure
We open exactly one item per exposure, in Jira, GitHub, GitLab, Gitea, Forgejo, YouTrack, or OpenProject, with an owner and a due date tracked against your own SLA. If a re-scan still finds the same exposure, we update that item instead of opening a new one, so the tracker never fills with duplicates. You can see at a glance what is overdue.
- 03
Closed means gone, not just marked resolved
When a later scan from module scry no longer sees the exposure, we close the item automatically and attach that scan as evidence. Done means the exposure is actually gone, not that someone remembered to mark it resolved. With module sigil, that confirmed-fix record becomes evidence for a NIS2 report.
Where it fits
- scrysee what you are exposing
- hexprove it can’t be broken into
- wardyou are herefix it, and confirm it’s gone
- sigilturn it into compliance evidence
Common questions about module ward
Which tools does module ward connect to today?
Ticketing: Jira, GitHub, GitLab, Gitea, Forgejo, YouTrack, OpenProject. Alerts: Slack, Microsoft Teams, Mattermost, Matrix, ntfy, a webhook, or email. Several of these (Gitea, Forgejo, Mattermost, Matrix) are European and self-hostable, which matters if your exposure data has to stay in the EU or on your own servers.
Will a re-scan flood our tracker with duplicate tickets?
No. We create exactly one tracked item per exposure. If a re-scan still finds the same exposure, we update the existing item instead of opening a new one, so the tracker stays a list of distinct problems, not scan noise.
Can someone just close the ticket without actually fixing anything?
They can close the ticket, but our record answers to the scan, not the ticket status. We close a tracked item only when a later scan from module scry no longer sees the exposure, and we keep that scan as the evidence. If you mark a ticket done while the exposure is still live, the item stays open until a scan confirms it gone.
The NIS2 deadline isn't moving. Your setup can start today.
See what your company exposes to the internet, free and EU-hosted, with no security team required.
*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.