temnir/

Finding an exposure was never the hard part. Getting it fixed, and keeping it fixed, is.

Most mid-sized teams newly in scope for NIS2 do not have a security specialist. Someone in IT or development ends up holding the exposure list on top of their regular work, and without a clear owner and a deadline, items sit in a spreadsheet until the next audit surfaces them again. We turn each exposure we find in module scry into one tracked item, in the tools your team already uses, with an owner, a due date, and a re-scan that confirms it is actually fixed.

integrations

We send every fix to the tools your team already uses.

We open a ticket for each finding and close it when a re-scan confirms the fix, so nothing gets copy-pasted into a spreadsheet or lost.

capabilities

Routing rules

Rules route each finding by type and severity: a ticket, a chat message, or muted. Set them once and every new exposure follows them.

Ownership rules

Rules assign each item to the right owner automatically, or you assign one by hand, so nothing sits unowned.

SLA due dates

Every item gets a due date from the rule that caught it, so the urgent work is obvious.

Auto-close

We close an item automatically once a re-scan confirms the exposure is gone, and reopen it if it returns.

Two-way ticket sync

Close the ticket in Jira, GitHub or GitLab and the item closes with it; reopen the ticket and it reopens.

Posture metrics

Open and overdue counts, mean time to remediate and SLA compliance, tracked week over week.

Webhooks post to your own endpoint; email is sent from our EU infrastructure.

  • Webhooks
  • Emailsoon

European

European vendors and open-source projects.

  • YouTrack
  • Forgejo
  • OpenProject
  • Matrix
  • ntfy

Non-EU, self-hostable

Open source you run yourself, so your data can still stay in the EU.

  • GitLab
  • Gitea
  • Mattermost
  • Redminesoon
  • Grafanasoon

Non-EU

Global SaaS. Data goes to the provider you connect.

  • Jira
  • GitHub
  • Slack
  • Microsoft Teams

How module ward works

  1. 01

    Set the routing rule once

    You decide how each severity is handled: a critical exposure opens a ticket in your tracker and pings a chat channel, a low one just sends a notification. Set the rule once, and we apply it to every new exposure from module scry. Nobody has to decide, each time, who should hear about this.

  2. 02

    One owned item per exposure

    We open exactly one item per exposure, in Jira, GitHub, GitLab, Gitea, Forgejo, YouTrack, or OpenProject, with an owner and a due date tracked against your own SLA. If a re-scan still finds the same exposure, we update that item instead of opening a new one, so the tracker never fills with duplicates. You can see at a glance what is overdue.

  3. 03

    Closed means gone, not just marked resolved

    When a later scan from module scry no longer sees the exposure, we close the item automatically and attach that scan as evidence. Done means the exposure is actually gone, not that someone remembered to mark it resolved. With module sigil, that confirmed-fix record becomes evidence for a NIS2 report.

Common questions about module ward

Which tools does module ward connect to today?

Ticketing: Jira, GitHub, GitLab, Gitea, Forgejo, YouTrack, OpenProject. Alerts: Slack, Microsoft Teams, Mattermost, Matrix, ntfy, a webhook, or email. Several of these (Gitea, Forgejo, Mattermost, Matrix) are European and self-hostable, which matters if your exposure data has to stay in the EU or on your own servers.

Will a re-scan flood our tracker with duplicate tickets?

No. We create exactly one tracked item per exposure. If a re-scan still finds the same exposure, we update the existing item instead of opening a new one, so the tracker stays a list of distinct problems, not scan noise.

Can someone just close the ticket without actually fixing anything?

They can close the ticket, but our record answers to the scan, not the ticket status. We close a tracked item only when a later scan from module scry no longer sees the exposure, and we keep that scan as the evidence. If you mark a ticket done while the exposure is still live, the item stays open until a scan confirms it gone.

The NIS2 deadline isn't moving. Your setup can start today.

See what your company exposes to the internet, free and EU-hosted, with no security team required.

*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.