Continuous Audit Evidence

You manage mobile compliance. ARES lets you prove it.

One agent on every device. Continuous mapping across every regulation that applies to your fleet. When your auditor asks — NIS2, ANSSI, ISO 27001, BSI, CyFun, FNCDP, NCSC CAF simultaneously — the evidence chain is already built.

One click. Timestamped. Article-cited. Ready.

EU Sovereign · Zero personal data · No MDM required
NIS2· ANSSI· ISO 27001· BSI· CyFun· FNCDP 2025· NCSC CAF· NIST 800-124
Fleet Dashboard · Your company
Active monitoring
47
Devices
41
No gaps detected
6
Cross-fw gaps
NIS2 92%
ANSSI 88%
ISO 27001 74%
BSI 81%
⚠ Cross-framework gap · Xiaomi 13T Pro — 2 controls · 4 frameworks
Priority alert · highest severity gap in fleet — resolve to clear 4 frameworks simultaneously
ADB debugging active
NIS2 6.3 ISO 27001 A.8.9 BSI SYS.3.2.4.A2 ANSSI R7
→ Disable ADB
resolves NIS2 + ANSSI + ISO 27001 + BSI
Security patch level
NIS2 6.6 ANSSI R19 ISO 27001 A.8.8 BSI SYS.3.2.1.A5
→ Update security patch
resolves NIS2 + ANSSI + ISO 27001 + BSI
→ 5 more devices with active gaps · view full report
Four buying triggers

Four moments where continuous audit evidence changes the outcome.

ARES gives you a continuous, multi-framework evidence chain — per device, per control, always current. The evidence is already structured the way your auditor expects.

01 — NIS2 or ANSSI audit

The evidence is already structured the way your auditor expects.

Per device. Per control. Per framework article. Timestamped from day one. No preparation work before the audit — the record has been running continuously since deployment.

02 — US market requires compliance evidence

NIST 800-124 or CMMC Level 2 — from your EU fleet.

ARES Tier 2 produces the full monitoring history your US market needs. EU data residency on OVH — a French company subject to EU law only. No sovereignty question from any US partner.

03 — Cyber insurance renewal

Your insurer gets a continuous record, not a reconstruction.

Nothing to reconstruct at renewal. No evidence gaps. The record was running from day one — that is the evidence your insurer needs to see.

04 — Board wants a compliance posture report

Fleet-wide regulatory liability status. No extra work from IT.

ARES generates a CEO-level executive risk summary automatically — fleet-wide status, percentage compliant per framework, regulatory liability. Produced by IT, consumed by the board.

Product Architecture

One Agent. One Backend. Eight Frameworks.

A lightweight agent on every device, all intelligence in an EU-sovereign backend, three outputs designed for three different stakeholders.

Device Agent

Lightweight app deployed on every Android and iOS device. Silent background collection — no user interaction required after installation.

  • System-level security signal collection — Android and iOS
  • Zero personal data — technical signals only
  • No IMEI · No serial number · No app list · No location
  • Anonymous device identity ARES cannot reverse
  • Provisioning via QR code — no MDM required

EU Sovereign Backend

All framework mapping lives here — hosted on OVH in the EU. When regulations update, ARES updates once. Every customer current, automatically. No re-deployment.

  • Framework mapping engine — backend only, never in the agent
  • Regulatory update engine — zero client updates required
  • Multi-tenant isolation
  • Per-customer key isolation in OVH's EU KMS — keys never extractable
  • Free from US legal jurisdiction by architecture

Three Outputs

Designed outputs for three audiences. The IT manager, the CEO, and the auditor each get exactly what they need, without extra work from IT.

  • Active fleet dashboard — IT manager
  • Executive risk summary — CEO / board
  • Audit-ready PDF — one click, any framework, any date
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • Always framework-current — regulatory updates propagate automatically
  • Continuous monitoring log — the history IS the evidence

Framework mapping lives in the backend only

When NIS2, ANSSI, BSI, ISO 27001, CyFun, FNCDP, NCSC CAF or NIST updates — ARES updates once. Every customer is automatically current. No client update. No re-deployment. No manual mapping review on your side. Device signals are mapped against the CIS Android control set — one signal set, eight frameworks, zero redundant collection.

Zero GDPR Friction — By Architecture

Deploy today. Free of process delays.
GDPR compliance is built in.

Every MDM and MTD competitor requires your organisation to process employee personal data before deploying a single agent. ARES collects zero personal data by architecture — which changes everything about how and when you deploy.

Every MDM and MTD competitor
✗ Collects personal data — GDPR Article 6 processing basis required
Device identifiers, app inventories, or behavioural signals. Article 6 basis must be established before the first device is enrolled.
✗ Mandatory DPIA under Article 35
Employee device monitoring is explicitly high-risk per EDPB guidance. DPIA is not optional.
✗ DPA negotiation with the vendor required before the first device is enrolled
Standard DPA may not cover your specific use case. Legal review required before any data flows.
✗ Works council consultation required — 4–8 week process in France
CSE consultation on employee monitoring. Germany: Betriebsrat. Belgium and Ireland: equivalent bodies.
✗ DPO review required
Processing basis, retention period, data subject rights, employee notice obligations.
Deployment requires HR, legal, DPO, and employee representatives before a single device is enrolled.
ARES
✓ Deploy the moment you decide — zero legal prerequisites
ARES collects only technical device configuration — not personal data under GDPR Art. 4 by definition.
✓ No DPIA under Article 35
Not high-risk by definition. No employee monitoring. No behavioural data.
✓ Your legal team stays out of it
ARES collects no personal data — no data processor relationship exists, no DPA required before deployment.
✓ HR and employee reps are not in the loop
France (CSE), Germany (Betriebsrat), Belgium, Ireland, Romania — none required. Zero personal data triggers no obligation.
✓ Your DPO has nothing to sign off
No processing basis to establish. No DPIA to commission. No data subjects to notify.
Deploy on any device. Today. No prerequisites.
Privacy Architecture

Zero Personal Data. Beyond US Jurisdiction.

ARES gives you full device-security visibility without the liability that usually comes with it. There's no personal data to breach, no identity we could expose if we tried, and no foreign government that can reach your data. Privacy and sovereignty aren't clauses in a contract here — they're built into the architecture.

Layer 1 — What We See

Security Posture, Not Surveillance

ARES reads a device's security configuration — never its contents, its location, or how your people use it. Employees aren't being watched; their device's security posture is what's assessed. That distinction clears works council and DPO review instead of stalling there.
  • Reads what makes a device safe — patch level, encryption, screen lock, boot integrity — and stops there
  • Location-free, and without access to messages, files, browsing, or app lists
  • Confirms a device is secure with no IMEI, serial number, or employee name attached
  • Outside GDPR Art. 4 personal data — one less data-protection liability to carry
Layer 2 — Who It's About

We Can't Identify Your People — By Design

To ARES, every device is an anonymous token. We can't reverse it to a device, a person, or an employee — and neither can anyone who breaches us. The only map from token to identity lives inside your systems, under your control.
  • Device identity is a one-way fingerprint of a key that never leaves the device's secure hardware
  • The original hardware identifier is discarded the moment a device enrols — never stored
  • Even with full access to our database, ARES cannot put a name to a signal
  • You hold the only link between a token and an employee — ARES never sees it
Layer 3 — Where It Lives

EU-Sovereign Key Custody

Every customer key is generated and held inside OVH's EU key service — and can never be exported in raw form.
  • Per-customer cryptographic isolation — its own dedicated certificate authority and keys
  • Private keys can never be extracted or copied — every key operation is gated and audited
  • Your data, reports, and keys never leave the EU — full European legal sovereignty
  • Immune to the US CLOUD Act and foreign data demands — by jurisdiction, not by promise
Privacy

One Cookie. Nothing Else.

This site keeps cookies to what's strictly necessary to run it — nothing for tracking, advertising, or analytics, and no third parties. Here's exactly what's set and when.

Browsing the Site

No Cookies Set

Pages, pricing, and documentation load with nothing stored in your browser.

Signing In to the Dashboard

One Cookie, Strictly Necessary

One cookie is set, solely to keep you signed in. It carries no tracking value and is never shared with a third party.

No consent banner is shown because this cookie is strictly necessary — it exists only so you stay logged in, not to track or profile you.

Framework Coverage

Eight Frameworks. One Deployment. Zero Overlap Work.

Every framework maps against the same device signal set, simultaneously. Every collection generates evidence across all eight frameworks at once. One deployment covers your entire regulatory stack.

NIS2
EU Directive 2022/2555
Mandatory for all EU essential and important entities. Mobile device security mandated under Article 21. Continuous monitoring evidence is what auditors evaluate — not a point-in-time assessment.
EU Law Tier 1
ANSSI
French National Cybersecurity Agency
French NIS2 transposition guidance and mobile security recommendations. ARES provides the mobile device technical evidence required for DAT-NT-010/ANSSI/SDE (R1–R21) technical guidance — no manual evidence gathering.
France Tier 1 DAT-NT-010 · R1–R21
ISO 27001
International Standard — 2022 Revision
Device-layer Annex A controls for certification audit preparation. Widely required across EU sectors and as a customer contractual requirement. Continuous monitoring log supports certification body review.
Certification Tier 1
BSI Grundschutz
German Federal Office for Information Security
German SME cybersecurity standard — critical for DACH market entry and supply chain compliance. SYS.3.2 mobile device module coverage with full evidence chain.
Germany · DACH Tier 1
CyFun 2025
CCB — Belgium · Ireland · Romania
Belgium's national NIS2 framework — mandatory for all NIS2-scoped entities. Co-owned by Belgium, Ireland, and Romania. Maps directly to ISO 27001 and CIS Controls.
Belgium · Ireland · Romania Tier 1
FNCDP 2025
ACN — Italy · NIST CSF 2.0 aligned
Italian National Framework for Cybersecurity and Data Protection — voluntary, aligned with NIST CSF 2.0. Relevant for Italian NIS2 entities and EU companies with Italian operations.
Italy Tier 1
NCSC CAF 4.0
UK National Cyber Security Centre — NIS Regulations · Essential Services
The UK's mandatory outcome-based framework for Operators of Essential Services — legally separate from NIS2 since Brexit, enforced independently by UK Competent Authorities. EU groups with UK subsidiaries, and UK companies with EU operations, now face two diverging audit regimes simultaneously. ARES resolves the overlap: the same device signal set maps against CAF Objectives A, B and C alongside NIS2 Article 21 simultaneously — one deployment, two evidence chains, no redundant collection.
UK · Ireland · Cross-border EU Tier 1
NIST 800-124
US National Institute of Standards and Technology
Required for EU companies with US market compliance obligations. The same device signal set separately maps to CMMC Level 2 evidence (NIST SP 800-171 Rev 2) for EU defense supply chain companies. Requires 3+ months continuous Tier 1 monitoring history.
US Market · Tier 2 CMMC Level 2 Evidence
DORA
EU Regulation 2022/2554 — Financial Sector
For financial entities subject to DORA, ARES continuous monitoring provides direct evidence for Article 9(4)(c) endpoint security control requirements. No additional deployment. Your Tier 1 data covers it. Scope boundary: one article of forty — ARES never claims DORA compliance.
Financial Sector · Art. 9(4)(c) Evidence Tier 1
Who This Is For

Built for the person who deploys it and the person who signs off the report it produces.

No dedicated security team. No procurement committee. One deployment covers both roles.

IT Manager / DSI

Deploy, monitor, and report — without a project.

  • QR code provisioning — any Android or iOS device in under an hour
  • No MDM, no Azure AD, no IT certification required
  • No DPO, no HR involvement — zero personal data by architecture
  • Fleet-wide compliance status across all frameworks at a glance
  • Audit-ready PDF generated in one click — any framework, any date
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • CEO executive risk summary ready to share upward without extra work
CISO / RSSI

Cross-framework gap intelligence and continuous evidence.

  • Simultaneous gap and overlap view across all applicable frameworks per device
  • Complete evidence history — audit-ready at any point, no preparation required
  • ANSSI DAT-NT-010 technical evidence — no manual gathering
  • Always current on regulation updates — backend mapping, zero re-deployment
  • OVH sovereignty — defensible to any NIS2 supervisor on data residency
  • Timestamped evidence chain per control, per framework, per device
Three Outputs

What ARES Delivers to Each Stakeholder

One platform. Three audiences. Each output designed for its reader.

IT Manager

Continuous Fleet Dashboard

Per-device status across all frameworks simultaneously. One fix resolves gaps across multiple frameworks at once. No manual aggregation.

  • Per-device compliance status by framework
  • Cross-framework gap and overlap view
  • Alert on posture degradation
  • Continuous monitoring log for audit evidence
CEO / Board

Executive Risk Summary

Fleet-wide regulatory liability status in plain language. Produced by the IT manager, consumed by the board. No technical jargon. No extra work.

  • Single risk indicator — compliant / action required
  • Fleet compliance percentage by framework
  • Regulatory liability status
  • Boardroom-ready — no translation required
Auditor / US Market

Audit-Ready PDF and Evidence Export

The PDF is the document your compliance lead uses to validate the purchase internally and hand to your auditor. One click. Evidence chain per control. Cites framework articles directly. The signed JSON and CSV export is the raw data that proves what the PDF states.

  • Signal → control → standard article reference
  • Timestamped evidence per device
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • Full monitoring history — audit readiness evaluated over time, not at a single point
  • Scope limitations stated explicitly as precision, not weakness

NIST 800-124 report requires a minimum of 3 months of Tier 1 monitoring history.

Not Your MDM/EMM

Your MDM/EMM manages your devices. It cannot produce this document.

ARES is the compliance intelligence and audit evidence layer MDMs cannot provide and were never designed to provide.

What your MDM does

Device management and policy enforcement

  • Enrolls and manages corporate devices
  • Enforces configuration policies (screen lock, encryption)
  • Pushes apps and certificates
  • Wipes lost or stolen devices remotely
  • Cannot map device signals against NIS2 Article 21 specifically
  • Cannot produce a timestamped, article-cited evidence chain
  • Cannot cover unmanaged or BYOD devices with audit evidence
  • Cannot show cross-framework gap and overlap view
  • Cannot generate an audit-ready PDF for an external auditor
  • Triggers GDPR Art. 6 processing basis — DPIA, DPA, works council
What ARES adds

Compliance intelligence and audit evidence

  • Maps device signals against NIS2 Art. 21, ANSSI, BSI, CyFun, ISO 27001, NCSC CAF simultaneously
  • Timestamped evidence chain — per device, per control, per framework
  • Covers any device — managed, unmanaged, BYOD — via QR code
  • Cross-framework gap and overlap view — one fix resolves multiple frameworks
  • One-click audit-ready PDF — any framework, any date, full monitoring history
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • Zero personal data — no GDPR processing basis, no DPIA, no works council
  • EU-sovereign on OVH — defensible to any NIS2 supervisor on data residency
Aligned with how NIS2 audits are actually evaluated. Audit readiness is assessed over time, not at a single point — ARES maintains that continuity automatically. The monitoring history IS the evidence. A gap in the record is a gap in the evidence.
Mapping Methodology

How ARES mappings are built and maintained.

Every claim ARES makes in an audit report is traceable to a source document and a specific device signal. This is how that traceability works.

01 — Source

Built from primary sources

Each framework mapping is built directly from the official published standard — NIS2 Directive text, ANSSI mobile security guides, BSI SYS.3.2 module, ISO 27001:2022 Annex A, CyFun 2025 specification, FNCDP 2025 documentation, NCSC CAF 4.0 guidance, NIST SP 800-124 Rev. 2. No secondary interpretation. No aggregator shortcuts.

02 — Backbone

CIS Android and Apple iOS Benchmarks as technical backbone

Device signals are mapped against the CIS Android Benchmark and the CIS Apple iOS Benchmark — both platforms, both signal sets. This single backbone drives all eight framework mappings simultaneously — eliminating redundant data collection and ensuring consistent evidence across every framework in every report, for every device in your fleet.

03 — Review

Expert review before pilot launch

All framework mappings are reviewed by a qualified compliance expert with ANSSI-specific experience before any customer deployment. Framework accuracy is a product liability — not an assumption. Reports cite the specific article and control that each device signal satisfies or fails.

04 — Currency

Maintained continuously in the backend

Framework mappings live in the ARES backend — not in the device agent. When NIS2, ANSSI, BSI, ISO 27001, CyFun, FNCDP, NCSC CAF, or NIST updates, the mapping updates once. Every customer's next report reflects the current standard. No client re-deployment. No manual review on your side.

Transparent Pricing

Free Gap Assessment · Tier 1 Audit · Tier 2 Audit + NIST

One price per tier. No per-device math. No hidden bundles. Every deployment is scoped before you commit.

Start Here
Free Gap Assessment
€0
Your fleet · All Tier 1 frameworks · From device one
See your full compliance picture across every Tier 1 framework from the moment your first device enrols — no credit card, no commitment.
  • Fleet dashboard — total devices enrolled, framework compliance scores across all Tier 1 frameworks
  • Compliance picture at fleet scale — per-device detail and audit reports unlocked at Tier 1
  • Continuous monitoring starts on enrolment — history preserved at conversion
  • Dashboard access — no time limit, no expiry
  • No credit card · No commitment
Start Free Assessment
Most Popular
Tier 1 — Audit
€6,800/year
Up to 100 devices · More than 100? Contact ARES
NIS2 enforcement is active. Your auditor is asking for continuous mobile device compliance evidence. ARES gives you a continuous, audit-ready answer across NIS2, ANSSI, ISO 27001, BSI, CyFun, FNCDP and NCSC CAF — one click, any time, always current.
  • Continuous fleet monitoring — Android and iOS
  • NIS2 · ANSSI · ISO 27001 · BSI · CyFun · FNCDP · NCSC CAF reports
  • Unlimited audit-ready PDF reports — any framework, any date
  • Signed JSON and CSV evidence export — per device, all Tier 1 EU and UK frameworks, full monitoring history
  • CEO executive risk summary
  • Dedicated EU key isolation included
  • Priority support
Start Tier 1
US Market
Tier 2 — Audit + NIST
€12,000/year
Up to 100 devices · Requires 3 months Tier 1 history
Everything in Tier 1, plus full NIST 800-124 gap analysis and a complete monitoring history evidence chain — ready for your US market audit. Tier 2 monitoring data separately generates CMMC Level 2 mobile device evidence (NIST SP 800-171 Rev 2) for EU companies in the US defense supply chain.
  • Everything in Tier 1
  • Signed JSON and CSV evidence export extended to NIST 800-124 and CMMC Level 2 evidence
  • NIST 800-124 full gap analysis report
  • CMMC Level 2 mobile device evidence support
  • Full monitoring period evidence chain for US market audit
  • Dedicated Customer Success Manager
Start Tier 2
›

A manual compliance audit costs €6,000–€25,000 per engagement.† It produces a point-in-time snapshot — accurate on signing day, outdated as your fleet changes. ARES produces continuous evidence across eight frameworks simultaneously, updated automatically when regulations change, for a flat annual fee. One invoice. No re-engagement cost when NIS2 updates. The monitoring history IS the evidence — a gap in the record is a gap in the evidence.
† EU SME compliance audit range €6,000–€25,000. Sources: Secfix 2025 · Digitemis FR 2025 · Feel Agile EU 2025. Comparison covers compliance assessment and continuous evidence-gathering, not full ISMS implementation.

Before you start Tier 2: a minimum of 3 months of Tier 1 continuous monitoring history is required before your first NIST 800-124 report can be generated. The report covers your full monitoring period on record — credible and defensible to US partners. Tier 2 includes Tier 1. There is no NIST-only subscription.

Start with the right scope.

We run a free gap assessment on your fleet. You see your posture at fleet scale — total compliance picture across all Tier 1 frameworks, from the moment your first device enrols.
Your next audit is already in progress — every day ARES runs is evidence.

How many devices?  ·  Android, iOS, or mix?  ·  Which frameworks apply?  ·  When is your next audit?

contact@ares-signum.eu

For Cybersecurity Providers

Add a continuous mobile compliance evidence layer to your NIS2 offer.

MSSPs and cybersecurity consultancies serving EU SMEs have no purpose-built tool to provide continuous, audit-ready mobile device compliance evidence. ARES fills that gap — you refer, ARES invoices your customer directly, and you earn a recurring referral fee for the lifetime of the contract.

Referral model

You introduce the customer. ARES invoices directly and owns the relationship. You receive an ACV referral fee annually, recurring as long as the customer stays.

No product investment

You do not resell, white-label, or maintain ARES. You add a capability your customers need and your portfolio currently lacks — with zero product overhead.

Complete the NIS2 offer

ARES is the continuous device evidence layer your existing NIS2 governance and documentation work cannot provide. Additive to everything you already deliver.

← Back ARES
About ARES

Mobile compliance is the gap every NIS2 audit exposes.

Most European SMEs entering their first NIS2 audit discover the same problem: they have no continuous, audit-ready evidence of their mobile device security posture. Policies exist on paper. The devices tell a different story. ARES was built to close that gap — automatically, continuously, at a price that makes sense for a 50-person company in Lyon or a logistics firm in Düsseldorf.

NIS2 Article 21 mandates continuous device security monitoring. The tools that existed before ARES were built for enterprise teams with dedicated security staff and six-figure budgets — Jamf, Intune, CrowdStrike. Powerful, expensive, and designed for a world very different from an SME trying to pass its first audit. ARES is the precision instrument built instead.

What ARES Does

ARES is an EU-sovereign mobile security platform that turns device signal data into audit-ready compliance evidence — automatically, continuously, and affordably. One lightweight agent on each device monitors the security posture signals that regulators evaluate: encryption status, patch level, screen lock, secure boot, developer mode, VPN configuration. No personal data. No IMEI. No location tracking.

That signal data feeds a single backend — hosted entirely on OVH in the EU — that maps posture against eight frameworks simultaneously: NIS2, ANSSI, ISO 27001, BSI Grundschutz, CyFun 2025, FNCDP 2025, NCSC CAF 4.0, and NIST 800-124, plus DORA Art. 9(4)(c) as an endpoint security evidence layer for financial entities. When a regulation updates, the mapping updates once in the backend. Every customer is automatically current. No re-deployment. No manual review.

Three outputs for three audiences: an active fleet dashboard for the IT manager, an executive risk summary for the CEO, and a one-click audit-ready PDF for the auditor or US supply-chain partner. Tier 1 includes a signed JSON and CSV export of the raw evidence data for all Tier 1 EU and UK frameworks; Tier 2 extends it to NIST 800-124 and CMMC Level 2 evidence. Per device, full monitoring history.

Why EU Sovereignty Matters

ARES runs entirely within the EU. Every device signal, every report, every encryption key sits on OVH's European infrastructure — operated by a French company under EU law alone, with no US hyperscaler anywhere in the stack. Each customer's keys are cryptographically isolated, never leave OVH's key service, and cannot be extracted or copied — every use gated and audited. This isn't a data-residency checkbox; it's the architecture. Freedom from US legal jurisdiction and the CLOUD Act isn't a risk ARES manages — it's a condition made structurally impossible by design.

ARES

For access requests, partnership discussions, or press:

contact@ares-signum.eu

← Back ARES
ARES

Terms & Conditions

ARES SIGNUM  ·  ares-signum.eu  ·  Effective: 1 January 2026  ·  Version 1.2

1. Definitions

1.1 "ARES" means the company operating the Platform, incorporated in France.

1.2 "Platform" means the ARES mobile security compliance SaaS, including the device agent, backend processing engine, dashboard, and report generation system.

1.3 "Customer" means the legal entity that creates an account and uses the Platform under these Terms.

1.4 "Device" means any Android or iOS device on which the ARES agent is installed.

1.5 "Customer Data" means all device signal data, pseudonymous device tokens, and reports generated from or associated with the Customer's account.

1.6 "Free Gap Assessment" means the no-cost tier providing fleet dashboard access with total devices enrolled and framework compliance scores across all Tier 1 frameworks, as described in Section 3.

1.7 "Subscription" means a paid annual licence to access the Platform under Tier 1 or Tier 2, as described in Section 4.

2. Acceptance

By creating an account or using the Platform, the Customer agrees to these Terms. These Terms form a binding agreement between the Customer and ARES. If the Customer does not agree, they must not use the Platform.

3. Free Gap Assessment

3.1 Scope. The Free Gap Assessment provides: fleet dashboard (total devices enrolled, framework compliance scores across all Tier 1 frameworks). The Free Gap Assessment does not include per-device detail, CEO executive risk summary, audit-ready PDF generation, or the signed JSON and CSV evidence export. Per-device detail, CEO report, audit-ready PDFs, and the signed JSON and CSV evidence export are unlocked at Tier 1.

3.2 No time limit. The Free Gap Assessment does not expire automatically. Access continues until the Customer converts to a Subscription or requests account deletion.

3.3 Conversion. The Customer may convert to a Tier 1 or Tier 2 Subscription at any time. Conversion unlocks full fleet detail, unlimited audit-ready PDF reports, the signed JSON and CSV evidence export for the frameworks included in the selected Tier, and the CEO executive risk summary. Monitoring history accumulated during the Free Gap Assessment is preserved and counts toward the Tier 2 NIST 800-124 history requirement.

3.4 Limitations. ARES reserves the right to limit Free Gap Assessment accounts if usage patterns indicate automated or abusive use.

4. Subscriptions

4.1 Tier 1 — Audit. €6,800 per year, up to 100 devices. Includes continuous fleet monitoring, NIS2, ANSSI, ISO 27001, BSI, CyFun, and FNCDP reports, unlimited audit-ready PDFs, signed JSON and CSV evidence export for all Tier 1 EU and UK frameworks, CEO executive risk summary, and OVH secure key container.

4.2 Tier 2 — Audit + NIST. €12,000 per year, up to 100 devices. Includes everything in Tier 1 plus NIST 800-124 full gap analysis, CMMC Level 2 mobile device evidence support, the extension of the signed JSON and CSV evidence export to NIST 800-124 and CMMC Level 2 evidence, and a dedicated Customer Success Manager. Requires a minimum of 3 months of Tier 1 continuous monitoring history before the first NIST 800-124 report can be generated.

4.3 Billing. Subscriptions are billed annually in advance. All prices are exclusive of applicable taxes.

4.4 Renewal. Subscriptions renew automatically at the end of each annual term unless the Customer provides written notice of non-renewal at least 30 days before the renewal date.

4.5 Device limit. Customers with more than 100 devices must contact ARES for a custom quote before activating a Subscription.

5. Acceptable Use

The Customer may use the Platform solely for the purpose of monitoring and assessing the security posture of devices under its operational control. The Customer must not use the Platform to monitor devices without the knowledge of the employing organisation, resell access to the Platform, reverse-engineer the Platform or its framework mappings, or use the Platform in any manner that violates applicable law.

6. Platform Availability

ARES targets 99.5% monthly uptime for the Platform, excluding scheduled maintenance windows. Scheduled maintenance will be notified to Customers at least 48 hours in advance. ARES does not guarantee uninterrupted access and is not liable for downtime outside its reasonable control.

7. Framework Mapping Disclaimer

Framework mappings are built from primary official sources and reviewed by qualified compliance experts. They represent ARES's interpretation of how device configuration signals relate to specific regulatory requirements. They do not constitute legal advice. Use of the Platform does not guarantee regulatory compliance or acceptance of reports by any specific regulatory authority. The Customer remains solely responsible for its own regulatory compliance obligations.

ANSSI certification of the ARES platform is not available at launch. The ARES claim of EU-sovereign architecture on OVH is valid and independent of any certification status.

8. Data Protection

8.1 Zero personal data by architecture. ARES collects only technical device configuration signals. No device identifiers (IMEI, serial number), no application lists, no location data, and no behavioural signals are collected. Device identity is represented by an opaque RSA-token generated and controlled by the Customer. ARES is not a data controller for device signals under GDPR Art. 4.

8.2 Customer key control. Each Customer account is provisioned with a dedicated OVH secure key container. The Customer's RSA key is stored in this container. ARES has zero access to the Customer's key material.

8.3 Infrastructure. All Customer Data is stored exclusively on OVH infrastructure located in France. No Customer Data is transferred outside the European Economic Area.

8.4 Sub-processors. OVH SAS (France) is the sole sub-processor engaged by ARES in connection with the Platform.

8.5 Data Processing Agreement. A full Data Processing Agreement (DPA) governing the parties' respective obligations under GDPR will be provided to the Customer prior to or at the time of account activation. The DPA forms part of these Terms. In the event of conflict between the DPA and these Terms on data protection matters, the DPA prevails.

8.6 Security. ARES implements AES-GCM and RSA-OAEP encryption for all Customer Data in transit and at rest. Access to Customer Data is restricted to the Customer via authenticated sessions. ARES personnel do not have access to Customer Data payloads.

9. Data Retention and Deletion

9.1 During the contract. Customer Data is retained and fully accessible for the duration of the active Subscription or Free Gap Assessment.

9.2 Grace period. Following the expiry, termination, or non-renewal of a Subscription, or when a Free Gap Assessment account is closed without conversion, ARES retains Customer Data for a grace period of 12 months. During the grace period, the Customer retains read-only access to the Platform for data export and report retrieval. Device signal ingestion is suspended during the grace period.

9.3 Automatic deletion. At the end of the 12-month grace period, all Customer Data is permanently and irreversibly deleted, including all device signal payloads, pseudonymous device tokens, stored PDF reports, and the Customer's dedicated OVH secure key container. ARES will notify the Customer at the start of the grace period and again at month 11. A deletion confirmation certificate is issued automatically upon completion.

9.4 Right to erasure. The Customer may request immediate deletion of all Customer Data at any time via the self-service dashboard. ARES will complete deletion within 72 hours of the request and issue a deletion confirmation certificate. The Customer acknowledges that exercising the right to erasure prior to report generation will permanently destroy the monitoring history required for NIST 800-124 Tier 2 reporting, and that this consequence is irreversible.

9.5 ARES retained records. Notwithstanding the above, ARES retains billing records, invoices, and contract metadata for 10 years in accordance with Article L123-22 of the French Code de Commerce. Anonymised aggregate statistics that cannot be linked to any Customer or Device may be retained indefinitely for product improvement purposes.

10. Intellectual Property

The Platform, including all software, algorithms, framework mappings, compliance logic, and reports generated by ARES, remains the exclusive intellectual property of ARES. These Terms do not transfer any intellectual property rights to the Customer.

The Customer retains all rights to its own Customer Data. By using the Platform, the Customer grants ARES a limited licence to process Customer Data solely as necessary to deliver the Platform services.

11. Confidentiality

Each party agrees to keep confidential all non-public information received from the other party in connection with these Terms that is designated as confidential or that reasonably should be understood to be confidential given its nature. This obligation does not apply to information that is publicly available, was already known to the receiving party, or is required to be disclosed by law or regulation.

ARES will not disclose Customer Data to any third party except OVH as sub-processor, or as required by a binding order of a French or EU court or competent authority. ARES will notify the Customer of any such order to the extent permitted by law.

12. Limitation of Liability

12.1 Exclusions. Neither party is liable for indirect, incidental, consequential, or punitive damages, including loss of profit, loss of data, or business interruption, arising from or related to these Terms, even if advised of the possibility of such damages.

12.2 Cap. ARES's total aggregate liability to the Customer for any and all claims arising under or in connection with these Terms is limited to the total fees paid by the Customer to ARES in the 12 months preceding the event giving rise to the claim. For the Free Gap Assessment, where no fees have been paid, ARES's total liability is limited to €500.

12.3 Exceptions. Nothing in these Terms limits either party's liability for fraud, gross negligence, wilful misconduct, death or personal injury caused by negligence, or any other liability that cannot be limited under applicable French law.

13. Warranties and Disclaimers

ARES warrants that the Platform will perform materially in accordance with its documentation under normal use. ARES does not warrant that the Platform constitutes legal advice, that use of the Platform guarantees regulatory compliance, or that audit reports generated by the Platform will be accepted by any specific regulatory authority. The Customer remains solely responsible for its own regulatory compliance obligations.

14. Term and Termination

14.1 Term. These Terms come into effect on the date the Customer creates an account and remain in effect until the end of the applicable Subscription term or, for Free Gap Assessment users who do not convert, until account closure and the end of the grace period described in Section 9.

14.2 Termination for cause. Either party may terminate these Terms immediately on written notice if the other party materially breaches these Terms and fails to remedy the breach within 30 days of written notice.

14.3 Termination for convenience. The Customer may terminate a Subscription at any time. No refund is provided for the unused portion of a prepaid annual Subscription unless termination is due to a material breach by ARES.

14.4 Effect of termination. On termination, the Customer's access to the Platform is suspended and the data retention provisions of Section 9 apply.

15. Modifications

ARES may modify these Terms at any time. Customers will be notified by email at least 30 days before any material change takes effect. Continued use of the Platform after the effective date of a modification constitutes acceptance. If the Customer does not accept a modification, it may terminate its Subscription before the effective date without penalty.

16. Governing Law and Dispute Resolution

These Terms are governed by French law. In the event of a dispute arising from or in connection with these Terms, the parties will attempt to resolve the matter amicably within 30 days of written notice. If no resolution is reached, the dispute will be submitted to the exclusive jurisdiction of the competent courts of Paris, France.

17. Miscellaneous

Entire agreement. These Terms, together with the DPA and any applicable order form, constitute the entire agreement between the parties regarding the Platform and supersede all prior agreements.

Severability. If any provision of these Terms is found to be unenforceable, the remaining provisions continue in full force.

No waiver. Failure by either party to enforce any provision of these Terms does not constitute a waiver of the right to enforce it in the future.

Assignment. The Customer may not assign its rights or obligations under these Terms without ARES's prior written consent. ARES may assign these Terms in connection with a merger, acquisition, or sale of substantially all of its assets.

Language. These Terms are drafted in English. In the event of any conflict between an English version and any translation, the English version prevails.

ARES
ARES SIGNUM  ·  ares-signum.eu  ·  contact@ares-signum.eu
← Back ARES
ARES

Privacy Policy — ARES Attest

ARES SIGNUM  ·  ares-signum.eu  ·  Effective: 1 September 2026  ·  Last updated: 1 September 2026

1. Who We Are

ARES Attest is published by ARES SIGNUM SAS, a company incorporated under French law, with its registered office in Frouzins, France.

For any privacy-related inquiries, contact us at: contact@ares-signum.eu

2. What ARES Attest Does

ARES Attest is a device security compliance agent. It is deployed by organisations to continuously monitor the security configuration of mobile devices in their fleet and to produce audit-ready compliance evidence.

ARES Attest is not a Mobile Device Management (MDM) solution. It does not manage, control, lock, wipe, or restrict the device in any way. It reports what the device's security configuration is — nothing more.

3. What Data We Collect

ARES Attest collects device security configuration data only: anonymous, non-personal technical readings that describe the security posture of the device. These readings cover categories such as operating system version and patch status, device encryption state, screen lock configuration, network interface states, and other security-relevant system settings.

Each reading is a factual state observation (e.g., whether a security feature is enabled or disabled). No reading identifies a person, and no reading reveals the content of any user activity.

ARES Attest also collects its own application version for fleet management purposes.

Device identity is established through a hardware-attested cryptographic key generated on the device at enrolment. This key is bound to the device hardware and cannot be extracted, copied, or used to identify the device owner.

4. What We Do Not Collect

ARES Attest does not collect any personal data. Specifically, the application never accesses, reads, or transmits:

  • Device identifiers such as IMEI, serial number, MAC address, or advertising identifier
  • Location data, whether precise or approximate
  • Contacts, call logs, or messages
  • Photos, videos, or audio
  • Files, documents, or browsing history
  • Installed application lists
  • Usernames, email addresses, or account information
  • Biometric data
  • Keyboard input or clipboard content

No GDPR Article 6 legal basis for processing personal data is required because no personal data is processed. No Data Protection Impact Assessment (DPIA) is required. No Data Processing Agreement (DPA) is required between the deploying organisation and ARES SIGNUM.

5. Legal Basis

The device security configuration data collected by ARES Attest is anonymous technical data that does not constitute personal data under the General Data Protection Regulation (GDPR). It cannot, alone or in combination with other data held by ARES SIGNUM, identify a natural person.

Where the deploying organisation considers the data to fall within the scope of GDPR due to its specific context of use, the applicable legal basis is the legitimate interest of the data controller (the deploying organisation) in maintaining the security of its device fleet, pursuant to GDPR Article 6(1)(f), or the performance of a contract between the organisation and the device user, pursuant to GDPR Article 6(1)(b).

6. How Data Is Used

The data collected by ARES Attest is used exclusively for:

  • Continuous monitoring of device security compliance against applicable regulatory frameworks
  • Generation of audit-ready compliance evidence for the deploying organisation
  • Fleet-level compliance reporting and risk visibility for the organisation's IT management and leadership

Data is never used for advertising, profiling, behavioural analysis, or any purpose unrelated to device security compliance.

7. Data Storage and Security

All data is processed and stored on EU-sovereign infrastructure operated by OVH, a French company subject exclusively to European Union law. There is no US-origin hyperscaler dependency and no exposure to extraterritorial data-access legislation.

Data is encrypted in transit between the device and the backend. Device identity is hardware-attested and cryptographically bound to the device.

8. Third-Party Sharing

Device security configuration data is shared only with the administrators of the organisation that enrolled the device. It is not sold, rented, or disclosed to any third party for any purpose.

ARES SIGNUM does not use third-party analytics, advertising, or tracking services within the application.

9. Data Retention

Data is retained for the duration of the device's enrolment with the deploying organisation, in accordance with the contractual terms between ARES SIGNUM and the organisation. Upon unenrolment or contract termination, data is deleted in accordance with applicable retention schedules.

10. Your Rights

If you believe that any data processed by ARES Attest constitutes personal data in your specific context, you may exercise the following rights under GDPR:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

To exercise any of these rights, contact your organisation's IT administrator or ARES SIGNUM directly at contact@ares-signum.eu.

You also have the right to lodge a complaint with the French data protection authority (CNIL) or with the supervisory authority of your EU member state of residence.

11. Children

ARES Attest is a business application intended for use by organisations. It is not directed at individuals under the age of 18.

12. Changes to This Policy

We may update this privacy policy to reflect changes in our practices or applicable law. The updated policy will be published at this URL with a revised effective date. We encourage you to review this page periodically.

13. Contact

ARES SIGNUM SAS
Frouzins, France
contact@ares-signum.eu