ARES
ARES
EN | FR | DE
Sign In Request Access
Continuous Audit Evidence

You manage mobile compliance. ARES lets you prove it.

One agent on every device. Continuous mapping across every regulation that applies to your fleet. When your auditor asks — NIS2, ANSSI, ISO 27001, BSI, CyFun, FNCDP, NCSC CAF simultaneously — the evidence chain is already built.

One click. Timestamped. Article-cited. Ready.

EU Sovereign · Zero personal data · No MDM required
NIS2· ANSSI· ISO 27001· BSI· CyFun· FNCDP 2025· NCSC CAF· NIST 800-124
Fleet Dashboard · Your company
Active monitoring
47
Devices
41
No gaps detected
6
Cross-fw gaps
NIS2 92%
ANSSI 88%
ISO 27001 74%
BSI 81%
⚠ Cross-framework gap · Xiaomi 13T Pro — 2 controls · 4 frameworks
Priority alert · highest severity gap in fleet — resolve to clear 4 frameworks simultaneously
ADB debugging active
NIS2 6.3 ISO 27001 A.8.9 BSI SYS.3.2.4.A2 ANSSI R7
→ Disable ADB
resolves NIS2 + ANSSI + ISO 27001 + BSI
Security patch level
NIS2 6.6 ANSSI R19 ISO 27001 A.8.8 BSI SYS.3.2.1.A5
→ Update security patch
resolves NIS2 + ANSSI + ISO 27001 + BSI
→ 5 more devices with active gaps · view full report
Four buying triggers

Four moments where continuous audit evidence changes the outcome.

ARES gives you a continuous, multi-framework evidence chain — per device, per control, always current. The evidence is already structured the way your auditor expects.

01 — NIS2 or ANSSI audit

The evidence is already structured the way your auditor expects.

Per device. Per control. Per framework article. Timestamped from day one. No preparation work before the audit — the record has been running continuously since deployment.

02 — US market requires compliance evidence

NIST 800-124 or CMMC Level 2 — from your EU fleet.

ARES Tier 2 produces the full monitoring history your US market needs. EU data residency on OVH — a French company subject to EU law only. No sovereignty question from any US partner.

03 — Cyber insurance renewal

Your insurer gets a continuous record, not a reconstruction.

Nothing to reconstruct at renewal. No evidence gaps. The record was running from day one — that is the evidence your insurer needs to see.

04 — Board wants a compliance posture report

Fleet-wide regulatory liability status. No extra work from IT.

ARES generates a CEO-level executive risk summary automatically — fleet-wide status, percentage compliant per framework, regulatory liability. Produced by IT, consumed by the board.

Product Architecture

One Agent. One Backend. Eight Frameworks.

A lightweight agent on every device, all intelligence in an EU-sovereign backend, three outputs designed for three different stakeholders.

Device Agent

Lightweight app deployed on every Android and iOS device. Silent background collection — no user interaction required after installation.

  • System-level security signal collection — Android and iOS
  • Zero personal data — technical signals only
  • No IMEI · No serial number · No app list · No location
  • Anonymous device identity ARES cannot reverse
  • Provisioning via QR code — no MDM required

EU Sovereign Backend

All framework mapping lives here — hosted on OVH in the EU. When regulations update, ARES updates once. Every customer current, automatically. No re-deployment.

  • Framework mapping engine — backend only, never in the agent
  • Regulatory update engine — zero client updates required
  • Multi-tenant isolation
  • Per-customer key isolation in OVH's EU KMS — keys never extractable
  • Free from US legal jurisdiction by architecture

Three Outputs

Designed outputs for three audiences. The IT manager, the CEO, and the auditor each get exactly what they need, without extra work from IT.

  • Active fleet dashboard — IT manager
  • Executive risk summary — CEO / board
  • Audit-ready PDF — one click, any framework, any date
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • Always framework-current — regulatory updates propagate automatically
  • Continuous monitoring log — the history IS the evidence

Framework mapping lives in the backend only

When NIS2, ANSSI, BSI, ISO 27001, CyFun, FNCDP, NCSC CAF or NIST updates — ARES updates once. Every customer is automatically current. No client update. No re-deployment. No manual mapping review on your side. Device signals are mapped against the CIS Android control set — one signal set, eight frameworks, zero redundant collection.

Zero GDPR Friction — By Architecture

Deploy today. Free of process delays.
GDPR compliance is built in.

Every MDM and MTD competitor requires your organisation to process employee personal data before deploying a single agent. ARES collects zero personal data by architecture — which changes everything about how and when you deploy.

Every MDM and MTD competitor
✗ Collects personal data — GDPR Article 6 processing basis required
Device identifiers, app inventories, or behavioural signals. Article 6 basis must be established before the first device is enrolled.
✗ Mandatory DPIA under Article 35
Employee device monitoring is explicitly high-risk per EDPB guidance. DPIA is not optional.
✗ DPA negotiation with the vendor required before the first device is enrolled
Standard DPA may not cover your specific use case. Legal review required before any data flows.
✗ Works council consultation required — 4–8 week process in France
CSE consultation on employee monitoring. Germany: Betriebsrat. Belgium and Ireland: equivalent bodies.
✗ DPO review required
Processing basis, retention period, data subject rights, employee notice obligations.
Deployment requires HR, legal, DPO, and employee representatives before a single device is enrolled.
ARES
✓ Deploy the moment you decide — zero legal prerequisites
ARES collects only technical device configuration — not personal data under GDPR Art. 4 by definition.
✓ No DPIA under Article 35
Not high-risk by definition. No employee monitoring. No behavioural data.
✓ Your legal team stays out of it
ARES collects no personal data — no data processor relationship exists, no DPA required before deployment.
✓ HR and employee reps are not in the loop
France (CSE), Germany (Betriebsrat), Belgium, Ireland, Romania — none required. Zero personal data triggers no obligation.
✓ Your DPO has nothing to sign off
No processing basis to establish. No DPIA to commission. No data subjects to notify.
Deploy on any device. Today. No prerequisites.
Privacy Architecture

Zero Personal Data. Beyond US Jurisdiction.

ARES gives you full device-security visibility without the liability that usually comes with it. There's no personal data to breach, no identity we could expose if we tried, and no foreign government that can reach your data. Privacy and sovereignty aren't clauses in a contract here — they're built into the architecture.

Layer 1 — What We See

Security Posture, Not Surveillance

ARES reads a device's security configuration — never its contents, its location, or how your people use it. Employees aren't being watched; their device's security posture is what's assessed. That distinction clears works council and DPO review instead of stalling there.
  • Reads what makes a device safe — patch level, encryption, screen lock, boot integrity — and stops there
  • Location-free, and without access to messages, files, browsing, or app lists
  • Confirms a device is secure with no IMEI, serial number, or employee name attached
  • Outside GDPR Art. 4 personal data — one less data-protection liability to carry
Layer 2 — Who It's About

We Can't Identify Your People — By Design

To ARES, every device is an anonymous token. We can't reverse it to a device, a person, or an employee — and neither can anyone who breaches us. The only map from token to identity lives inside your systems, under your control.
  • Device identity is a one-way fingerprint of a key that never leaves the device's secure hardware
  • The original hardware identifier is discarded the moment a device enrols — never stored
  • Even with full access to our database, ARES cannot put a name to a signal
  • You hold the only link between a token and an employee — ARES never sees it
Layer 3 — Where It Lives

EU-Sovereign Key Custody

Every customer key is generated and held inside OVH's EU key service — and can never be exported in raw form.
  • Per-customer cryptographic isolation — its own dedicated certificate authority and keys
  • Private keys can never be extracted or copied — every key operation is gated and audited
  • Your data, reports, and keys never leave the EU — full European legal sovereignty
  • Immune to the US CLOUD Act and foreign data demands — by jurisdiction, not by promise
Privacy

One Cookie. Nothing Else.

This site keeps cookies to what's strictly necessary to run it — nothing for tracking, advertising, or analytics, and no third parties. Here's exactly what's set and when.

Browsing the Site

No Cookies Set

Pages, pricing, and documentation load with nothing stored in your browser.

Signing In to the Dashboard

One Cookie, Strictly Necessary

One cookie is set, solely to keep you signed in. It carries no tracking value and is never shared with a third party.

No consent banner is shown because this cookie is strictly necessary — it exists only so you stay logged in, not to track or profile you.

Framework Coverage

Eight Frameworks. One Deployment. Zero Overlap Work.

Every framework maps against the same device signal set, simultaneously. Every collection generates evidence across all eight frameworks at once. One deployment covers your entire regulatory stack.

NIS2
EU Directive 2022/2555
Mandatory for all EU essential and important entities. Mobile device security mandated under Article 21. Continuous monitoring evidence is what auditors evaluate — not a point-in-time assessment.
EU Law Tier 1
ANSSI
French National Cybersecurity Agency
French NIS2 transposition guidance and mobile security recommendations. ARES provides the mobile device technical evidence required for DAT-NT-010/ANSSI/SDE (R1–R21) technical guidance — no manual evidence gathering.
France Tier 1 DAT-NT-010 · R1–R21
ISO 27001
International Standard — 2022 Revision
Device-layer Annex A controls for certification audit preparation. Widely required across EU sectors and as a customer contractual requirement. Continuous monitoring log supports certification body review.
Certification Tier 1
BSI Grundschutz
German Federal Office for Information Security
German SME cybersecurity standard — critical for DACH market entry and supply chain compliance. SYS.3.2 mobile device module coverage with full evidence chain.
Germany · DACH Tier 1
CyFun 2025
CCB — Belgium · Ireland · Romania
Belgium's national NIS2 framework — mandatory for all NIS2-scoped entities. Co-owned by Belgium, Ireland, and Romania. Maps directly to ISO 27001 and CIS Controls.
Belgium · Ireland · Romania Tier 1
FNCDP 2025
ACN — Italy · NIST CSF 2.0 aligned
Italian National Framework for Cybersecurity and Data Protection — voluntary, aligned with NIST CSF 2.0. Relevant for Italian NIS2 entities and EU companies with Italian operations.
Italy Tier 1
NCSC CAF 4.0
UK National Cyber Security Centre — NIS Regulations · Essential Services
The UK's mandatory outcome-based framework for Operators of Essential Services — legally separate from NIS2 since Brexit, enforced independently by UK Competent Authorities. EU groups with UK subsidiaries, and UK companies with EU operations, now face two diverging audit regimes simultaneously. ARES resolves the overlap: the same device signal set maps against CAF Objectives A, B and C alongside NIS2 Article 21 simultaneously — one deployment, two evidence chains, no redundant collection.
UK · Ireland · Cross-border EU Tier 1
NIST 800-124
US National Institute of Standards and Technology
Required for EU companies with US market compliance obligations. The same device signal set separately maps to CMMC Level 2 evidence (NIST SP 800-171 Rev 2) for EU defense supply chain companies. Requires 3+ months continuous Tier 1 monitoring history.
US Market · Tier 2 CMMC Level 2 Evidence
DORA
EU Regulation 2022/2554 — Financial Sector
For financial entities subject to DORA, ARES continuous monitoring provides direct evidence for Article 9(4)(c) endpoint security control requirements. No additional deployment. Your Tier 1 data covers it. Scope boundary: one article of forty — ARES never claims DORA compliance.
Financial Sector · Art. 9(4)(c) Evidence Tier 1
Who This Is For

Built for the person who deploys it and the person who signs off the report it produces.

No dedicated security team. No procurement committee. One deployment covers both roles.

IT Manager / DSI

Deploy, monitor, and report — without a project.

  • QR code provisioning — any Android or iOS device in under an hour
  • No MDM, no Azure AD, no IT certification required
  • No DPO, no HR involvement — zero personal data by architecture
  • Fleet-wide compliance status across all frameworks at a glance
  • Audit-ready PDF generated in one click — any framework, any date
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • CEO executive risk summary ready to share upward without extra work
CISO / RSSI

Cross-framework gap intelligence and continuous evidence.

  • Simultaneous gap and overlap view across all applicable frameworks per device
  • Complete evidence history — audit-ready at any point, no preparation required
  • ANSSI DAT-NT-010 technical evidence — no manual gathering
  • Always current on regulation updates — backend mapping, zero re-deployment
  • OVH sovereignty — defensible to any NIS2 supervisor on data residency
  • Timestamped evidence chain per control, per framework, per device
Three Outputs

What ARES Delivers to Each Stakeholder

One platform. Three audiences. Each output designed for its reader.

IT Manager

Continuous Fleet Dashboard

Per-device status across all frameworks simultaneously. One fix resolves gaps across multiple frameworks at once. No manual aggregation.

  • Per-device compliance status by framework
  • Cross-framework gap and overlap view
  • Alert on posture degradation
  • Continuous monitoring log for audit evidence
CEO / Board

Executive Risk Summary

Fleet-wide regulatory liability status in plain language. Produced by the IT manager, consumed by the board. No technical jargon. No extra work.

  • Single risk indicator — compliant / action required
  • Fleet compliance percentage by framework
  • Regulatory liability status
  • Boardroom-ready — no translation required
Auditor / US Market

Audit-Ready PDF and Evidence Export

The PDF is the document your compliance lead uses to validate the purchase internally and hand to your auditor. One click. Evidence chain per control. Cites framework articles directly. The signed JSON and CSV export is the raw data that proves what the PDF states.

  • Signal → control → standard article reference
  • Timestamped evidence per device
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • Full monitoring history — audit readiness evaluated over time, not at a single point
  • Scope limitations stated explicitly as precision, not weakness

NIST 800-124 report requires a minimum of 3 months of Tier 1 monitoring history.

Not Your MDM/EMM

Your MDM/EMM manages your devices. It cannot produce this document.

ARES is the compliance intelligence and audit evidence layer MDMs cannot provide and were never designed to provide.

What your MDM does

Device management and policy enforcement

  • Enrolls and manages corporate devices
  • Enforces configuration policies (screen lock, encryption)
  • Pushes apps and certificates
  • Wipes lost or stolen devices remotely
  • Cannot map device signals against NIS2 Article 21 specifically
  • Cannot produce a timestamped, article-cited evidence chain
  • Cannot cover unmanaged or BYOD devices with audit evidence
  • Cannot show cross-framework gap and overlap view
  • Cannot generate an audit-ready PDF for an external auditor
  • Triggers GDPR Art. 6 processing basis — DPIA, DPA, works council
What ARES adds

Compliance intelligence and audit evidence

  • Maps device signals against NIS2 Art. 21, ANSSI, BSI, CyFun, ISO 27001, NCSC CAF simultaneously
  • Timestamped evidence chain — per device, per control, per framework
  • Covers any device — managed, unmanaged, BYOD — via QR code
  • Cross-framework gap and overlap view — one fix resolves multiple frameworks
  • One-click audit-ready PDF — any framework, any date, full monitoring history
  • Signed JSON and CSV evidence export — per device, every framework in your tier, full monitoring history
  • Zero personal data — no GDPR processing basis, no DPIA, no works council
  • EU-sovereign on OVH — defensible to any NIS2 supervisor on data residency
Aligned with how NIS2 audits are actually evaluated. Audit readiness is assessed over time, not at a single point — ARES maintains that continuity automatically. The monitoring history IS the evidence. A gap in the record is a gap in the evidence.
Mapping Methodology

How ARES mappings are built and maintained.

Every claim ARES makes in an audit report is traceable to a source document and a specific device signal. This is how that traceability works.

01 — Source

Built from primary sources

Each framework mapping is built directly from the official published standard — NIS2 Directive text, ANSSI mobile security guides, BSI SYS.3.2 module, ISO 27001:2022 Annex A, CyFun 2025 specification, FNCDP 2025 documentation, NCSC CAF 4.0 guidance, NIST SP 800-124 Rev. 2. No secondary interpretation. No aggregator shortcuts.

02 — Backbone

CIS Android and Apple iOS Benchmarks as technical backbone

Device signals are mapped against the CIS Android Benchmark and the CIS Apple iOS Benchmark — both platforms, both signal sets. This single backbone drives all eight framework mappings simultaneously — eliminating redundant data collection and ensuring consistent evidence across every framework in every report, for every device in your fleet.

03 — Review

Expert review before pilot launch

All framework mappings are reviewed by a qualified compliance expert with ANSSI-specific experience before any customer deployment. Framework accuracy is a product liability — not an assumption. Reports cite the specific article and control that each device signal satisfies or fails.

04 — Currency

Maintained continuously in the backend

Framework mappings live in the ARES backend — not in the device agent. When NIS2, ANSSI, BSI, ISO 27001, CyFun, FNCDP, NCSC CAF, or NIST updates, the mapping updates once. Every customer's next report reflects the current standard. No client re-deployment. No manual review on your side.

Transparent Pricing

Free Gap Assessment · Tier 1 Audit · Tier 2 Audit + NIST

One price per tier. No per-device math. No hidden bundles. Every deployment is scoped before you commit.

Start Here
Free Gap Assessment
€0
Your fleet · All Tier 1 frameworks · From device one
See your full compliance picture across every Tier 1 framework from the moment your first device enrols — no credit card, no commitment.
  • Fleet dashboard — total devices enrolled, framework compliance scores across all Tier 1 frameworks
  • Compliance picture at fleet scale — per-device detail and audit reports unlocked at Tier 1
  • Continuous monitoring starts on enrolment — history preserved at conversion
  • Dashboard access — no time limit, no expiry
  • No credit card · No commitment
Start Free Assessment
Most Popular
Tier 1 — Audit
€6,800/year
Up to 100 devices · More than 100? Contact ARES
NIS2 enforcement is active. Your auditor is asking for continuous mobile device compliance evidence. ARES gives you a continuous, audit-ready answer across NIS2, ANSSI, ISO 27001, BSI, CyFun, FNCDP and NCSC CAF — one click, any time, always current.
  • Continuous fleet monitoring — Android and iOS
  • NIS2 · ANSSI · ISO 27001 · BSI · CyFun · FNCDP · NCSC CAF reports
  • Unlimited audit-ready PDF reports — any framework, any date
  • Signed JSON and CSV evidence export — per device, all Tier 1 EU and UK frameworks, full monitoring history
  • CEO executive risk summary
  • Dedicated EU key isolation included
  • Priority support
Start Tier 1
US Market
Tier 2 — Audit + NIST
€12,000/year
Up to 100 devices · Requires 3 months Tier 1 history
Everything in Tier 1, plus full NIST 800-124 gap analysis and a complete monitoring history evidence chain — ready for your US market audit. Tier 2 monitoring data separately generates CMMC Level 2 mobile device evidence (NIST SP 800-171 Rev 2) for EU companies in the US defense supply chain.
  • Everything in Tier 1
  • Signed JSON and CSV evidence export extended to NIST 800-124 and CMMC Level 2 evidence
  • NIST 800-124 full gap analysis report
  • CMMC Level 2 mobile device evidence support
  • Full monitoring period evidence chain for US market audit
  • Dedicated Customer Success Manager
Start Tier 2
›

A manual compliance audit costs €6,000–€25,000 per engagement.† It produces a point-in-time snapshot — accurate on signing day, outdated as your fleet changes. ARES produces continuous evidence across eight frameworks simultaneously, updated automatically when regulations change, for a flat annual fee. One invoice. No re-engagement cost when NIS2 updates. The monitoring history IS the evidence — a gap in the record is a gap in the evidence.
† EU SME compliance audit range €6,000–€25,000. Sources: Secfix 2025 · Digitemis FR 2025 · Feel Agile EU 2025. Comparison covers compliance assessment and continuous evidence-gathering, not full ISMS implementation.

Before you start Tier 2: a minimum of 3 months of Tier 1 continuous monitoring history is required before your first NIST 800-124 report can be generated. The report covers your full monitoring period on record — credible and defensible to US partners. Tier 2 includes Tier 1. There is no NIST-only subscription.

Start with the right scope.

We run a free gap assessment on your fleet. You see your posture at fleet scale — total compliance picture across all Tier 1 frameworks, from the moment your first device enrols.
Your next audit is already in progress — every day ARES runs is evidence.

How many devices?  ·  Android, iOS, or mix?  ·  Which frameworks apply?  ·  When is your next audit?

contact@ares-signum.eu

For Cybersecurity Providers

Add a continuous mobile compliance evidence layer to your NIS2 offer.

MSSPs and cybersecurity consultancies serving EU SMEs have no purpose-built tool to provide continuous, audit-ready mobile device compliance evidence. ARES fills that gap — you refer, ARES invoices your customer directly, and you earn a recurring referral fee for the lifetime of the contract.

Referral model

You introduce the customer. ARES invoices directly and owns the relationship. You receive an ACV referral fee annually, recurring as long as the customer stays.

No product investment

You do not resell, white-label, or maintain ARES. You add a capability your customers need and your portfolio currently lacks — with zero product overhead.

Complete the NIS2 offer

ARES is the continuous device evidence layer your existing NIS2 governance and documentation work cannot provide. Additive to everything you already deliver.