← Back ARES
About ARES

Mobile compliance is the gap every NIS2 audit exposes.

Most European SMEs entering their first NIS2 audit discover the same problem: they have no continuous, audit-ready evidence of their mobile device security posture. Policies exist on paper. The devices tell a different story. ARES was built to close that gap — automatically, continuously, at a price that makes sense for a 50-person company in Lyon or a logistics firm in Düsseldorf.

NIS2 Article 21 mandates continuous device security monitoring. The tools that existed before ARES were built for enterprise teams with dedicated security staff and six-figure budgets — Jamf, Intune, CrowdStrike. Powerful, expensive, and designed for a world very different from an SME trying to pass its first audit. ARES is the precision instrument built instead.

What ARES Does

ARES is an EU-sovereign mobile security platform that turns device signal data into audit-ready compliance evidence — automatically, continuously, and affordably. One lightweight agent on each device monitors the security posture signals that regulators evaluate: encryption status, patch level, screen lock, secure boot, developer mode, VPN configuration. No personal data. No IMEI. No location tracking.

That signal data feeds a single backend — hosted entirely on OVH in the EU — that maps posture against eight frameworks simultaneously: NIS2, ANSSI, ISO 27001, BSI Grundschutz, CyFun 2025, FNCDP 2025, NCSC CAF 4.0, and NIST 800-124, plus DORA Art. 9(4)(c) as an endpoint security evidence layer for financial entities. When a regulation updates, the mapping updates once in the backend. Every customer is automatically current. No re-deployment. No manual review.

Three outputs for three audiences: an active fleet dashboard for the IT manager, an executive risk summary for the CEO, and a one-click audit-ready PDF for the auditor or US supply-chain partner. Tier 1 includes a signed JSON and CSV export of the raw evidence data for all Tier 1 EU and UK frameworks; Tier 2 extends it to NIST 800-124 and CMMC Level 2 evidence. Per device, full monitoring history.

Why EU Sovereignty Matters

ARES runs entirely within the EU. Every device signal, every report, every encryption key sits on OVH's European infrastructure — operated by a French company under EU law alone, with no US hyperscaler anywhere in the stack. Each customer's keys are cryptographically isolated, never leave OVH's key service, and cannot be extracted or copied — every use gated and audited. This isn't a data-residency checkbox; it's the architecture. Freedom from US legal jurisdiction and the CLOUD Act isn't a risk ARES manages — it's a condition made structurally impossible by design.

ARES

For access requests, partnership discussions, or press:

contact@ares-signum.eu