Legislative Decree 138/2024 · NIS2 baseline measures in force

NIS2 baseline measures
by 31 October 2026. Get there ready.

30-day free trial No credit card required Self-serve sign-up
Decision flow: am I a NIS2 entity? Sector in the annexes of Legislative Decree 138/2024, company size, registration on the NIS platform
Built for teams in
ManufacturingHealthcarePublic sectorLegalLogisticsFinanceAutomotiveEnergy & utilitiesIT & MSPs
What Sherlock Guard does

Twenty-three capabilities,
one console.

Collect, connect, classify, prioritize, automate, manage vendor and incident risk, coordinate regulatory work, draft DPAs, train your people, and prove compliance — without stitching together a dozen tools.

Collection

Endpoint agent

The sgagent CLI inventories your machines — packages, applications, services, OS/EOL — and flags vulnerabilities with guided remediation. From the install command generated in the console to a live agent in under two minutes.

  • Windows · Linux · macOS
  • 2-minute install, defensive & on-box only
  • CVE matching (OSV · NVD · MSRC)
  • Signed self-update + watch mode
Connectors

Data connectors

Pull findings straight from systems you own: GitHub, GitLab and Gitea repositories, plus AWS, Azure, GCP and Microsoft 365 cloud accounts.

  • GitHub, GitLab & Gitea (Dependabot, repos)
  • Cloud spend anomalies + Defender/SCC posture
  • M365 secure score, MFA gaps & risky users
  • HIBP breached-account monitoring
Classification

Classify, enrich & triage

Findings are classified by severity, tagged with CWE and enriched with CVE context — AI-assisted with a deterministic fallback — then reviewed, assigned and annotated by your analysts.

  • AI-assisted + deterministic fallback
  • CWE/CVE context
  • Analyst review workflow
  • Incidents & clustering
Intelligence

CTI & prioritization

Threat feeds plus KEV and EPSS signals to prioritize what's actually exploited — with a grounded CTI Q&A assistant.

  • Threat feeds (TAXII/MISP)
  • KEV + EPSS prioritization
  • CTI Q&A with sources
Automation

Triage & response

Auto-triage rules, playbooks, metric alerts and outbound actions: notify signed webhooks or open tickets in your own Jira / ServiceNow.

  • Auto-triage rules
  • Playbooks, alerts & signed webhooks
  • Jira / ServiceNow tickets
Compliance

Guided compliance

Step-by-step procedures for NIS2/ACN, the Cyber Resilience Act, ISO 27001, CIS Controls v8, DORA, GDPR, SOC 2, NIST CSF 2.0, PCI DSS, TISAX (automotive, VDA ISA), ISO 13485 (medical devices) and ISO 22716 (cosmetics GMP): checklists, evidence attachable to every step, decisions that conclude which obligations are yours, and a branded handbook — in Italian and English. Plus your open findings mapped to the controls of 13 frameworks, with a curated crosswalk between them, including what the agent finds on your machines. Audit readiness assembles a unified accountability dossier from that evidence, exports it for a certification body (PDF/JSON/ZIP with checksum), and shares a read-only portal with an external auditor who records findings — evidence of review, not a certification.

  • Guided paths for all 13 frameworks: NIS2/ACN, CRA, ISO 27001, CIS v8, DORA, GDPR, SOC 2, NIST CSF, PCI DSS, TISAX, ISO 13485, ISO 22716 (IT/EN)
  • 13 frameworks + crosswalk mapping
  • Accountability dossier + certification export
  • External-auditor portal with findings
Regulatory operations

Regulatory traceability

Run a regulatory, contractual or audit matter from its source or confirmed clause through obligations, ownership, evidence, approval, communication, receipt and a checksum dossier. Version contracts and review AI-assisted, cited clause proposals manually; then use live deadlines, recurring obligations and pilot trends to find work that needs attention. The workspace supports human decisions — it does not determine legal applicability or compliance.

  • Matter–obligation matrix with evidence links
  • Actions, RACI, reminders & communication packs
  • Checksum dossier export + delivery proof
  • Deadlines, bottlenecks, recurrence & pilot trends
Third-party risk

Vendor & TPRM

Manage your suppliers as a portfolio: onboarding, risk tiering and scoring, security assessments sent and scored, contract and DPA tracking with renewal reminders — evidence gathered through a public assessment portal. Advanced scoring adds a portfolio risk heatmap, per-vendor score trend (delta & slope) and a curated sector benchmark.

  • Vendor register & risk scoring
  • Portfolio heatmap, score trend & sector benchmark
  • Assessment campaigns + public portal
  • Contracts, DPAs & renewal reminders
Incident response

Incident management

Run security incidents end to end: case timeline, tasks, evidence custody and the NIS2/ACN 24h/72h regulatory-notification workflow — with playbooks to standardise the response. Advanced reporting adds a visual swimlane timeline, checklist templates, per-task approvals and Jira/ServiceNow ticket linkage with pull sync.

  • Case timeline, tasks & evidence custody
  • 24h/72h regulatory notification
  • Visual timeline, checklists & task approvals
  • Jira/ServiceNow ticket linkage (pull sync)
Governance & privacy

Governance & RoPA

A governance register for decisions and approvals, a GDPR Record of Processing Activities (RoPA) with processors and DPAs, and policy management — the organisational half of compliance, not just the technical one.

  • Decision & approval register
  • GDPR RoPA, processors & DPAs
  • Policy lifecycle management
Accountability

RACI & delegations

Make accountability explicit: assign R/A/C/I roles to people on any resource, register formal delegations of authority with a legal or operational mandate, record a legal review as evidence, and read each delegation's tamper-evident audit trail. Governance decisions get a named Accountable owner. A recorded review is evidence, never a claim of legal validity.

  • RACI matrix across any resource
  • Legal & operational delegations + review
  • Per-delegation audit trail
Privacy · Legal

DPA generator

Draft Data Processing Agreements (GDPR Art. 28) from versioned templates, merging vendor and RoPA data into the clauses, with clause variants by vendor risk. Send a draft to external counsel through a secure review portal, record their verdict, sign off internally with two-person approval, and promote the approved agreement into your contract register with renewal tracking. Drafts only — never a claim of legal validity.

  • GDPR Art. 28 templates + risk-based clauses
  • External legal-review portal + verdict
  • Two-person approval → contract handoff
Training

Security awareness

Assign the right security training to the right people: a predefined, versioned course catalogue with a course for every one of the 13 compliance frameworks (ISO 27001, ACN, NIS2, GDPR, CRA, SOC 2, PCI DSS, NIST CSF, CIS v8, DORA, TISAX, plus ISO 13485/22716 quality-GMP) auto-assigned by role, with due dates and recurrence when a certificate lapses, generated PDF certificates, a per-course guide with by-role expectations and the regulator link, and completion reporting surfaced as a positive attestation on the Compliance pages. It surfaces material and records completion — it does not host full course content (video/SCORM) or grade an exam.

  • Predefined catalogue for all 13 frameworks
  • Auto-assign by role + recurrence
  • PDF certificates + completion reporting
CRA / SBOM

Product SBOMs

Upload each product's CycloneDX SBOM: components are matched against CVE sources, re-uploads reconcile automatically, VEX records your triage decisions — and one search answers the Log4j question across every product.

  • Per-product SBOM inventory + VEX
  • KEV triggers, Art. 14 readiness panel
  • “Are we affected?” component search
Trust

Documents & questionnaires

A document library for policies, certificates and audit evidence; a grounded document Q&A that answers from your library with citations; security questionnaires answered for you from your live coverage; a public, NDA-gated trust portal for your customers.

  • Document library + Q&A (RAG with citations)
  • Questionnaire auto-answer
  • Public trust portal (NDA-gated)
Reporting

Compliance exports

Produce CSV, JSON and PDF exports — with formula-injection-safe CSV — plus scheduled recurring reports, ready for audits.

  • CSV / JSON / PDF
  • Formula-safe CSV
  • Scheduled reports
Insurance

Insurance integration

Deliver your cyber-insurance / posture report straight to a broker or insurer — as an email attachment or a signed webhook — with a tracked send history, and keep policy renewals on the radar with due dates and status reconciliation.

  • Broker/insurer delivery templates
  • Direct report send + history
  • Policy-renewal tracking
SecOps

SIEM & SOC integration

Receive alerts pushed from your SIEM/SOC (Splunk, Elastic, QRadar, Sentinel or any source) over a tokenised inbound webhook, correlate them to incidents with a confidence score, and open incidents automatically with SOC playbooks. Inbound and defensive only — we never reach out to your SIEM.

  • Inbound alert webhook (token-gated)
  • Alert↔incident correlation + confidence
  • SOC playbooks: auto-open / enrich / notify
Interoperability

External GRC integration

Interoperate with ServiceNow GRC, OneTrust, Archer and other GRC platforms via standard formats: export controls, findings and risks as JSON/XML/CSV (download or signed webhook), and import external frameworks into your control model with control-to-control mapping. Standard-format interoperability — no fragile vendor lock-in.

  • Export controls/findings/risks (JSON/XML/CSV)
  • Import external frameworks + map controls
  • ServiceNow GRC / OneTrust / Archer profiles
Compliance

Authority integration

Notify authorities by real PEC (certified email over standard SMTP/IMAP) with your provider mailbox — Aruba, Postel, Italpost — and keep the official proof trail: acceptance/delivery receipts pulled automatically, plus the ACN/CSIRT portal protocol number. PEC is a real transport; portal submission stays operator-driven (no fabricated authority API).

  • Real PEC send + receipt pull
  • Aruba / Postel / Italpost mailboxes
  • Official receipts & portal protocols
Visibility

Dashboards & risk

An executive dashboard and threat overview for management, custom widgets, a risk register, an asset graph and cross-module search — the state of your security at a glance.

  • Executive & threat overview
  • Risk register
  • Asset graph, hunt & search
Identity

Enterprise access

Sign in with your corporate identity provider: SSO via OIDC (Entra ID, Google) and SAML 2.0 (ADFS and legacy IdPs), with SCIM 2.0 and JIT provisioning and enforced SSO. 2FA and custom role-based access for everyone.

  • SSO: OIDC + SAML 2.0
  • SCIM 2.0 + JIT provisioning
  • 2FA (TOTP) + custom roles
Support

Help that answers

Contextual help on every page, an AI assistant grounded on curated product knowledge, and live chat with a human operator when you need one.

  • Live chat: AI + operator
  • Contextual help everywhere
  • Guides & documentation
How it works

Sign up, collect,
review.

No six-month rollout. Create an org, deploy the agent to inventory your hosts — or upload logs and CSV from the console — and let the worker do the first pass.

01

Sign up & create your org

Start a 30-day free trial — no card. Your tenant is provisioned with row-level isolation in Postgres.

02

Deploy the agent or connect your sources

Generate the install command in the console and paste it on each host — under two minutes to a live agent, defensive and on-box only, on Windows, Linux and macOS. Or connect GitHub, GitLab, Gitea, AWS, Azure, GCP, Microsoft 365 and HIBP, or upload logs, CSV and product SBOMs from the console.

03

Classify, review, export

The worker classifies findings; analysts review and triage; you export compliance-ready reports.

sgagent · quickstart
$ sgagent register --backend $API --token $TOKEN→ registered: device 9f3a…          ok$ sgagent collect 412 packages · 31 services · OS/EOL (1.2s)$ sgagent watch --interval 300→ collecting every 5m · on-box only$ sgagent recommendations --ndjson{"action":"upgrade","pkg":"openssl"} ×3
100% EU
Software & data
made in Italy, EU-hosted
13
Compliance frameworks
from SOC 2 to ISO 13485
8
Data connectors
GitHub · GitLab · Gitea · AWS · Azure · GCP · M365 · HIBP
RLS
Tenant isolation
enforced in Postgres
Plans

Plans that grow with you.

Every plan starts with a 30-day free trial — no card. Prices are per month, billed in EUR, VAT excluded.

Monthly, semiannual (−10%) or annual (−20%) billing — pick the cadence above the cards. Active promotions are shown on each card.

Plus
€100/ monthVAT excl.

For small teams getting started with real workloads.

  • 25 monitored assets (extra: €2.00/asset/mo)
  • 2 analysts + unlimited viewers
  • GitHub, GitLab, Gitea, AWS, Azure, GCP, M365 & HIBP connectors
  • Document library (20 docs)
  • CSV export
  • API access
  • 90-day retention
  • Email support (48h)
Start free trial
Most popular
Pro
€300/ monthVAT excl.

The complete plan: more formats, watch mode, audit export.

  • 150 monitored assets (extra: €1.80/asset/mo)
  • 8 analysts + unlimited viewers
  • GitHub, GitLab, Gitea, AWS, Azure, GCP, M365 & HIBP connectors
  • Document library (100 docs)
  • CSV + JSON export
  • Scheduled watch mode
  • Public trust portal (NDA-gated evidence)
  • Audit export
  • 1-year retention
  • Email support (24h)
Start free trial
Max
€700/ monthVAT excl.

High volume, every format, custom dashboards and MSP multi-tenant.

  • Everything in Pro, plus:
  • 500 monitored assets (extra: €1.60/asset/mo)
  • 25 analysts + unlimited viewers
  • Document library (500 docs)
  • All export formats (CSV/JSON/PDF)
  • Custom dashboard widgets
  • MSP multi-tenant
  • 2-year retention
  • Chat support
Start free trial
Just exploring? Start freeLarger or multi-tenant needs? Enterprise is custom-priced — contact us.
Ready to start?

Create your account and run your first classification in minutes.

Start free trial Already have an account? Sign in
30-day trial · no credit card required.