Know what is exposed. Know what it reaches.
Lodemark maps every asset you own across five strata, traces how exposure reaches regulated data, and turns the handful of paths that actually break you into owned work with a date on it.
Illustrative product data. Nothing on this site performs a live scan.
Northfleet Group · exposure surface
Demo data- S1 Edge1,284
- S2 Gateway312
- S3 Workload4,870
- S4 Identity9,615
- S5 Core486
16,567 assets across five strata, from the public edge down to regulated data. Discovery is continuous, and 37 of these appeared this week.
- Harlowe Maritime
- Vantle Payments
- Brantford Health
- Ostergaard Energy
- Kirkwall Rail
- Petronell Group
Four thousand findings is not a security programme. It is a queue.
Posture tools are good at finding things and bad at saying which of them matter. So the backlog grows, engineering learns to ignore security tickets, and the one path that genuinely reaches your customer master sits at position 812 because its CVSS score is a 6.4.
- Severity describes the vulnerability, not your environmentA critical on an unreachable host is a worse use of a Tuesday than a medium two hops from regulated data.
- Inventories are written by people who rememberThe staging clone, the acquired subsidiary’s relay and the 2021 vendor portal are never on the list.
- Nobody can prove the programme is workingOpen-finding counts go up when you look harder. That makes them useless as a board metric.
Five moves, in the order a security team actually needs them
Every surface in Lodemark maps onto one of these. If a feature does not serve one of them, it is not in the product.
- 01
Discover
Continuous discovery across domains, cloud accounts, APIs, identities, endpoints and the SaaS holding your data. Ownership is inferred, then confirmed by a human.
- 02
Understand
Assets are placed on five strata, from the internet edge down to regulated data. Relationships between them become traversable paths, not a wall of dots.
- 03
Prioritise
A finding matters when it sits on a path that terminates somewhere expensive. Everything else waits its turn, and we say so plainly.
- 04
Act
Choke points collapse many findings into one fix. Each one becomes a ticket in the tracker the owning team already uses, with an SLA and a named human.
- 05
Prove
Exposure score, path count and remediation velocity over time, with the measurement method written out so nobody has to trust the number blindly.
Everything you own, including what nobody remembers owning
How exposure actually reaches what matters
The seven paths that break you, not the 4,000 that do not
Exposure has a depth, and depth is what makes it expensive
Assets sit on five strata, from the public edge down to regulated data. A finding on S1 is an inconvenience. A path from S1 to S5 is an incident waiting for a date.
Exposure score, 26 weeks. 78 → 34.
Supplier exchange to invoice archive
An anonymous listing on the supplier exchange leaks object keys. Those keys resolve through the ingest identity, which can read the invoice archive because the bucket policy grants the analytics role without a prefix restriction.
- Entry point
- supplier-docs.northfleet.io
- Destination
- nfg-invoice-archive
- Blast radius
- 7 years of invoices · 2,140 supplier records · 4 downstream reports
This is the real interface, not a screenshot
Filter it, sort it, select a node, advance a finding. Every control below works. The data is fictional; the interface is the one that ships with the template.
Nine sections, from asset inventory to executive reporting.
Exposure trend
Weekly score across the selected range. Lower is better.
Band: Moderate · method published in the assurance pack.
Coverage
What discovery can currently see.
- Cloud accounts connected4/4
- Domains under continuous discovery118/124
- Workloads with agent or API coverage4,512/4,870
- Identity providers federated3/3
Strata
Assets by depth, and how many are currently exposed.
- S1 Edge1,28437 exposed
- S2 Gateway31214 exposed
- S3 Workload4,87061 exposed
- S4 Identity9,61528 exposed
- S5 Core4866 exposed
Needs a decision today
4 critical findings and 4 live paths reaching Core.
- Unauthenticated file listing on the partner document exchangeFND-8841 · supplier-docs.northfleet.io · 7d oldin progress
- EDI gateway runs an end-of-life TLS stackFND-8836 · legacy-edi.northfleet.io · 19d oldopen
- Machine identity holds write access across three accountsFND-8829 · svc-datalake-ingest · 14d oldtriaged
- Invoice archive readable by the analytics lake roleFND-8824 · nfg-invoice-archive · 12d oldin progress
Activity
Discovery, intelligence and posture changes in one record.
northfleet-invoices[.]co resolved for the first time. Certificate transparency match on the supplier portal name.
supplier-docs.northfleet.io began answering on a second origin pool in eu-west-2.
Blast radius widened after the analytics role gained read on a fourth prefix.
Enforcement point deployed between the campus range and the depot gateway.
Deploy identity subject claim narrowed to 13 active repositories.
Three new hosts in 185.214.44.0/24 matched the remote-access scanning pattern.
Subsidiary account nfg-baltics-prod onboarded; 412 assets discovered in the first sweep.
Six modules on one model
They share an inventory, a graph and an ownership record. That is the whole reason the findings stop contradicting each other.
Intelligence that arrives as “this affects these four assets”
Indicators are resolved against your own inventory before anyone sees them. A look-alike domain matters because it imitates the portal you actually run, not because it appeared in a feed.
- Quiet Ledger · 3 surface matchesInvoice fraud crew that harvests supplier document portals, then re-issues payment instructions from look-alike domains.
- Halverstone · 2 surface matchesSells footholds obtained from unpatched remote-access concentrators. Broad, opportunistic and fast to weaponise new advisories.
- Marrow Tide · 1 surface matchesTargets flat operational networks after commodity phishing. Exfiltrates before encryption and negotiates on stolen contracts.
It has to land where the work already happens
24 connectors across cloud, SIEM, ticketing, DevOps, identity and alerting — plus a documented REST API and signed webhooks for everything else.
“We stopped arguing about which list was right. That argument had been eating a day a week for three years.”
A security company should be the easiest vendor you ever assess
Read-only by default. Regional data residency. A published disclosure process with a named inbox and a key. No certification claims on this page that we have not evidenced in the trust centre.
Open the trust centre- Read-only discoveryWrite access is requested only for optional remediation actions and is off by default.
- Residency you chooseEU, UK, US or Canada, selected at tenant creation. Evidence never leaves that region.
- Disclosure, in publicA monitored security inbox, a published key and a stated response window.
- Export everythingNo proprietary format, no export fee, no hostage data at renewal.
Discovery is passive by default: registrars, certificate transparency, cloud control planes, identity providers and endpoint management APIs. Active checks exist, are off until you enable them per scope, and are rate-limited against surfaces you have confirmed you own.
The first discovery sweep usually completes within a day of connecting cloud, DNS and identity. Path modelling becomes meaningful once ownership resolution is roughly 60% complete, which most teams reach in three to five weeks.
It can, and for many teams it does. The material difference is that findings arrive with reachability and path context, so a posture tool's raw output stops being the thing engineering is asked to work through.
Read-only roles in each cloud account, read access to your DNS provider and identity provider, and optionally an API token for your ticketing system. Write access is requested only for optional remediation actions and is disabled by default.
In the region you select at tenant creation: EU, UK, US or Canada. Evidence and findings stay in that region. Programme customers can supply their own encryption keys.
Yes. Every asset, finding, path and remediation record is available through the API and as a bulk export. There is no proprietary format and no export fee.
See your own surface the way an attacker reads it
A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout of what was found.
Illustrative product data. Nothing on this site performs a live scan.