Platform
Six modules, one model of your exposure
They share an inventory, a graph and an ownership record. That is why the findings stop contradicting each other, and why a path can be scored by where it ends rather than by how bad the CVE sounds.
Demo tenant at a glance
- Assets
- 16,567
- Exposure score
- 34
- Live paths to Core
- 7
- Median critical fix
- 4.2 days
The modules
Each one answers a different question about the same estate
The strata
Depth is the organising idea
Everything Lodemark discovers is placed on one of five strata. Findings inherit the depth of the asset they sit on, and paths are only interesting when they cross from shallow to deep.
- 01Discover — Continuous discovery across domains, cloud accounts, APIs, identities, endpoints and the SaaS holding your data. Ownership is inferred, then confirmed by a human.
- 02Understand — Assets are placed on five strata, from the internet edge down to regulated data. Relationships between them become traversable paths, not a wall of dots.
- 03Prioritise — A finding matters when it sits on a path that terminates somewhere expensive. Everything else waits its turn, and we say so plainly.
- 04Act — Choke points collapse many findings into one fix. Each one becomes a ticket in the tracker the owning team already uses, with an SLA and a named human.
- 05Prove — Exposure score, path count and remediation velocity over time, with the measurement method written out so nobody has to trust the number blindly.
- S1EdgeAnything the public internet can reach without credentials.1,28437 exposed
- S2GatewayIngress control: load balancers, WAF, VPN, API gateways.31214 exposed
- S3WorkloadCompute, containers, functions and the services they run.4,87061 exposed
- S4IdentityHuman accounts, machine identities, roles and entitlements.9,61528 exposed
- S5CoreRegulated data stores, secrets and the systems of record.4866 exposed
The console
Nine working sections, one dataset
Sort the table, focus a node, advance a finding. Every control is live.
| Stratum | Owner | |||||
|---|---|---|---|---|---|---|
| partners.northfleet.io | Domains & DNS | Edge | Platform Web | critical | 4 | 2024-11-03 |
| nfg-invoice-archiveCrown jewel | Cloud resources | Core | Finance Systems | critical | 3 | 2023-02-19 |
| svc-datalake-ingest | Identities | Identity | Data Platform | critical | 2 | 2023-08-27 |
| legacy-edi.northfleet.io | Services | Edge | Integration | critical | 7 | 2021-11-19 |
| api.northfleet.io/v2/consignments | APIs | Gateway | Freight Platform | high | 6 | 2024-04-08 |
| staging.tenders.northfleet.io | Domains & DNS | Edge | Commercial | high | 5 | 2025-06-14 |
| nfg-prod-eks-freight | Cloud resources | Workload | Freight Platform | high | 9 | 2023-01-11 |
| vpn-ams-02.northfleet.io | Endpoints | Gateway | Network Ops | high | 3 | 2022-09-30 |
| nfg-customer-pii-euCrown jewel | Cloud resources | Core | Data Platform | high | 2 | 2022-05-16 |
| ci-runner-fleet-07 | Endpoints | Workload | Developer Experience | high | 4 | 2024-07-05 |
| depot-scada-rtd-12 | Endpoints | Workload | Facilities | high | 2 | 2022-08-08 |
| supplier-docs.northfleet.io | Domains & DNS | Edge | Procurement | high | 4 | 2025-01-30 |
| crew-scheduling.northfleet.io | Services | Workload | People Ops | medium | 2 | 2024-01-22 |
| nfg-secrets-prodCrown jewel | Cloud resources | Core | Platform Security | medium | 1 | 2023-04-04 |
| api.northfleet.io/internal/pricing | APIs | Gateway | Commercial | medium | 3 | 2025-02-27 |
| svc-github-deploy | Identities | Identity | Developer Experience | medium | 2 | 2024-03-13 |
| nfg-analytics-lake | Cloud resources | Workload | Data Platform | medium | 4 | 2023-10-01 |
| sso.northfleet.io | Services | Identity | Identity | medium | 2 | 2021-07-14 |
| mail-relay-rot-03 | Endpoints | Gateway | Network Ops | medium | 3 | 2022-02-11 |
| nfg-prod-rds-freightCrown jewel | Cloud resources | Core | Freight Platform | medium | 2 | 2022-03-25 |
| a.rehman@northfleet.io | Identities | Identity | Security | low | 0 | 2021-03-02 |
| careers.northfleet.io | Domains & DNS | Edge | People Ops | low | 1 | 2024-09-12 |
| api.northfleet.io/v1/tracking | APIs | Gateway | Freight Platform | low | 1 | 2022-12-06 |
| nfg-backup-vault-euCrown jewel | Cloud resources | Core | Infrastructure | low | 0 | 2023-06-21 |
What it is not
Said plainly, because it shortens everyone’s week
- Not an EDR or an antivirusWe model exposure and paths. Endpoint detection stays with your endpoint vendor, and we ingest its signal.
- Not a penetration testReachability is computed from configuration, not proven by exploitation. Use both; they answer different questions.
- Not a compliance toolThe assurance pack supports an audit. It does not claim to make you compliant with anything.
- Not an agent-first platformAgents are optional. Most coverage comes from control planes and APIs you already run.
Next step
See your own surface the way an attacker reads it
A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout of what was found.
Book a walkthroughOpen the console demo
Illustrative product data. Nothing on this site performs a live scan.