Platform

Six modules, one model of your exposure

They share an inventory, a graph and an ownership record. That is why the findings stop contradicting each other, and why a path can be scored by where it ends rather than by how bad the CVE sounds.

Demo tenant at a glance
Assets
16,567
Exposure score
34
Live paths to Core
7
Median critical fix
4.2 days
The modules

Each one answers a different question about the same estate

The strata

Depth is the organising idea

Everything Lodemark discovers is placed on one of five strata. Findings inherit the depth of the asset they sit on, and paths are only interesting when they cross from shallow to deep.

  • 01DiscoverContinuous discovery across domains, cloud accounts, APIs, identities, endpoints and the SaaS holding your data. Ownership is inferred, then confirmed by a human.
  • 02UnderstandAssets are placed on five strata, from the internet edge down to regulated data. Relationships between them become traversable paths, not a wall of dots.
  • 03PrioritiseA finding matters when it sits on a path that terminates somewhere expensive. Everything else waits its turn, and we say so plainly.
  • 04ActChoke points collapse many findings into one fix. Each one becomes a ticket in the tracker the owning team already uses, with an SLA and a named human.
  • 05ProveExposure score, path count and remediation velocity over time, with the measurement method written out so nobody has to trust the number blindly.
  • S1EdgeAnything the public internet can reach without credentials.1,28437 exposed
  • S2GatewayIngress control: load balancers, WAF, VPN, API gateways.31214 exposed
  • S3WorkloadCompute, containers, functions and the services they run.4,87061 exposed
  • S4IdentityHuman accounts, machine identities, roles and entitlements.9,61528 exposed
  • S5CoreRegulated data stores, secrets and the systems of record.4866 exposed
The console

Nine working sections, one dataset

Sort the table, focus a node, advance a finding. Every control is live.

LodemarkDemo tenantNorthfleet Group · 4 cloud accounts · 11 regions · 3 subsidiariesHead of Security OperationsSigned in as Asha Rehman
Asset inventory24 of 24 shown · 16,567 in the full demo tenant
Discovered assets with exposure rating, owning team and open finding count. Select a row for detail.
StratumOwner
partners.northfleet.ioDomains & DNSEdgePlatform Webcritical42024-11-03
nfg-invoice-archiveCrown jewelCloud resourcesCoreFinance Systemscritical32023-02-19
svc-datalake-ingestIdentitiesIdentityData Platformcritical22023-08-27
legacy-edi.northfleet.ioServicesEdgeIntegrationcritical72021-11-19
api.northfleet.io/v2/consignmentsAPIsGatewayFreight Platformhigh62024-04-08
staging.tenders.northfleet.ioDomains & DNSEdgeCommercialhigh52025-06-14
nfg-prod-eks-freightCloud resourcesWorkloadFreight Platformhigh92023-01-11
vpn-ams-02.northfleet.ioEndpointsGatewayNetwork Opshigh32022-09-30
nfg-customer-pii-euCrown jewelCloud resourcesCoreData Platformhigh22022-05-16
ci-runner-fleet-07EndpointsWorkloadDeveloper Experiencehigh42024-07-05
depot-scada-rtd-12EndpointsWorkloadFacilitieshigh22022-08-08
supplier-docs.northfleet.ioDomains & DNSEdgeProcurementhigh42025-01-30
crew-scheduling.northfleet.ioServicesWorkloadPeople Opsmedium22024-01-22
nfg-secrets-prodCrown jewelCloud resourcesCorePlatform Securitymedium12023-04-04
api.northfleet.io/internal/pricingAPIsGatewayCommercialmedium32025-02-27
svc-github-deployIdentitiesIdentityDeveloper Experiencemedium22024-03-13
nfg-analytics-lakeCloud resourcesWorkloadData Platformmedium42023-10-01
sso.northfleet.ioServicesIdentityIdentitymedium22021-07-14
mail-relay-rot-03EndpointsGatewayNetwork Opsmedium32022-02-11
nfg-prod-rds-freightCrown jewelCloud resourcesCoreFreight Platformmedium22022-03-25
a.rehman@northfleet.ioIdentitiesIdentitySecuritylow02021-03-02
careers.northfleet.ioDomains & DNSEdgePeople Opslow12024-09-12
api.northfleet.io/v1/trackingAPIsGatewayFreight Platformlow12022-12-06
nfg-backup-vault-euCrown jewelCloud resourcesCoreInfrastructurelow02023-06-21
What it is not

Said plainly, because it shortens everyone’s week

  • Not an EDR or an antivirusWe model exposure and paths. Endpoint detection stays with your endpoint vendor, and we ingest its signal.
  • Not a penetration testReachability is computed from configuration, not proven by exploitation. Use both; they answer different questions.
  • Not a compliance toolThe assurance pack supports an audit. It does not claim to make you compliant with anything.
  • Not an agent-first platformAgents are optional. Most coverage comes from control planes and APIs you already run.
Next step

See your own surface the way an attacker reads it

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout of what was found.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.