Detection & response
Exposure state feeds detection, so an alert on an asset that sits on a live path to regulated data is not treated like an alert on a static marketing page.
of pages in the demo tenant tied to a live path
What detection & response actually does
Path-weighted alerting
Alert priority inherits the asset's path position and destination value.
Case timeline
Detection, asset context, recent changes and related findings assembled in one place.
Response runbooks
Containment steps written against your own architecture, versioned alongside it.
SIEM handoff
Structured events to Splunk, Sentinel, Elastic or Chronicle with stable entity identifiers.
See it working on demo data
- Alert priority inherits the asset's path position and the value of what that path reaches.
- Case timelines assemble detection, asset context, recent changes and related findings in one place.
- Structured events stream to Splunk, Sentinel, Elastic or Chronicle with stable entity identifiers.
Exposure trend
Weekly score across the selected range. Lower is better.
Band: Moderate · method published in the assurance pack.
Coverage
What discovery can currently see.
- Cloud accounts connected4/4
- Domains under continuous discovery118/124
- Workloads with agent or API coverage4,512/4,870
- Identity providers federated3/3
Strata
Assets by depth, and how many are currently exposed.
- S1 Edge1,28437 exposed
- S2 Gateway31214 exposed
- S3 Workload4,87061 exposed
- S4 Identity9,61528 exposed
- S5 Core4866 exposed
Needs a decision today
4 critical findings and 4 live paths reaching Core.
- Unauthenticated file listing on the partner document exchangeFND-8841 · supplier-docs.northfleet.io · 7d oldin progress
- EDI gateway runs an end-of-life TLS stackFND-8836 · legacy-edi.northfleet.io · 19d oldopen
- Machine identity holds write access across three accountsFND-8829 · svc-datalake-ingest · 14d oldtriaged
- Invoice archive readable by the analytics lake roleFND-8824 · nfg-invoice-archive · 12d oldin progress
Activity
Discovery, intelligence and posture changes in one record.
northfleet-invoices[.]co resolved for the first time. Certificate transparency match on the supplier portal name.
supplier-docs.northfleet.io began answering on a second origin pool in eu-west-2.
Blast radius widened after the analytics role gained read on a fourth prefix.
Enforcement point deployed between the campus range and the depot gateway.
Deploy identity subject claim narrowed to 13 active repositories.
Three new hosts in 185.214.44.0/24 matched the remote-access scanning pattern.
Subsidiary account nfg-baltics-prod onboarded; 412 assets discovered in the first sweep.
No. It enriches it. Exposure context is streamed as structured events so your existing analytics rules can weigh it.
You do, against your own architecture, and they are versioned alongside it. We ship starting templates for the most common containment actions.
Only where you explicitly grant it, per action and per scope. Everything is off by default and every action is recorded.
Put detection & response against your own estate
A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout. Lodemark stays read-only throughout.
Illustrative product data. Nothing on this site performs a live scan.