Security
Exposure from inventory. Policy on the box.
LodeStar does not invent a scanner brand. CVE and KEV land on what the agent already knows is installed. Policy is how you change the machine.
- Inventory
- The device agent reports what is on the host. That list is the source of truth for packages and apps, including snaps installed from Canonical.
- CVE / KEV
- Known vulnerabilities, including CISA Known Exploited Vulnerabilities, are mapped from that inventory. If it is not installed, it is not an exposure on that device.
- Policy
- Close the gap on the host. Policy is for operators, not a PDF of intentions.
- Live query
- When inventory is stale in your head, ask the fleet. Do not wait for a nightly export you already distrust.
This page does not claim SOC 2, FedRAMP, or a magic risk score. If you need a security review, request access and we will talk like adults.
Request access.
Security questionnaires belong in a conversation, not a marketing footer.