Security

Exposure from inventory. Policy on the box.

LodeStar does not invent a scanner brand. CVE and KEV land on what the agent already knows is installed. Policy is how you change the machine.

Inventory
The device agent reports what is on the host. That list is the source of truth for packages and apps, including snaps installed from Canonical.
CVE / KEV
Known vulnerabilities, including CISA Known Exploited Vulnerabilities, are mapped from that inventory. If it is not installed, it is not an exposure on that device.
Policy
Close the gap on the host. Policy is for operators, not a PDF of intentions.
Live query
When inventory is stale in your head, ask the fleet. Do not wait for a nightly export you already distrust.
This page does not claim SOC 2, FedRAMP, or a magic risk score. If you need a security review, request access and we will talk like adults.

Request access.

Security questionnaires belong in a conversation, not a marketing footer.

Request access