CEDX Network scores every lateral path, classifies every flow — allow, block, inspect — and shows the drift between the policy you wrote and the network you actually have.
32 paths in the demo show high drift: the effective route is not the intended one. The table says which, from what hop, to which target, and how stale the policy behind it is.
network.cedxsystems.com — live build
Runs on demo data — Northline is the software's sample estate, not a customer.
21.6% of flows blocked82 of 380 in the sample window, rate on the card
57 high-risk lateral pathsof 110 scored — open east-west, named per row
15 of 48 gateways healthy31% — the edge estate says so itself
What it is
The network as a policy you can read.
110 lateral paths, scored and explained
The path risk queue lists device, hop and target with risk and drift: a personal phone reaching the ledger database through a remote jump at risk 95, drift 75 — top signal “open east-west path”, confidence and last seen attached.
Path heat map, policy drift and simulator as tabs
Drift ≥55 means effective differs from intended
0 shadow paths, 54 stale — counted separately
network — screen-2
Flows with a policy name on each
The flow table shows source, destination, protocol, port, action and the policy that decided it — a blocked assistant-chat call cites AI governance; an inspected database connection cites Shadow OT route; bytes moved are on the row.
Allow 234 · block 82 · inspect 64 in the sample
AI class: assistant chat, model API, agent framework
56 AI destinations, 14.7% of all flows
network — screen-4
Devices with posture and behaviour
320 enrolled devices with site, segment, OS, posture and a UEBA behaviour score: 232 managed, 52 high risk, 67 with behaviour scores at 70 or above. The guest segment and the OT segment are columns, not surprises.
Not a mockup and not a concept deck. This is what opens at /app/network.
network.cedxsystems.com
01 — Overview
The estate's traffic, judged
286 of 320 devices online, a 21.6% block rate, an 8.1% DNS block rate on malicious categories — and a network health ring at 56 that lists its own inputs: online devices, lateral paths, block rate, gateway health.
Allowed versus blocked flows, daily, with markers
Devices by segment: remote 102, OT 67, DMZ 38
Lowest-posture devices named, ava-phone-88 at 22
02 — Lateral & drift
Who can reach what they should not
The OT gateway reaching the deploy host through a jump box scores 95 with drift 91 — a path that was never supposed to exist, persisting because nothing removed it. 57 of the 110 scored paths are high risk right now.
Min-path chips: all, ≥40, ≥55, ≥70
Average path risk 60 across the board
Simulated high 57 · no levers, stated
03 — Devices
The enrolled estate, scored
Every device with owner, site, segment, posture and behaviour score — sortable, exportable, and honest about coverage: 89% online, 73% managed, and the 52 high-risk devices averaging posture 89.
320 devices with owner on every row
Low, medium, high and behaviour ≥70 chips
Last seen to the day
04 — Flows
The policy, applied and visible
Read the sample like a ledger: a blocked call to an AI-apps workspace at 0 bytes under AI governance, an inspected connection to a flagged drop host under Shadow OT route, a 32.7 MB internal transfer allowed under CI-to-registry.
380 flows in the sample window
Sensitive destinations: 167, 1,337 MB
Search source, destination or policy
Who runs it
Three roles keep the network honest.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
Network engineer
Owns the gateways, the segments and the physical end of the flow table — and the 33 edges that are not healthy.
gateways · 15/48 healthy
Policy author
Writes the rules the flow table cites — AI governance, posture floor, east-west blocks — and reads the drift report to see what the network actually does.
policy drift · 61
Device fleet owner
Keeps the enrolled estate managed and postured: the 73% coverage figure and the 52 high-risk devices are theirs to move.
high risk · 52
The shape of it
What the demo estate actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
380flows in the sample windowallow, block or inspect on each
110lateral paths scored57 high risk · 32 high drift
56AI destinations14.7% of flows, classified by policy
8.1%DNS block ratemalicious categories, trending on the card
Devices by segment320 enrolled, from the Overview
Remote — the perimeter that moved home102
OT — operational technology, least managed67
DMZ38
Corp LAN33
Staging VPC31
Guest30
Prod VPC19
Flow actions in the sample234 allowed of 380 sampled flows
Allow · 234
Block · 82 — 21.6% of the window
Inspect · 64
Network health56 on the Overview ring, inputs listed beside it
56
Score 56 · 286 online, block rate 21.6%
57 high lateral paths · 15/48 healthy gateways — the drag on the score
How it runs
A flow's life, in the order it actually happens.
01
Enrol
Devices join the estate with owner, site and segment — 320 enrolled, each with a posture and a behaviour score from the first packet.
02
Classify
Every flow is typed and matched to policy: east-west, egress, AI destination, sensitive target — 56 AI-bound flows in the window alone.
03
Decide
Allow, block or inspect, with the deciding policy's name on the row — AI governance, posture floor, shadow-OT route.
04
Drift
The intended policy and the effective network are compared continuously; 32 high-drift paths are a work queue, not an audit finding.
One record
The flow knows the device, the identity, the verdict.
A flow is not just two addresses — it is a device with a posture, a principal with grants, and a signal the SOC reads. Those records already exist.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Network is not generally available. What opens today is the live build on demo data — Northline is the software's sample estate, not a customer.
We have no named customers to show you, so this page shows none. The devices and flows in the captures are the sample estate's.
The flow table is a sample window — 380 flows — and the cards say so. We are not claiming full-packet capture or unlimited retention in this build.
Gateway health in the demo is 15 of 48, and the product prints it on its own cards. Coverage of your edge estate depends on deployment, which this page does not claim.
No audit or compliance certification has been issued for Network. What we can evidence about hosting, encryption and inspection is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/network. It runs on demo data — Northline is the sample estate.
What is path drift?
The difference between the policy you intended and the route traffic actually takes. 32 paths in the demo score drift ≥55 — like the OT gateway reaching the deploy host through a jump box. The drift tab lists them with the hop and the staleness of the policy behind each.
How is AI traffic handled?
AI destinations are classified — assistant chat, model API, agent framework — and governed by a named AI-governance policy: a blocked assistant-chat call cites that policy on the flow row, at 0 bytes, with the class attached.
What does the block rate mean?
In the sample window, 82 of 380 flows were blocked — 21.6% — and DNS blocks on malicious categories run at 8.1%. Both figures are the demo estate's own, printed on the cards.
Is Network audited or certified?
No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and inspection is written up on the security page.
The flows are classified. Go and look at them.
Live build, demo data, no card. Then ask which of your paths would show drift.