A network engineer patching cables in a cramped closet with a laptop open — the physical end of the flow table.

CEDX Network · IT & Security

East-west traffic,
finally legible.

CEDX Network scores every lateral path, classifies every flow — allow, block, inspect — and shows the drift between the policy you wrote and the network you actually have.

32 paths in the demo show high drift: the effective route is not the intended one. The table says which, from what hop, to which target, and how stale the policy behind it is.

network.cedxsystems.com — live build
CEDX Network overview: devices online, blocked flows, high lateral risk, gateways healthy and DNS block rate.

Runs on demo data — Northline is the software's sample estate, not a customer.

21.6% of flows blocked82 of 380 in the sample window, rate on the card
57 high-risk lateral pathsof 110 scored — open east-west, named per row
15 of 48 gateways healthy31% — the edge estate says so itself

What it is

The network as a policy you can read.

110 lateral paths, scored and explained

The path risk queue lists device, hop and target with risk and drift: a personal phone reaching the ledger database through a remote jump at risk 95, drift 75 — top signal “open east-west path”, confidence and last seen attached.

  • Path heat map, policy drift and simulator as tabs
  • Drift ≥55 means effective differs from intended
  • 0 shadow paths, 54 stale — counted separately
network — screen-2
110 lateral paths, scored and explained

Flows with a policy name on each

The flow table shows source, destination, protocol, port, action and the policy that decided it — a blocked assistant-chat call cites AI governance; an inspected database connection cites Shadow OT route; bytes moved are on the row.

  • Allow 234 · block 82 · inspect 64 in the sample
  • AI class: assistant chat, model API, agent framework
  • 56 AI destinations, 14.7% of all flows
network — screen-4
Flows with a policy name on each

Devices with posture and behaviour

320 enrolled devices with site, segment, OS, posture and a UEBA behaviour score: 232 managed, 52 high risk, 67 with behaviour scores at 70 or above. The guest segment and the OT segment are columns, not surprises.

  • Segments: corp, prod, staging, remote, guest, OT, DMZ
  • 73% managed coverage — the gap is printed
  • Behaviour ≥70 isolates 67 devices
network — screen-3
Devices with posture and behaviour

Product tour

Four screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/network.

network.cedxsystems.com
CEDX Network Overview screen.CEDX Network Lateral & drift screen.CEDX Network Devices screen.CEDX Network Flows screen.

01 — Overview

The estate's traffic, judged

286 of 320 devices online, a 21.6% block rate, an 8.1% DNS block rate on malicious categories — and a network health ring at 56 that lists its own inputs: online devices, lateral paths, block rate, gateway health.

  • Allowed versus blocked flows, daily, with markers
  • Devices by segment: remote 102, OT 67, DMZ 38
  • Lowest-posture devices named, ava-phone-88 at 22

02 — Lateral & drift

Who can reach what they should not

The OT gateway reaching the deploy host through a jump box scores 95 with drift 91 — a path that was never supposed to exist, persisting because nothing removed it. 57 of the 110 scored paths are high risk right now.

  • Min-path chips: all, ≥40, ≥55, ≥70
  • Average path risk 60 across the board
  • Simulated high 57 · no levers, stated

03 — Devices

The enrolled estate, scored

Every device with owner, site, segment, posture and behaviour score — sortable, exportable, and honest about coverage: 89% online, 73% managed, and the 52 high-risk devices averaging posture 89.

  • 320 devices with owner on every row
  • Low, medium, high and behaviour ≥70 chips
  • Last seen to the day

04 — Flows

The policy, applied and visible

Read the sample like a ledger: a blocked call to an AI-apps workspace at 0 bytes under AI governance, an inspected connection to a flagged drop host under Shadow OT route, a 32.7 MB internal transfer allowed under CI-to-registry.

  • 380 flows in the sample window
  • Sensitive destinations: 167, 1,337 MB
  • Search source, destination or policy

Who runs it

Three roles keep the network honest.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

Network engineer

Owns the gateways, the segments and the physical end of the flow table — and the 33 edges that are not healthy.

gateways · 15/48 healthy

Policy author

Writes the rules the flow table cites — AI governance, posture floor, east-west blocks — and reads the drift report to see what the network actually does.

policy drift · 61

Device fleet owner

Keeps the enrolled estate managed and postured: the 73% coverage figure and the 52 high-risk devices are theirs to move.

high risk · 52

The shape of it

What the demo estate actually looks like.

Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.

380flows in the sample windowallow, block or inspect on each
110lateral paths scored57 high risk · 32 high drift
56AI destinations14.7% of flows, classified by policy
8.1%DNS block ratemalicious categories, trending on the card
Devices by segment320 enrolled, from the Overview
  • Remote — the perimeter that moved home102
  • OT — operational technology, least managed67
  • DMZ38
  • Corp LAN33
  • Staging VPC31
  • Guest30
  • Prod VPC19
Flow actions in the sample234 allowed of 380 sampled flows
  • Allow · 234
  • Block · 82 — 21.6% of the window
  • Inspect · 64
Network health56 on the Overview ring, inputs listed beside it
56
  • Score 56 · 286 online, block rate 21.6%
  • 57 high lateral paths · 15/48 healthy gateways — the drag on the score

How it runs

A flow's life, in the order it actually happens.

01

Enrol

Devices join the estate with owner, site and segment — 320 enrolled, each with a posture and a behaviour score from the first packet.

02

Classify

Every flow is typed and matched to policy: east-west, egress, AI destination, sensitive target — 56 AI-bound flows in the window alone.

03

Decide

Allow, block or inspect, with the deciding policy's name on the row — AI governance, posture floor, shadow-OT route.

04

Drift

The intended policy and the effective network are compared continuously; 32 high-drift paths are a work queue, not an audit finding.

One record

The flow knows the device,
the identity, the verdict.

A flow is not just two addresses — it is a device with a posture, a principal with grants, and a signal the SOC reads. Those records already exist.

All 132 applications

Limits

What Network does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Pilot

Your segments, your policies

  • Everything in Try
  • Flow-baseline assessment
  • Segmentation workshop
  • Estate map
Talk to sales

Estate

Network with the rest of it

  • Network with Endpoint, Access and SIEM
  • One identity, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot Network.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build and you can open the same build at /app/network. It runs on demo data — Northline is the sample estate.

What is path drift?

The difference between the policy you intended and the route traffic actually takes. 32 paths in the demo score drift ≥55 — like the OT gateway reaching the deploy host through a jump box. The drift tab lists them with the hop and the staleness of the policy behind each.

How is AI traffic handled?

AI destinations are classified — assistant chat, model API, agent framework — and governed by a named AI-governance policy: a blocked assistant-chat call cites that policy on the flow row, at 0 bytes, with the class attached.

What does the block rate mean?

In the sample window, 82 of 380 flows were blocked — 21.6% — and DNS blocks on malicious categories run at 8.1%. Both figures are the demo estate's own, printed on the cards.

Is Network audited or certified?

No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and inspection is written up on the security page.

The flows are classified. Go and look at them.

Live build, demo data, no card. Then ask which of your paths would show drift.