Typhoon Fleet Start

Enterprise security principles, available to all.

A small crew of agents, each with one job, checking the things a good security team would check. Some are working today; the rest are still being built. Every report says what was checked, and what was not.

Starting takes about two minutes. You prove the domain is yours before anything is checked.

The security crew

Eight agents, one job each. Lit gear is a check that runs today. Locked gear is a check that is not built yet. The crew shown only as a light are not sailing yet.

runs today not built yet Small type under each name: the NIST CSF 2.0 function the agent serves.

The map

Illustrative sea map at night: open sea and fog at the top, three channels running down to a lit harbour, lighthouses along the channels, the crew at their posts. Illustrative

The harbour is what you protect. Attacks arrive from the open sea along three routes: email and accounts, sites and code, devices and the home network. Lighthouses are controls. Fog is what nobody has checked.

The threat is never drawn. It is a light in the fog.

The lighthouse states on this map are a story, not a reading of any estate. Hero and item status is real.

Lit, control standing
Dim, control weak
Fog, nobody has looked
Red light, a threat drifting in
Open the full map

The rest of the fleet

Security leads, but the same machine runs the other ships. Every one of them routes through LifeOS and writes to one log.

Bridge routing, decision log Security crew 8 Other ships 5 Slots open
The Red-Teamer from the earlier roster now sails as Squall, in the security crew above.

How it works

Three steps. What runs today is marked on each one.

1

Add what you own and prove it

Enter a domain at start.typhoonfleet.com and add one DNS record to show it is yours. For code, give read access to the repo. Nothing is checked until ownership is proved.

Live today: domain proof by DNS record. Code repository checks are not self-serve yet.
2

The crew checks it

Squall reads headers, TLS and email records on the domain, and runs secret, dependency and code checks on the repo. Glass watches the exploited lists. Open-source tools, read-only, and a person reviews what they find.

Live today: Squall and Glass. Identity, footprint, device and recovery checks are not built yet.
3

You get a one-page brief

Findings come ranked with their proof, and the brief says what was out of reach. Bridge sends each finding to the crew member who owns it and keeps the decision log.

Live today: findings with proof, routing, decision log. The monthly brief is not built yet.

Start with the domain you own.

Two minutes to prove it, one night for the first checks, and a report that says what it did not look at.