Platform
Platform OverviewStart here — see how the hubs fit together.
Security Operations
Extended Detection and ResponseCorrelation engine, not just a log lake. Threat IntelligencePre-correlated to your environment. Not shelfware. Incident ResponseA structured six-phase workflow, not a chat thread.
Exposure Management
Attack Surface ManagementDiscovery plus correlation against your live stack.Asset & IdentityEvery endpoint and identity you run, tied to your threats. Vulnerability ManagementThreat-weighted prioritization. CVSS alone isn't enough.
Govern & Report
GRCContinuous evidence collection. No screenshot factory. Reporting & DashboardsLive dashboards and client-branded reports, on a schedule.
Connect
ArmorPoint AgentOne install for telemetry, inventory, and daily vulnerability reporting. IntegrationsPre-built connectors across the major security categories.
Inside the platform

Connected hubs, one operations plane

Five connected hubs. The capabilities on the left run inside them.

VisualizeSee your posture, not your tool sprawl.→OperationsFrom signal to incident to closed ticket.→GovernanceControls mapped to live evidence.→EnvironmentKnow what you have before you defend it.→Response CenterThe analyst's tools, one click away on any screen.→
Services
Compare ServicesFrom self-run to fully managed, plus advisory and onboarding.
Managed SOC
MXDROur SOC runs detection and response across your whole environment. MDRA managed SOC on your endpoints. Start here, grow into more.
Platform only
XDRThe full platform, run by your team.
Advisory layer
AdviseGet more from ArmorPoint, at the level you need.
Implementation
Guided ImplementationExpert-led, consultative onboarding to go-live.
Managed by ArmorPoint

A 24/7 SOC behind your stack

A U.S.-based SOC and the platform it runs on, watching, investigating, and responding to what matters. Security operations run for you, not handed to you.

ArmorPoint · SOC Console LIVE THREAT RADAR Signals / 24h 2,051 Analysts on shift 6 U.S. Coverage 24/7 always on
Solutions
Compare SolutionsFind your fit by industry or by the problem on your desk.
By industry
For MSPsRun a SOC across every client without standing one up for each. Federal & CMMCCMMC readiness on the same platform that runs your SOC.HealthcareProtect patient data without slowing patient care. See All Industries →Finance, Manufacturing, Utilities, Education, and more.
By need
Cyber Insurance ReadinessAnswer the renewal questionnaire with evidence, not guesses. Compliance CertificationGet certification-ready on the evidence you already produce. Post-IncidentA disciplined response when you have been breached.
Built for your mandate

What you actually answer for

Healthcare, finance, federal, MSPs — mapped to the obligations you're measured against.

What you answer for HIPAA Healthcare privacy and security MAPPED PCI-DSS Cardholder data protection MAPPED CMMC Federal contractor readiness MAPPED Cyber insurance Renewal evidence, on demand MAPPED
Resources
Resource LibraryField-tested writing, frameworks, and customer stories from the SOC.
Read
BlogPractical writing on operations, compliance, and incidents. Press ReleasesPartner announcements, awards, and milestones. ArmorPoint in the news.
Latest content

Field notes from the SOC

180+ posts. 40+ press releases. 40+ downloadable guides. Practitioner-grade writing on the work that actually matters.

BLOG · 6 MIN READ STRATEGY · MAY 2026 PRESS RELEASE ANNOUNCEMENT · MAY 2026 LIBRARY · REPORT DOWNLOAD · 24 PAGES
Partners
Partner Program OverviewFind the track that fits how you sell and deliver.
Program tracks
Service ProviderDeliver managed security with your brand on every report and your team on the relationship. ResellerAdd cybersecurity to your portfolio. Skip the operational lift.
Distribution
TD SYNNEXSell or buy ArmorPoint through TD SYNNEX distribution.
Tech alliances
Tech AlliancesEDR partners that run inside ArmorPoint: CrowdStrike, SentinelOne, Cybereason.
Get started
Become a PartnerTell us about your practice and we'll route the right program.
Partner ecosystem

We sell with you, never around you

Sold and delivered through partners who own the customer relationship. Multiple tracks, one platform.

Partner YOU Your customer THE RELATIONSHIP ArmorPoint THE PLATFORM NEVER AROUND YOU
ArmorPoint Platform Partner Portal
Request a demo
↑↓ navigate · Enter all results
Platform Overview
Security Operations
Extended Detection and ResponseThreat IntelligenceIncident Response
Exposure Management
Attack Surface ManagementAsset & IdentityVulnerability Management
Govern & Report
GRCReporting & Dashboards
Connect
ArmorPoint AgentIntegrations
Compare Services
Managed SOC
MXDRMDR
Platform only
XDR
Advisory layer
Advise
Implementation
Guided Implementation
Compare Solutions
By industry
For MSPsFederal & CMMCHealthcareSee All Industries →
By need
Cyber Insurance ReadinessCompliance CertificationPost-Incident
Resource Library
Read
BlogPress Releases
Partner Program Overview
Program tracks
Service ProviderReseller
Distribution
TD SYNNEX
Tech alliances
Tech Alliances
Get started
Become a Partner
ArmorPoint Platform Partner Portal Request a demo
Home/Legal/ArmorPoint Advise Service Agreement

Legal

ArmorPoint Advise Service Agreement

Last Updated: 09/08/2026

This Agreement defines the scope of Services. Fees, quantities, term, and any Customer-specific commercial terms are set out in an accompanying Order Form, which is incorporated into and governed by this Agreement and the ArmorPoint Terms of Service. ArmorPoint’s liability remains subject to the limitation of liability in the ArmorPoint Terms of Service.

Description of Services

ArmorPoint Advise is a tiered advisory service that helps Customer optimize its ArmorPoint investment, improve overall security posture, and achieve proactive threat identification through platform tooling and, at higher tiers, dedicated technical advisory resources. The service is offered in three cumulative tiers — Tier 1 (Enhanced Platform Access), Tier 2 (Dedicated Technical Resource), and Tier 3 (Strategic Security Partner). Each tier includes all capabilities of the tier(s) below it. The tier purchased by Customer is identified on the applicable Order Form.

ArmorPoint Advise presupposes an active ArmorPoint platform subscription and/or managed service. Tier capabilities operate on, and report against, Customer’s existing ArmorPoint deployment; this Agreement does not by itself provision the underlying platform or managed service. Tier capabilities that reference ArmorPoint’s SOC, managed detection, incident handling, or response apply only where the Customer’s underlying ArmorPoint service includes the referenced capability.

Where a tier includes a dedicated resource, that resource serves as a qualified strategic advisor and operational extension of Customer’s team. ArmorPoint will assign a primary Technical Resource and will use reasonable effort to maintain continuity. ArmorPoint may substitute or supplement the assigned resource with comparably qualified personnel as needed, including for availability, expertise, or personnel changes. The service includes an initial discovery session to understand Customer’s business needs and security objectives. All services are delivered remotely via secure virtual meetings and collaboration tools unless otherwise agreed in writing.

Service Tiers

The following describes the scope of each tier. Tiers are cumulative: Tier 2 includes Tier 1, and Tier 3 includes Tiers 1 and 2. Service cadence and hour allocations for the purchased tier are set on the Order Form.

Tier 1 — Enhanced Platform Access

Best aligned to customers seeking self-service uplift. No dedicated technical resource is provided at this tier. Tier 1 is delivered entirely through the ArmorPoint platform.

Tier 1 carries no advisory hours and includes no dedicated, named, or shared technical resource. All Tier 1 value is delivered through the ArmorPoint platform; advisory hours and a dedicated resource are available only at Tier 2 and Tier 3.

Operational Reporting Visuals and Content

Branded, dynamic operational dashboard views for risk-posture reporting, compliance scorecards, and detection-coverage heatmaps, beyond the standard Platform Dashboard views.

MITRE ATT&CK Coverage Map

A dynamic visual showing which MITRE ATT&CK techniques are covered by current detection rules versus where gaps exist, updated automatically as detection rules evolve.

Vulnerability Trend Analytics

Historical risk-reduction visualizations with remediation-velocity tracking, enabling Customer to demonstrate measurable security improvement over time rather than relying on point-in-time scan results.

Threat Intelligence Feed Dashboard

A visual feed of enriched indicators of compromise (IPs, hashes, domains) with relevance scoring tied to Customer’s environment, providing actionable context rather than raw data.

Environmental Health Scorecard

A consolidated view of agent-deployment coverage, log-source health, data-ingest trends, and configuration-drift indicators.

Security Reputation

Domain evaluation and overall scoring with supporting evidence identifying areas for improvement. Security Reputation domain evaluation is limited to a maximum of 300 domains.

Monthly Security Posture Summary (Automated)

An auto-generated monthly digest of key metrics including incidents handled, mean time to respond, alert-volume trends, and vulnerability counts delivered as a PDF.

Tier 1 Deliverables: Dashboard access, automated monthly posture reports, custom report builder, MITRE coverage map, vulnerability trend analytics, threat intelligence feed, and environment health scorecard.

Tier 2 — Dedicated Technical Resource

Best aligned to mid-market customers with moderate complexity. Includes everything in Tier 1, plus a named resource serving as a technical advisor and operational extension of Customer’s team. Available monthly or quarterly.

Named Technical Resource

A single dedicated point of contact for operational questions, tuning requests, and strategic guidance. The technical resource develops familiarity with Customer’s environment and serves as Customer’s advocate within ArmorPoint.

Monthly Security Operations Review

A structured review covering incident trends, detection efficacy, coverage gaps, and forward-looking recommendations, delivered as a presentation with an executive summary.

Detection Rule Tuning

Review of alert noise and false-positive rates, and refinement of detection logic specific to Customer’s environment and threat profile. ArmorPoint performs rule modifications within the ArmorPoint platform with Customer’s written authorization.

Incident Response (IR) Runbook Development / Review

Assistance building and periodically reviewing Customer’s incident-response playbook to keep it current and aligned with Customer’s Business Continuity Plan.

Onboarding & Integration Acceleration

Guided onboarding for new log sources, third-party integrations, or environment changes against a defined runbook, reducing time-to-value for new telemetry sources.

ArmorPoint or EDR Orientation

Facilitated orientation on the ArmorPoint Security Operations platform or the selected EDR console, covering navigation, management, and best practices, including support for personnel changes.

Incident Post-Mortem Report Review

Written review reports for Critical- or High-severity incidents, including timeline, advisory-level root-cause review, MITRE ATT&CK mapping, containment steps taken, and prevention recommendations.

Remediation Prioritization Guidance

Resource-led review of vulnerability findings with risk-ranked remediation recommendations based on exploitability, business context, and threat intelligence.

Annual Tabletop Exercise (Add-On)

A guided incident-response tabletop exercise testing Customer’s IR plan and coordination with ArmorPoint’s SOC, with a findings report and improvement recommendations. Available as a priced add-on; facilitated virtually.

Tier 2 Deliverables: Monthly or Quarterly Security Operations Review deck, incident post-mortem reports, detection-tuning summaries, tabletop exercise report (if purchased), and remediation priority matrix.

Tier 3 — Strategic Security Partner

Best aligned to larger or more complex environments where ArmorPoint functions as a virtual extension of Customer’s security program. Includes everything in Tiers 1 and 2, plus the following.

Dedicated Security Engineer

A named engineer assigned to Customer’s account, available for hands-on work within the ArmorPoint platform: platform configuration, detection rule creation and modification, integration and telemetry troubleshooting, and detection coverage tuning. Rule and configuration changes are made only with Customer’s written authorization. Work on Customer-owned systems and equipment is outside scope; see Exclusions.

Monthly Security Operations Reviews

Monthly reviews with deeper operational metrics, forward-looking threat briefings, and actionable recommendations tied to Customer’s evolving risk landscape.

Custom Detection Engineering

Bespoke detection rules and correlation searches built specifically for Customer’s environment, applications, and threat profile, beyond the managed detection library.

Threat Hunting Engagements

Proactive, scheduled threat hunts (monthly or quarterly) with written findings reports. These are hypothesis-driven investigations, not reactive alerting.

Architecture Review & Telemetry Gap Analysis

An annual or semi-annual deep dive into Customer’s security architecture, identifying coverage blind spots and recommending telemetry improvements to strengthen detection.

Executive Threat Briefings

Quarterly or monthly briefings tailored to Customer’s industry vertical, covering relevant threat-actor activity, campaign trends, and actionable defensive recommendations.

Expanded Post-Eradication Hours

This entitlement applies only where the Customer has an active ArmorPoint MDR or MXDR managed service subscription. It provides an increased monthly allocation of post-eradication hours above the post-eradication baseline included in that underlying managed service. The additional hours are an entitlement included with Tier 3; the post-eradication work itself is performed under, and governed by, the incident-response scope and authorizations of Customer’s underlying ArmorPoint managed service, not under this advisory Agreement. Where the Customer has no qualifying MXDR or MDR subscription, this entitlement does not apply.

Annual Tabletop Exercise (Add-On)

A guided incident-response tabletop exercise testing Customer’s IR plan and coordination with ArmorPoint’s SOC, with a findings report and improvement recommendations. Available as a priced add-on; facilitated virtually.

Tier 3 Deliverables: Monthly operations review decks, threat-hunt reports, custom detection documentation, and executive threat briefings.

Tier Comparison Summary

The following table provides a consolidated view of capabilities across all three ArmorPoint Advise tiers.

Capability Tier 1 Tier 2 Tier 3
Enhanced dashboards & metrics ✓ ✓ ✓
Automated posture reports ✓ ✓ ✓
Custom report builder ✓ ✓ ✓
Named Technical Resource — ✓ ✓
Security operations reviews — Monthly / Quarterly Monthly
Detection tuning sessions — ✓ ✓ + Custom
Incident post-mortem reports — ✓ ✓
Architecture review — — ✓
Executive threat briefings — — ✓
Expanded post-eradication hours — — ✓
Threat hunting engagements — — ✓
Tabletop exercise (add-on) — Annual (add-on) Annual (add-on)

Service Options

Service Cadence: Tier 1 is delivered through continuous platform access. Tier 2 is available monthly or quarterly. Tier 3 is delivered monthly. The purchased cadence is set on the Order Form.

Monthly Hour Allocation: Tier 1: none — no advisory hours (platform access only). Tier 2 includes a monthly or quarterly advisory hour allocation; Tier 3 includes a monthly advisory hour allocation. The allocation for the purchased tier is set out on the Order Form.

Hour Usage: For tiers with a dedicated resource, all service activities — meetings, report preparation, training sessions, and follow-up communications and action items — are included within the monthly hour allocation. Sessions are subject to availability within the allocated hours and must be scheduled in advance. Unused hours do not roll over to the following month.

Additional Hours: ArmorPoint has no obligation to perform services beyond the monthly hour allocation. Additional hours may be requested by the Customer and are provided at ArmorPoint’s discretion subject to resource availability, billed at the then-current standard hourly rate set on the Order Form. Unused allocated hours do not roll over.

Contractual Changes

This Agreement may be amended only by the mutual written agreement of the Parties through the Contract Change Process described below; ArmorPoint will not unilaterally modify the terms of this Agreement. This Agreement is incorporated into and governed by the ArmorPoint Terms of Service. The limitation of liability, exclusion of consequential and indirect damages, disclaimer of warranties, indemnification, and insurance provisions of the ArmorPoint Terms of Service apply to this Agreement in full, and nothing in this Agreement expands ArmorPoint’s liability beyond the cap stated in the Terms of Service. In the event of a conflict among the documents that comprise the agreement between the Parties, the order of precedence is: (1) the ArmorPoint Terms of Service; (2) this Service Agreement; and (3) the applicable Order Form, provided that the fees, quantities, and term set out in the Order Form control over any conflicting commercial terms.

The following Governance structure defines the Contract Change Process:

Change To Process / Justification Vehicle
Service Scope Change of scope presented with justification and supporting data. Changes that cause a change to the monthly cost to Customer of more than $1,000 will require further Executive Approval through a Contract Change Process. Order Form
New project or effort Each proposed effort or initiative is presented to executive leadership with a supporting charter, solution outline, and estimates. Order Form
Service requirements & performance Each change is presented to the Executive and processed with further Executive Approval. CCR or Addendum
Scope, terms & conditions Each change is presented to the Executive and processed with further Executive Approval. Contract Addendum

Exclusions

The following are outside the scope of ArmorPoint Advise unless expressly added on the Order Form, and are incorporated as assumptions into the pricing on the Order Form:

  • Incident root-cause analysis (beyond advisory post-mortem review) and digital forensics.
  • Access to, configuration of, or modification of Customer-owned systems, endpoints, servers, network equipment, appliances, or other Customer assets. ArmorPoint Advise is delivered within the ArmorPoint platform.
  • Unsupported integration review or completion.
  • Customer migrations.
  • Feature-request development.
  • Incident Response Activities, other than the additional post-eradication hours included at Tier 3, which are delivered under Customer’s underlying ArmorPoint managed service and governed by that agreement’s incident-response scope and authorizations.
  • Patch-management consulting.
  • Technical onboarding support or implementation services not expressly provided herein.
  • Any application development or integration effort not expressly provided herein.
  • Actual implementation of recommendations made by ArmorPoint, unless specified in this document.
  • Use of advisory hours as a general-purpose retainer, or for professional-services work outside the deliverables defined in this Agreement.
  • Any software license or physical hardware expense.
  • Any work or services not expressly provided for herein.
  • Any hardware purchase for on-premise needs.
  • Any migration or upgrade of infrastructure (servers, network, and the like).
  • Any effort tied to re-installing an operating system due to virus or malware, or any system instability following virus removal.
  • Any work related to a crypto-lock event. Containment of such events is not within ArmorPoint Advise and, where applicable, is performed under the Customer’s underlying ArmorPoint managed service agreement.
  • Any data-recovery or forensics work arising from purposeful or malicious Customer or application errors.
  • Any additional work requested beyond the scope of this Agreement, which will be set forth by subsequent agreement, including a Contract Change Request (“CCR”).

Disclaimers

This Agreement, together with all corresponding schedules, quotes, exhibits, Order Forms, the ArmorPoint Terms of Service, and any Change Orders, comprises the entire agreement between the parties and replaces any prior oral or written agreements between ArmorPoint and Customer. Limitation of liability, consequential-damages waiver, warranty disclaimer, indemnification, and insurance terms are governed by the ArmorPoint Terms of Service and are not restated in this scope document.

  • ArmorPoint Advise is an advisory service delivered within the ArmorPoint platform. Recommendations, assessments, reviews, roadmaps, prioritizations, and reports are informational deliverables and are not warranties or guarantees of any security, detection, prevention, compliance, or business outcome. The Customer retains sole responsibility for evaluating, accepting, and implementing any recommendation and for all resulting decisions.
  • When Customer authorizes ArmorPoint in writing to create or modify a detection rule or platform configuration, ArmorPoint performs that change within the ArmorPoint platform. No such change is a warranty or guarantee of any detection, prevention, or security outcome, and Customer remains responsible for the configuration and security of its own environment.
  • ArmorPoint does not guarantee compliance outcomes and does not assume legal liability for the Customer’s compliance.
  • Threat hunts, custom detection rules, and detection tuning are performed on a best-effort basis using available telemetry; no detection, prevention, or breach-prevention result is guaranteed.
  • ArmorPoint is not a guarantor of the Customer’s security and is not liable for a security breach except to the extent expressly provided in the ArmorPoint Terms of Service.
  • ArmorPoint Advise does not include a managed Security Operations Center, monitoring, or incident response; those services, where purchased, are provided under the Customer’s underlying managed service agreement and governed by it.

Document history

ArmorPoint is the security outcome layer for midsize enterprises and their partners, connecting detection, response, exposure, and compliance in one cloud-delivered platform with a 24/7 U.S.-based SOC. AI accelerates triage; human analysts stay in the loop.

Detection · Response · Compliance

Platform

  • Overview
  • GRC
  • Attack Surface Mgmt
  • Extended Detection and Response
  • Vulnerability Mgmt
  • Threat Intelligence
  • Integrations

Services

  • Compare all
  • MXDR
  • MDR
  • XDR
  • Advise
  • Guided Implementation

Solutions

  • Compare all
  • For MSPs
  • Federal & CMMC
  • Healthcare
  • Financial Services
  • Cyber Insurance
  • Compliance Cert.

Resources

  • Resource library
  • Blog
  • Press Releases

Company

  • About
  • Partners
  • Find a partner
  • Become a partner
  • Request a demo
  • Platform login

Legal

  • Trust Center
  • Privacy notice
  • Terms of service
  • Status page
SC Awards 2026 Excellence Award Winner MSSP Alert Top 250 MSSP 2024 Honoree CRN 5-Star Partner Program Guide Winner 2025 CRN 5-Star Partner Program Guide Winner 2024
© 2026 ArmorPoint, LLC. All rights reserved.
Privacy Terms Trust