This Agreement defines the scope of Services. Fees, quantities, term, and any Customer-specific commercial terms are set out in an accompanying Order Form, which is incorporated into and governed by this Agreement and the ArmorPoint Terms of Service. ArmorPoint’s liability remains subject to the limitation of liability in the ArmorPoint Terms of Service.
Description of Services
ArmorPoint Advise is a tiered advisory service that helps Customer optimize its ArmorPoint investment, improve overall security posture, and achieve proactive threat identification through platform tooling and, at higher tiers, dedicated technical advisory resources. The service is offered in three cumulative tiers — Tier 1 (Enhanced Platform Access), Tier 2 (Dedicated Technical Resource), and Tier 3 (Strategic Security Partner). Each tier includes all capabilities of the tier(s) below it. The tier purchased by Customer is identified on the applicable Order Form.
ArmorPoint Advise presupposes an active ArmorPoint platform subscription and/or managed service. Tier capabilities operate on, and report against, Customer’s existing ArmorPoint deployment; this Agreement does not by itself provision the underlying platform or managed service. Tier capabilities that reference ArmorPoint’s SOC, managed detection, incident handling, or response apply only where the Customer’s underlying ArmorPoint service includes the referenced capability.
Where a tier includes a dedicated resource, that resource serves as a qualified strategic advisor and operational extension of Customer’s team. ArmorPoint will assign a primary Technical Resource and will use reasonable effort to maintain continuity. ArmorPoint may substitute or supplement the assigned resource with comparably qualified personnel as needed, including for availability, expertise, or personnel changes. The service includes an initial discovery session to understand Customer’s business needs and security objectives. All services are delivered remotely via secure virtual meetings and collaboration tools unless otherwise agreed in writing.
Service Tiers
The following describes the scope of each tier. Tiers are cumulative: Tier 2 includes Tier 1, and Tier 3 includes Tiers 1 and 2. Service cadence and hour allocations for the purchased tier are set on the Order Form.
Tier 1 — Enhanced Platform Access
Best aligned to customers seeking self-service uplift. No dedicated technical resource is provided at this tier. Tier 1 is delivered entirely through the ArmorPoint platform.
Tier 1 carries no advisory hours and includes no dedicated, named, or shared technical resource. All Tier 1 value is delivered through the ArmorPoint platform; advisory hours and a dedicated resource are available only at Tier 2 and Tier 3.
Operational Reporting Visuals and Content
Branded, dynamic operational dashboard views for risk-posture reporting, compliance scorecards, and detection-coverage heatmaps, beyond the standard Platform Dashboard views.
MITRE ATT&CK Coverage Map
A dynamic visual showing which MITRE ATT&CK techniques are covered by current detection rules versus where gaps exist, updated automatically as detection rules evolve.
Vulnerability Trend Analytics
Historical risk-reduction visualizations with remediation-velocity tracking, enabling Customer to demonstrate measurable security improvement over time rather than relying on point-in-time scan results.
Threat Intelligence Feed Dashboard
A visual feed of enriched indicators of compromise (IPs, hashes, domains) with relevance scoring tied to Customer’s environment, providing actionable context rather than raw data.
Environmental Health Scorecard
A consolidated view of agent-deployment coverage, log-source health, data-ingest trends, and configuration-drift indicators.
Security Reputation
Domain evaluation and overall scoring with supporting evidence identifying areas for improvement. Security Reputation domain evaluation is limited to a maximum of 300 domains.
Monthly Security Posture Summary (Automated)
An auto-generated monthly digest of key metrics including incidents handled, mean time to respond, alert-volume trends, and vulnerability counts delivered as a PDF.
Tier 1 Deliverables: Dashboard access, automated monthly posture reports, custom report builder, MITRE coverage map, vulnerability trend analytics, threat intelligence feed, and environment health scorecard.
Tier 2 — Dedicated Technical Resource
Best aligned to mid-market customers with moderate complexity. Includes everything in Tier 1, plus a named resource serving as a technical advisor and operational extension of Customer’s team. Available monthly or quarterly.
Named Technical Resource
A single dedicated point of contact for operational questions, tuning requests, and strategic guidance. The technical resource develops familiarity with Customer’s environment and serves as Customer’s advocate within ArmorPoint.
Monthly Security Operations Review
A structured review covering incident trends, detection efficacy, coverage gaps, and forward-looking recommendations, delivered as a presentation with an executive summary.
Detection Rule Tuning
Review of alert noise and false-positive rates, and refinement of detection logic specific to Customer’s environment and threat profile. ArmorPoint performs rule modifications within the ArmorPoint platform with Customer’s written authorization.
Incident Response (IR) Runbook Development / Review
Assistance building and periodically reviewing Customer’s incident-response playbook to keep it current and aligned with Customer’s Business Continuity Plan.
Onboarding & Integration Acceleration
Guided onboarding for new log sources, third-party integrations, or environment changes against a defined runbook, reducing time-to-value for new telemetry sources.
ArmorPoint or EDR Orientation
Facilitated orientation on the ArmorPoint Security Operations platform or the selected EDR console, covering navigation, management, and best practices, including support for personnel changes.
Incident Post-Mortem Report Review
Written review reports for Critical- or High-severity incidents, including timeline, advisory-level root-cause review, MITRE ATT&CK mapping, containment steps taken, and prevention recommendations.
Remediation Prioritization Guidance
Resource-led review of vulnerability findings with risk-ranked remediation recommendations based on exploitability, business context, and threat intelligence.
Annual Tabletop Exercise (Add-On)
A guided incident-response tabletop exercise testing Customer’s IR plan and coordination with ArmorPoint’s SOC, with a findings report and improvement recommendations. Available as a priced add-on; facilitated virtually.
Tier 2 Deliverables: Monthly or Quarterly Security Operations Review deck, incident post-mortem reports, detection-tuning summaries, tabletop exercise report (if purchased), and remediation priority matrix.
Tier 3 — Strategic Security Partner
Best aligned to larger or more complex environments where ArmorPoint functions as a virtual extension of Customer’s security program. Includes everything in Tiers 1 and 2, plus the following.
Dedicated Security Engineer
A named engineer assigned to Customer’s account, available for hands-on work within the ArmorPoint platform: platform configuration, detection rule creation and modification, integration and telemetry troubleshooting, and detection coverage tuning. Rule and configuration changes are made only with Customer’s written authorization. Work on Customer-owned systems and equipment is outside scope; see Exclusions.
Monthly Security Operations Reviews
Monthly reviews with deeper operational metrics, forward-looking threat briefings, and actionable recommendations tied to Customer’s evolving risk landscape.
Custom Detection Engineering
Bespoke detection rules and correlation searches built specifically for Customer’s environment, applications, and threat profile, beyond the managed detection library.
Threat Hunting Engagements
Proactive, scheduled threat hunts (monthly or quarterly) with written findings reports. These are hypothesis-driven investigations, not reactive alerting.
Architecture Review & Telemetry Gap Analysis
An annual or semi-annual deep dive into Customer’s security architecture, identifying coverage blind spots and recommending telemetry improvements to strengthen detection.
Executive Threat Briefings
Quarterly or monthly briefings tailored to Customer’s industry vertical, covering relevant threat-actor activity, campaign trends, and actionable defensive recommendations.
Expanded Post-Eradication Hours
This entitlement applies only where the Customer has an active ArmorPoint MDR or MXDR managed service subscription. It provides an increased monthly allocation of post-eradication hours above the post-eradication baseline included in that underlying managed service. The additional hours are an entitlement included with Tier 3; the post-eradication work itself is performed under, and governed by, the incident-response scope and authorizations of Customer’s underlying ArmorPoint managed service, not under this advisory Agreement. Where the Customer has no qualifying MXDR or MDR subscription, this entitlement does not apply.
Annual Tabletop Exercise (Add-On)
A guided incident-response tabletop exercise testing Customer’s IR plan and coordination with ArmorPoint’s SOC, with a findings report and improvement recommendations. Available as a priced add-on; facilitated virtually.
Tier 3 Deliverables: Monthly operations review decks, threat-hunt reports, custom detection documentation, and executive threat briefings.
Tier Comparison Summary
The following table provides a consolidated view of capabilities across all three ArmorPoint Advise tiers.
| Capability | Tier 1 | Tier 2 | Tier 3 |
|---|---|---|---|
| Enhanced dashboards & metrics | ✓ | ✓ | ✓ |
| Automated posture reports | ✓ | ✓ | ✓ |
| Custom report builder | ✓ | ✓ | ✓ |
| Named Technical Resource | — | ✓ | ✓ |
| Security operations reviews | — | Monthly / Quarterly | Monthly |
| Detection tuning sessions | — | ✓ | ✓ + Custom |
| Incident post-mortem reports | — | ✓ | ✓ |
| Architecture review | — | — | ✓ |
| Executive threat briefings | — | — | ✓ |
| Expanded post-eradication hours | — | — | ✓ |
| Threat hunting engagements | — | — | ✓ |
| Tabletop exercise (add-on) | — | Annual (add-on) | Annual (add-on) |
Service Options
Service Cadence: Tier 1 is delivered through continuous platform access. Tier 2 is available monthly or quarterly. Tier 3 is delivered monthly. The purchased cadence is set on the Order Form.
Monthly Hour Allocation: Tier 1: none — no advisory hours (platform access only). Tier 2 includes a monthly or quarterly advisory hour allocation; Tier 3 includes a monthly advisory hour allocation. The allocation for the purchased tier is set out on the Order Form.
Hour Usage: For tiers with a dedicated resource, all service activities — meetings, report preparation, training sessions, and follow-up communications and action items — are included within the monthly hour allocation. Sessions are subject to availability within the allocated hours and must be scheduled in advance. Unused hours do not roll over to the following month.
Additional Hours: ArmorPoint has no obligation to perform services beyond the monthly hour allocation. Additional hours may be requested by the Customer and are provided at ArmorPoint’s discretion subject to resource availability, billed at the then-current standard hourly rate set on the Order Form. Unused allocated hours do not roll over.
Contractual Changes
This Agreement may be amended only by the mutual written agreement of the Parties through the Contract Change Process described below; ArmorPoint will not unilaterally modify the terms of this Agreement. This Agreement is incorporated into and governed by the ArmorPoint Terms of Service. The limitation of liability, exclusion of consequential and indirect damages, disclaimer of warranties, indemnification, and insurance provisions of the ArmorPoint Terms of Service apply to this Agreement in full, and nothing in this Agreement expands ArmorPoint’s liability beyond the cap stated in the Terms of Service. In the event of a conflict among the documents that comprise the agreement between the Parties, the order of precedence is: (1) the ArmorPoint Terms of Service; (2) this Service Agreement; and (3) the applicable Order Form, provided that the fees, quantities, and term set out in the Order Form control over any conflicting commercial terms.
The following Governance structure defines the Contract Change Process:
| Change To | Process / Justification | Vehicle |
|---|---|---|
| Service Scope | Change of scope presented with justification and supporting data. Changes that cause a change to the monthly cost to Customer of more than $1,000 will require further Executive Approval through a Contract Change Process. | Order Form |
| New project or effort | Each proposed effort or initiative is presented to executive leadership with a supporting charter, solution outline, and estimates. | Order Form |
| Service requirements & performance | Each change is presented to the Executive and processed with further Executive Approval. | CCR or Addendum |
| Scope, terms & conditions | Each change is presented to the Executive and processed with further Executive Approval. | Contract Addendum |
Exclusions
The following are outside the scope of ArmorPoint Advise unless expressly added on the Order Form, and are incorporated as assumptions into the pricing on the Order Form:
- Incident root-cause analysis (beyond advisory post-mortem review) and digital forensics.
- Access to, configuration of, or modification of Customer-owned systems, endpoints, servers, network equipment, appliances, or other Customer assets. ArmorPoint Advise is delivered within the ArmorPoint platform.
- Unsupported integration review or completion.
- Customer migrations.
- Feature-request development.
- Incident Response Activities, other than the additional post-eradication hours included at Tier 3, which are delivered under Customer’s underlying ArmorPoint managed service and governed by that agreement’s incident-response scope and authorizations.
- Patch-management consulting.
- Technical onboarding support or implementation services not expressly provided herein.
- Any application development or integration effort not expressly provided herein.
- Actual implementation of recommendations made by ArmorPoint, unless specified in this document.
- Use of advisory hours as a general-purpose retainer, or for professional-services work outside the deliverables defined in this Agreement.
- Any software license or physical hardware expense.
- Any work or services not expressly provided for herein.
- Any hardware purchase for on-premise needs.
- Any migration or upgrade of infrastructure (servers, network, and the like).
- Any effort tied to re-installing an operating system due to virus or malware, or any system instability following virus removal.
- Any work related to a crypto-lock event. Containment of such events is not within ArmorPoint Advise and, where applicable, is performed under the Customer’s underlying ArmorPoint managed service agreement.
- Any data-recovery or forensics work arising from purposeful or malicious Customer or application errors.
- Any additional work requested beyond the scope of this Agreement, which will be set forth by subsequent agreement, including a Contract Change Request (“CCR”).
Disclaimers
This Agreement, together with all corresponding schedules, quotes, exhibits, Order Forms, the ArmorPoint Terms of Service, and any Change Orders, comprises the entire agreement between the parties and replaces any prior oral or written agreements between ArmorPoint and Customer. Limitation of liability, consequential-damages waiver, warranty disclaimer, indemnification, and insurance terms are governed by the ArmorPoint Terms of Service and are not restated in this scope document.
- ArmorPoint Advise is an advisory service delivered within the ArmorPoint platform. Recommendations, assessments, reviews, roadmaps, prioritizations, and reports are informational deliverables and are not warranties or guarantees of any security, detection, prevention, compliance, or business outcome. The Customer retains sole responsibility for evaluating, accepting, and implementing any recommendation and for all resulting decisions.
- When Customer authorizes ArmorPoint in writing to create or modify a detection rule or platform configuration, ArmorPoint performs that change within the ArmorPoint platform. No such change is a warranty or guarantee of any detection, prevention, or security outcome, and Customer remains responsible for the configuration and security of its own environment.
- ArmorPoint does not guarantee compliance outcomes and does not assume legal liability for the Customer’s compliance.
- Threat hunts, custom detection rules, and detection tuning are performed on a best-effort basis using available telemetry; no detection, prevention, or breach-prevention result is guaranteed.
- ArmorPoint is not a guarantor of the Customer’s security and is not liable for a security breach except to the extent expressly provided in the ArmorPoint Terms of Service.
- ArmorPoint Advise does not include a managed Security Operations Center, monitoring, or incident response; those services, where purchased, are provided under the Customer’s underlying managed service agreement and governed by it.