ArmorPoint MDR Service Scope
ArmorPoint MDR is EDR-led Managed Detection and Response (MDR), with included EDR agents and 24/7 U.S.-based SOC monitoring and response. The MDR scope is unchanged under the FY26 portfolio rebrand; this revision aligns structure, terminology, and formatting with the ArmorPoint MXDR Service Agreement only.
This Agreement defines the scope of Services. Fees, quantities, term, and any Customer-specific commercial terms are set out in the accompanying Order Form, which is incorporated into and governed by this Agreement and the ArmorPoint Terms of Service. “In-scope” means the endpoints, servers, and other event sources that (a) are connected to and sending data to the ArmorPoint platform, (b) run a supported operating system (see Appendix A), and (c) are within the quantities recorded in the Order Form. ArmorPoint’s obligations and liability under this Agreement apply only to in-scope items. Connecting, or sending data from, devices or event sources in excess of, or otherwise not covered by, the Order Form does not place those items within ArmorPoint’s obligations or liability, does not expand the Services, and is addressed by a quantity true-up through the Order Form or a Contract Change Request; ArmorPoint’s liability remains subject to the limitation of liability in the ArmorPoint Terms of Service.
ArmorPoint Platform and Technology
Endpoint Detection and Response Agents
ArmorPoint will provide EDR software agents to Customer for install on in-scope Endpoints and Servers that are on supported operating systems. The EDR agents will provide the following functions and services:
- Anti-Virus
- Anti-Malware
- Exploit Protection
- PowerShell and .Net Protection
- Anti-Ransomware
ArmorPoint provides, configures, and manages the ArmorPoint-provided EDR at the management-console level and tunes its detection and response policies. Customer deploys the ArmorPoint-provided EDR agents to its in-scope Endpoints and Servers, keeps agent software at a current supported version, and maintains those Endpoints and Servers in a state that allows the agents to run and communicate. ArmorPoint does not install or maintain EDR agents on individual Endpoints or Servers, and does not manage, tune, or maintain any other EDR, MDR, or anti-virus tool the Customer operates (see Multiple EDR Risk Acceptance Agreement).
Log Collection and Retention
The ArmorPoint log retention policy is as follows unless otherwise specified in the Order Form:
- Security Alerts / Incidents / Tickets — minimum 365 Days Online and Searchable
- Benign Data (anything not related to Alerts, Incidents, Tickets; e.g., unrelated Windows Event) — 30 Days Online and Searchable; 365 Days Archived and Retrievable
The retention periods above apply during the term of the Services. Export of Customer data, restoration of archived data, and the return and deletion of Customer data upon expiration or termination are governed by the ArmorPoint Terms of Service; any data export beyond what is described there, or retrieval of archived data after termination, may be subject to additional fees as set out in the Order Form or a Contract Change Request.
Platform Dashboard and Log Analytics
ArmorPoint will provide a Platform Dashboard for correlation and reporting of collected data and events.
ArmorPoint Security Operations Center (SOC)
Management Services
ArmorPoint will provide SOC Platform management services which include:
- Platform Health, Security, and Maintenance
- Platform Support
- Standard Dashboard and Report Configuration (standard dashboards and reports from ArmorPoint’s standard catalog; custom dashboards or reports are available through ArmorPoint Advise or via Contract Change Request)
- Alert Rule Generation
- Event-Handling
- Log Parsing
Monitoring
ArmorPoint will provide 24x7x365 monitoring of Alerts and Incidents (definitions below) within the SOC Platform. This will include:
- Alert assignment and management of all generated and open alerts
- Initial alert investigation to determine if any suspicious behavior is occurring
- Upon alert investigation, ArmorPoint will action the alert, which may include any of the following:
- Closing the alert with the following documentation inside the platform: Resolution Type, Resolution Synopsis, Resolution Actions, Resolution Notes
- Engage and notify Customer via pre-built notification policies with investigation notes and confirmation of activity (Customer is responsible for responding to that engagement with direction on how to proceed)
- Escalate the alert into an Incident to be worked by the ArmorPoint Incident Management Team and notify Customer via pre-built notification policies of such escalation
- Incident escalation, assignment and management of all escalated and created Incidents
Alert Definition
An Alert is an observable, measurable anomalous occurrence in a system or network. An example of an alert is an instance of unsuccessful logon, system crash, unplanned reboot, degradation in service performance, or network traffic spike. Alerts are monitored, reviewed, and analyzed by the ArmorPoint SOC Team and either confirmed to be benign or escalated to the level of an Incident.
Incident Definition
An Incident is an observable, measurable event taking place in a system or network that deviates from the normal behavior and implies harm or threat to do harm. Additionally, an event involving accidental loss of sensitive information is also classified as an Incident. An example of an Incident would be any unauthorized access and/or disclosure of confidential information, successful or repeated network intrusion attempt, or detection of any unwanted / malicious application or process. Upon confirmation of an Incident, ArmorPoint Incident Response services are invoked.
Monitoring and Remediation Process
ArmorPoint maintains a Security Incident Response Plan (IRP) that will be reviewed and tested annually. Appropriate training will be provided to any staff with responsibilities as part of the Security Incident Response Team (IRT).
ArmorPoint’s SOC bases its IRP on the SANS Institute’s Incident Handling methodology. The SANS Incident Handling methodology divides the response process into six phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The basic premise of this methodology is that organizations are constantly in a state of Incident response and are responsible for performing actions based on the phase they are in; the default phase is Preparation. Remediation — the work of fixing what an Incident affected — is not a separate phase under this methodology; remediation activities occur within Containment (short-term), Eradication (root-cause), and Recovery (long-term).
The Incident response process is determined by the severity level of the Incident. As the impact of an Incident becomes more significant or widespread, the escalation level increases, bringing more resources to assist in addressing the Incident. At each escalation level, individuals who will be needed at the next higher level of escalation are alerted to the Incident so they will be ready to respond when they are needed. The ArmorPoint SOC maintains 24x7 availability of IT individuals with additional on-call support as required for Incident response and monitoring coverage for any evidence of unauthorized activity, unauthorized system use, and alerts.
How ArmorPoint Delivers Response
ArmorPoint’s actions in response to a confirmed Security Incident are referred to collectively as Response. ArmorPoint delivers each response action in one of two ways. Active means ArmorPoint performs the action itself through the managed EDR, the ArmorPoint platform, or an available integration. Guided means ArmorPoint provides recommendations and the Customer performs the action. Under ArmorPoint MDR, ArmorPoint provides and manages the EDR, so endpoint actions — including host isolation, process termination, and file quarantine — are performed by ArmorPoint (Active). Active remediation through ArmorPoint’s own integrations (such as disabling an account or resetting a password) is available where the integration is in place. Actions outside ArmorPoint’s tooling or available integrations are Guided: ArmorPoint recommends and the Customer performs them.
The specific actions available in any environment depend on the tooling and integrations in use. Nothing in this Agreement obligates ArmorPoint to perform security engineering, security architecture, compliance management, or general hands-on administration of Customer systems. Active response performed during an Incident is included in the Services and is not subject to the hour limits in the Post-Eradication Scope section; ongoing remediation is subject to that section and to the Exclusions. Where active-response demand becomes sustained and materially exceeds normal operating conditions, ArmorPoint may address the additional effort through a Contract Change Request.
The Customer authorizes ArmorPoint to take automated and analyst-initiated containment actions at the endpoint through the managed EDR (including host isolation, process termination, and file quarantine) without obtaining the Customer’s approval for each individual action. Active remediation that ArmorPoint performs through an integration (such as disabling an account or resetting a password) is taken with the Customer’s approval unless the Parties agree otherwise in writing. Guided actions are performed by the Customer. The Customer may modify or revoke this standing authorization by written notice, in which case ArmorPoint’s response capability and Acknowledgement Targets are adjusted accordingly.
ArmorPoint shall have no liability for any loss, interruption, or damage arising from a containment or response action taken in good faith under the standing authorization in this section — including isolation, process termination, or quarantine of a host or file later determined to be non-malicious — except to the extent caused by ArmorPoint’s gross negligence or willful misconduct. The Customer’s sole and exclusive remedy for an erroneous containment action is ArmorPoint’s reversal of that action (for example, un-isolating the affected host or removing the applicable block) as promptly as commercially reasonable after the action is determined to have been erroneous. This remedy does not extend to data restoration, system reconstruction, or any consequential effects, which remain subject to the limitation of liability in the ArmorPoint Terms of Service.
Preparation
The Preparation phase for an Incident takes place before the Incident is identified and establishes the capability to identify Security Incidents in a timely manner and provide guidance to minimize damage from identified Incidents.
The ArmorPoint SOC IRT is authorized to leverage all necessary equipment, communication methods, offices, conference rooms, and other ArmorPoint resources for handling an Incident. This includes contacting all available on-call support personnel.
Identification
The objective of the Identification phase is to determine if a Security Incident has occurred and determine its severity based on the impact and scope of the Incident.
The ArmorPoint SOC Team is responsible for the monitoring of events and identification of suspicious activity on information systems and networks. The SOC monitors events and alerts from provided security tools and notifies the Customer in the event that suspicious activity is identified, in line with the Acknowledgement Targets set out in this Agreement and corresponding to the determined event criticality.
All Security Incidents / notifications are documented and tracked within the ArmorPoint platform. Where communication is required, the SOC will reference an Incident Response Plan (IRP) contact list provided by the Customer to ensure the appropriate individual or group is getting the appropriate level of communication.
If it is suspected that the email system has been compromised, this communication will not take place via email unless email encryption not controlled by the email server is used. Alternatively, other secure communication methods may be utilized.
Containment
The objective of the Containment phase is to mitigate risk of additional exposure or damage from a Security Incident (short-term remediation). Containment efforts may include isolating or quarantining a host, terminating a process, quarantining a file, blocking a file hash, maintaining a platform-level IP block list, and, where integrated, disabling a compromised user account or resetting a password. All Incident response activities must be carried out in a manner which does not further jeopardize the confidentiality, availability, or integrity of systems and information.
ArmorPoint performs endpoint containment actions – host isolation, process termination, file quarantine, and file-hash blocking – actively through the managed EDR and the ArmorPoint platform, under the standing authorization in the Monitoring and Remediation Process section. Off-endpoint containment steps are performed by the Customer with ArmorPoint’s guidance, and ArmorPoint provides containment recommendations and supporting information to the Customer’s designated support team for those Guided steps.
Eradication
The objective of the Eradication phase is to directly address the Security Incident and eliminate its root cause (root-cause remediation). Eradication efforts may include removing malware and attacker persistence, guidance around uninstalling affected software, applying or recommending patches, and consulting on creating or modifying firewall rules. ArmorPoint provides eradication recommendations and supporting information to the Customer’s designated support team. Off-endpoint steps, such as uninstalling affected software or modifying firewall rules, are performed by the Customer with ArmorPoint’s guidance.
Post-Eradication Scope
Once the threat has been confirmed as being contained and is no longer active, this Service includes five (5) “use it or lose it” hours per month of post-eradication remediation assistance. Any hours above the originating five (5) hours will be billed at $300.00/Hour. Included hours do not roll over from month to month.
Recovery
The objective of the Recovery phase is to resume normal operations and return any compromised systems, applications, and devices into production (long-term remediation and validation). After the system has been returned to production, its operation must be monitored to ensure the compromise does not recur and the system(s) are operating properly. ArmorPoint performs recovery actions on the ArmorPoint platform and managed EDR, such as un-isolating a host or removing a platform-level IP or file-hash block. Off-endpoint steps are performed by the Customer with ArmorPoint’s guidance, consistent with the Monitoring and Remediation Process section.
Lessons Learned
The objective of the Lessons Learned phase is to identify root causes of the Incident and develop a plan for preventing similar Incidents from occurring in the future.
A post incident report will be accessible within the ArmorPoint platform. Reporting will include information on how the incident was identified, the impact of the incident, any persons notified of the incident, and steps taken to remediate the incident. Customer follow-up will be initiated before incident closure.
If necessary, a closing meeting should occur no later than two weeks after completion of the Recovery phase. This meeting should review the incident report and is an opportunity to reflect on the incident response process to identify opportunities for improvement.
Customer Responsibilities
By accepting this agreement, the Customer understands that the below items are the responsibility of the Customer to implement and maintain. In the event that these best practices are not initiated, Customer understands that they are operating in a non-supported manner, and ArmorPoint is not responsible or liable for any performance impacts or security incidents that may occur:
- Deploy the ArmorPoint-provided EDR agents to in-scope Endpoints and Servers, keep them at a current supported version, and keep those Endpoints and Servers in a state that allows the agents to run
- Set EDR agent in prevention mode with appropriate modules, not detection mode
- ArmorPoint is not responsible for security incidents originating from unmonitored devices
- Designate authorized contacts and an escalation/notification list, and keep the Incident Response Plan contact list current; ArmorPoint relies on this list for all incident communications
- Provide and maintain an accurate inventory of in-scope assets, and notify ArmorPoint of material changes to the environment
- Grant and maintain the access, permissions, and network egress/firewall allowances required for the ArmorPoint-provided EDR agents to operate and communicate with the ArmorPoint platform
- Provide the standing authorization (or revocation) for automated endpoint containment described in the Monitoring and Remediation Process section and acknowledge and respond to SOC engagement promptly. The Customer understands that ArmorPoint’s ability to perform Guided actions and to progress an Incident depends on timely Customer response.
- System Requirements are as follows; if system requirements are unable to be met, an alternative agentless approach will be discussed with Customer (additional fees may apply):
- Machine RAM: 4GB
- CPU: Dual Core 2GHz Core i3 and above or equivalent
- Available Disk Space: 1.5 GB Minimum
- Network Connectivity: Ethernet or Wi-Fi
Important Disclaimers
- The functional capabilities listed in this Agreement describe features of the tooling provided. They are functional descriptions, not warranties of outcome; no detection, prevention, or breach-prevention result is guaranteed.
- ArmorPoint does not guarantee compliance outcomes.
- ArmorPoint does not imply full automation without human SOC involvement.
- ArmorPoint does not assume legal liability for customer compliance.
- Running multiple EDR/MDR/AV tools may cause resource conflicts and visibility limitations — the ArmorPoint SOC operates on a commercially reasonable basis in such scenarios.
Multiple EDR Risk Acceptance Agreement
The Parties agree to the following relating to operating multiple “EDR” (Endpoint Detection and Response) or “MDR” (Managed Detection and Response) or “AV” (Anti-Virus) Tools.
ArmorPoint’s solution includes its own EDR tool that can be run in conjunction with a previously installed EDR, MDR or AV tool.
ArmorPoint recommends all Customers to singularly use the EDR tool provided as part of the ArmorPoint solution and discontinue use of multiple EDR, MDR or AV tools as part of their security stack.
With this understanding, Customer accepts this risk if dual EDRs are in use and acknowledges the following:
- Customer is choosing to run multiple EDR, MDR or AV tools in their current deployment.
- Customer acknowledges that running multiple EDR, MDR or AV tools can cause the following challenges:
- Resource consumption issues on the device with multiple tools.
- There is risk that the competing tools could interfere with each other’s processes.
- Customer is responsible for setting exceptions and assigning policies to allow the ArmorPoint EDR tool to operate and ensure there are no conflicts.
- There are scenarios where one tool may interfere with collection of data and block files, giving off the illusion one tool did not block against it, when the competing tool never had the opportunity to assess the data as potentially malicious.
- Having two security products running simultaneously can cause unexpected behavior.
Customer hereby acknowledges the ArmorPoint SOC team will work on a commercially reasonable basis to support the Customer environment but may be hindered by a lack of visibility due to multiple tools being operated.
End of Life Device and Operating System Risk Acceptance Agreement
The Parties agree to the following relating to End of Life Devices and Operating Systems:
- ArmorPoint aligns with the manufacturers when classifying End of Life devices.
- ArmorPoint does not provide agent or collector installers for end of life devices and/or operating systems. ArmorPoint recommends all Customers upgrade to supported versions as soon as possible.
- End of life devices and/or operating systems are unable to continue to be patched from a security perspective and are high risk security profiles for both Customer and ArmorPoint to support.
With this understanding, Customer accepts this risk and acknowledges the following:
- ArmorPoint does not provide installers or collectors for device logs to be collected by the ArmorPoint platform;
- ArmorPoint will provide EDR agent to devices where an EDR package has an approved installer on specific end of life devices;
- If the EDR agent does not install properly on an end of life device, troubleshooting becomes the responsibility of the Customer;
- ArmorPoint will provide an EDR agent and installer, but there is no guarantee on performance or protection of those devices;
- Any such non-supported devices are not included in the bucket of support hours provided by ArmorPoint; and
- Any remediation work specifically tied to end of life devices and/or operating systems will be billed at $300.00 / hour by ArmorPoint.
*End of Life Devices and/or Operating Systems are defined as any device or operating system that has ended or limited support on the product and/or version from the originating manufacturer or software company for maintenance purposes (software updates and security patches) and/or troubleshooting. See Appendix A for the In-Scope and Out-of-Scope Operating Systems provisions.
Customer Environment Failures
Customer agrees that ArmorPoint will not be liable for any failure to provide the SOC Services if such failure is caused by Customer’s failure to meet the applicable requirements for each Service. At a minimum, Customer is responsible for ensuring the following environmental failures do not negatively impact the Services:
- Service interruptions or degradations due to any Customer supplied internet or private access whether provided by Customer or third parties engaged by Customer, or equipment when provided by Customer or third parties engaged by Customer.
- Failure to completely deploy the ArmorPoint scoped solution across the in-scope environment.
- Failure or deficient performance of Customer-supplied power, equipment, services, or systems.
- Customer’s failure to adhere to SOC recommended configurations on managed or unmanaged equipment that affects the Service.
- Failure to provide a secure environment for on-premise devices, including, but not limited to, secure mounting/racking, appropriate cooling and air handling, secure from theft, etc.
- Service interruptions or degradations in Service caused by a piece of equipment, configuration, routing event or technology required to be operative in order to perform that is under the management and control of Customer.
Contractual Changes
This Agreement may be amended only by the mutual written agreement of the Parties through the Contract Change Process described below; ArmorPoint will not unilaterally modify the terms of this Agreement. ArmorPoint may update the externally maintained references expressly identified in this Agreement and its Appendices (such as any Supported Products list) strictly in accordance with the notice and version-controlled procedures stated in the applicable Appendix. Such updates take effect as provided in that Appendix and do not constitute amendments to this agreement. This Agreement is incorporated into and governed by the ArmorPoint Terms of Service. The limitation of liability, exclusion of consequential and indirect damages, disclaimer of warranties, indemnification, and insurance provisions of the ArmorPoint Terms of Service apply to this Agreement in full, and nothing in this Agreement expands ArmorPoint’s liability beyond the cap stated in the Terms of Service. In the event of a conflict among the documents that comprise the agreement between the Parties, the order of precedence is: (1) the ArmorPoint Terms of Service; (2) this Service Agreement; and (3) the applicable Order Form, provided that the fees, quantities, and term set out in the Order Form control over any conflicting commercial terms.
The following Governance structure defines the Contract Change Process:
| Change To | Process | Vehicle |
|---|---|---|
| Service scope | Change of scope presented with justification and supporting data. Changes that cause a change to the monthly cost to Customer of more than $1,000 will require further Executive Approval through a Contract Change process. | Order Form |
| New project or effort | Each proposed effort or initiative will be presented to executive leadership and/or board with supporting charter, solution outline and estimates. | Order Form |
| Change to the overall service requirements and performances | Each change will be presented to the Executive and be processed with further Executive Approval. | Contract CCR or Addendum |
| Change to the scope, terms and conditions of the current Contract | Each change will be presented to the Executive and be processed with further Executive Approval. | Contract Addendum |
Exclusions
The following exclusions apply to the scope of the work stated above and have been incorporated into the pricing set out in the Order Form:
- Implementation of technology, including software agents, is not included within this Agreement
- Any work or services not expressly provided for herein
- Any application development or integration efforts not expressly provided for herein
- Any actual hardware purchases for on-premise needs
- Any migration or upgrade of Customer infrastructure (servers, network, etc.)
- Any actual implementation of the recommendations made by ArmorPoint unless specified in this document
- Any efforts tied to re-installing OS due to virus or malware or any system instability after the removal of a virus
- Any decryption, data recovery, restoration, or rebuild work arising from a ransomware or crypto-locking event. For the avoidance of doubt, ArmorPoint may, as a containment measure under the Monitoring and Remediation Process, block at the network edge and/or isolate affected hosts; doing so does not obligate ArmorPoint to perform the excluded work described in this item.
- Digital forensics, incident root-cause investigation beyond the data recorded in the ArmorPoint platform, malware reverse-engineering, breach-notification and regulatory-response services, and expert or litigation testimony.
- Any data recovery and forensics work due to purposeful or malicious Customer or application errors
- Any software license or physical hardware expenses
- Any software license that is not explicitly mentioned, and not covered by ArmorPoint
- All travel and lodging costs
- Any fees related to shipping, handling, customs, duties and/or taxes
- Any additional work requested beyond the scope of this Agreement will be expressly set forth by subsequent agreement, including, but not limited to, a Contract Change Request (“CCR”)
Service Level Targets
The following constitutes the reference for performance and expectations regarding this entire agreement. Updates to the Service Level Targets are effective only upon the mutual written approval of both Customer and ArmorPoint through the Contract Change Process, unless otherwise specified in the Order Form.
Hours of Operation – 24x7x365 Support
Service Guidelines
ArmorPoint Security Operations uses a Triaged Response Metrics system to prioritize Customer Alerts or Incidents. The below Triaged Response Metrics outline our standard service level targets for communicating the Alert or Incident status to Customer.
Ticket Priority Definitions
Priority of a ticket is defined by its impact and the criticality of the affected system. Support tickets are handled in priority order based on impact and system criticality, on a commercially reasonable basis, and not a guaranteed service level. Impact and system criticality are determined according to the chart below and assigned by ArmorPoint:
| Impact \ System Criticality | Tertiary System | Secondary System | Core Business Service |
|---|---|---|---|
| All users | High | High | Critical |
| Group of users | Medium | High | Critical |
| One User | Low | Medium | High |
Acknowledgement Target Metrics for Alerts and Incidents
ArmorPoint’s “Acknowledgement Target” is the time for a SOC analyst to acknowledge and begin investigating an alert or incident after it has been created. The Acknowledgement Target measures the time to begin work and is distinct from the response actions described in the Monitoring and Remediation Process section.
| Priority | Acknowledgement Target |
|---|---|
| High or Critical Priority | 30 Minutes |
| Medium Priority | 2 Hours |
| Low Priority | 4 Hours |
Appendix A — In-Scope Operating Systems and Supported EDR
In-Scope Event Source Operating Systems
In-scope operating systems are those that, at the relevant time, (a) remain within their originating manufacturer’s or publisher’s standard support lifecycle and are receiving security updates from that manufacturer or publisher (excluding paid extended or custom security-update programs unless ArmorPoint agrees otherwise in writing), and (b) are supported by the ArmorPoint platform and the applicable ArmorPoint agent or collector. ArmorPoint does not maintain a separate list of in-scope operating systems; supportability is determined by the manufacturer’s published support lifecycle together with ArmorPoint’s then-current platform and agent compatibility. Order Form quantities continue to control pricing.
Out-Of-Scope Operating Systems
Any operating system or version that has reached end-of-life or end-of-support from its originating manufacturer or publisher (no longer receiving security updates), or that is not supported by the ArmorPoint platform or the applicable ArmorPoint agent or collector, is out of scope and is governed by the End of Life Device and Operating System Risk Acceptance Agreement. ArmorPoint will use commercially reasonable efforts to notify the Customer before in-scope event sources lose coverage because operating system has reached manufacturer end-of-support.
ArmorPoint-Provided EDR (Supported Products)
Where ArmorPoint provides the EDR, the supported products are:
- Cybereason EDR
- SentinelOne Complete
- CrowdStrike Defend