Platform
Platform OverviewStart here — see how the hubs fit together.
Security Operations
Extended Detection and ResponseCorrelation engine, not just a log lake. Threat IntelligencePre-correlated to your environment. Not shelfware. Incident ResponseA structured six-phase workflow, not a chat thread.
Exposure Management
Attack Surface ManagementDiscovery plus correlation against your live stack.Asset & IdentityEvery endpoint and identity you run, tied to your threats. Vulnerability ManagementThreat-weighted prioritization. CVSS alone isn't enough.
Govern & Report
GRCContinuous evidence collection. No screenshot factory. Reporting & DashboardsLive dashboards and client-branded reports, on a schedule.
Connect
ArmorPoint AgentOne install for telemetry, inventory, and daily vulnerability reporting. IntegrationsPre-built connectors across the major security categories.
Inside the platform

Connected hubs, one operations plane

Five connected hubs. The capabilities on the left run inside them.

VisualizeSee your posture, not your tool sprawl.→OperationsFrom signal to incident to closed ticket.→GovernanceControls mapped to live evidence.→EnvironmentKnow what you have before you defend it.→Response CenterThe analyst's tools, one click away on any screen.→
Services
Compare ServicesFrom self-run to fully managed, plus advisory and onboarding.
Managed SOC
MXDROur SOC runs detection and response across your whole environment. MDRA managed SOC on your endpoints. Start here, grow into more.
Platform only
XDRThe full platform, run by your team.
Advisory layer
AdviseGet more from ArmorPoint, at the level you need.
Implementation
Guided ImplementationExpert-led, consultative onboarding to go-live.
Managed by ArmorPoint

A 24/7 SOC behind your stack

A U.S.-based SOC and the platform it runs on, watching, investigating, and responding to what matters. Security operations run for you, not handed to you.

ArmorPoint · SOC Console LIVE THREAT RADAR Signals / 24h 2,051 Analysts on shift 6 U.S. Coverage 24/7 always on
Solutions
Compare SolutionsFind your fit by industry or by the problem on your desk.
By industry
For MSPsRun a SOC across every client without standing one up for each. Federal & CMMCCMMC readiness on the same platform that runs your SOC.HealthcareProtect patient data without slowing patient care. See All Industries →Finance, Manufacturing, Utilities, Education, and more.
By need
Cyber Insurance ReadinessAnswer the renewal questionnaire with evidence, not guesses. Compliance CertificationGet certification-ready on the evidence you already produce. Post-IncidentA disciplined response when you have been breached.
Built for your mandate

What you actually answer for

Healthcare, finance, federal, MSPs — mapped to the obligations you're measured against.

What you answer for HIPAA Healthcare privacy and security MAPPED PCI-DSS Cardholder data protection MAPPED CMMC Federal contractor readiness MAPPED Cyber insurance Renewal evidence, on demand MAPPED
Resources
Resource LibraryField-tested writing, frameworks, and customer stories from the SOC.
Read
BlogPractical writing on operations, compliance, and incidents. Press ReleasesPartner announcements, awards, and milestones. ArmorPoint in the news.
Latest content

Field notes from the SOC

180+ posts. 40+ press releases. 40+ downloadable guides. Practitioner-grade writing on the work that actually matters.

BLOG · 6 MIN READ STRATEGY · MAY 2026 PRESS RELEASE ANNOUNCEMENT · MAY 2026 LIBRARY · REPORT DOWNLOAD · 24 PAGES
Partners
Partner Program OverviewFind the track that fits how you sell and deliver.
Program tracks
Service ProviderDeliver managed security with your brand on every report and your team on the relationship. ResellerAdd cybersecurity to your portfolio. Skip the operational lift.
Distribution
TD SYNNEXSell or buy ArmorPoint through TD SYNNEX distribution.
Tech alliances
Tech AlliancesEDR partners that run inside ArmorPoint: CrowdStrike, SentinelOne, Cybereason.
Get started
Become a PartnerTell us about your practice and we'll route the right program.
Partner ecosystem

We sell with you, never around you

Sold and delivered through partners who own the customer relationship. Multiple tracks, one platform.

Partner YOU Your customer THE RELATIONSHIP ArmorPoint THE PLATFORM NEVER AROUND YOU
ArmorPoint Platform Partner Portal
Request a demo
↑↓ navigate · Enter all results
Platform Overview
Security Operations
Extended Detection and ResponseThreat IntelligenceIncident Response
Exposure Management
Attack Surface ManagementAsset & IdentityVulnerability Management
Govern & Report
GRCReporting & Dashboards
Connect
ArmorPoint AgentIntegrations
Compare Services
Managed SOC
MXDRMDR
Platform only
XDR
Advisory layer
Advise
Implementation
Guided Implementation
Compare Solutions
By industry
For MSPsFederal & CMMCHealthcareSee All Industries →
By need
Cyber Insurance ReadinessCompliance CertificationPost-Incident
Resource Library
Read
BlogPress Releases
Partner Program Overview
Program tracks
Service ProviderReseller
Distribution
TD SYNNEX
Tech alliances
Tech Alliances
Get started
Become a Partner
ArmorPoint Platform Partner Portal Request a demo
Home/Legal/ArmorPoint MDR Service Agreement

Legal

ArmorPoint MDR Service Agreement

Last Updated: 09/08/2026

ArmorPoint MDR Service Scope

ArmorPoint MDR is EDR-led Managed Detection and Response (MDR), with included EDR agents and 24/7 U.S.-based SOC monitoring and response. The MDR scope is unchanged under the FY26 portfolio rebrand; this revision aligns structure, terminology, and formatting with the ArmorPoint MXDR Service Agreement only.

This Agreement defines the scope of Services. Fees, quantities, term, and any Customer-specific commercial terms are set out in the accompanying Order Form, which is incorporated into and governed by this Agreement and the ArmorPoint Terms of Service. “In-scope” means the endpoints, servers, and other event sources that (a) are connected to and sending data to the ArmorPoint platform, (b) run a supported operating system (see Appendix A), and (c) are within the quantities recorded in the Order Form. ArmorPoint’s obligations and liability under this Agreement apply only to in-scope items. Connecting, or sending data from, devices or event sources in excess of, or otherwise not covered by, the Order Form does not place those items within ArmorPoint’s obligations or liability, does not expand the Services, and is addressed by a quantity true-up through the Order Form or a Contract Change Request; ArmorPoint’s liability remains subject to the limitation of liability in the ArmorPoint Terms of Service.

ArmorPoint Platform and Technology

Endpoint Detection and Response Agents

ArmorPoint will provide EDR software agents to Customer for install on in-scope Endpoints and Servers that are on supported operating systems. The EDR agents will provide the following functions and services:

  • Anti-Virus
  • Anti-Malware
  • Exploit Protection
  • PowerShell and .Net Protection
  • Anti-Ransomware

ArmorPoint provides, configures, and manages the ArmorPoint-provided EDR at the management-console level and tunes its detection and response policies. Customer deploys the ArmorPoint-provided EDR agents to its in-scope Endpoints and Servers, keeps agent software at a current supported version, and maintains those Endpoints and Servers in a state that allows the agents to run and communicate. ArmorPoint does not install or maintain EDR agents on individual Endpoints or Servers, and does not manage, tune, or maintain any other EDR, MDR, or anti-virus tool the Customer operates (see Multiple EDR Risk Acceptance Agreement).

Log Collection and Retention

The ArmorPoint log retention policy is as follows unless otherwise specified in the Order Form:

  • Security Alerts / Incidents / Tickets — minimum 365 Days Online and Searchable
  • Benign Data (anything not related to Alerts, Incidents, Tickets; e.g., unrelated Windows Event) — 30 Days Online and Searchable; 365 Days Archived and Retrievable

The retention periods above apply during the term of the Services. Export of Customer data, restoration of archived data, and the return and deletion of Customer data upon expiration or termination are governed by the ArmorPoint Terms of Service; any data export beyond what is described there, or retrieval of archived data after termination, may be subject to additional fees as set out in the Order Form or a Contract Change Request.

Platform Dashboard and Log Analytics

ArmorPoint will provide a Platform Dashboard for correlation and reporting of collected data and events.

ArmorPoint Security Operations Center (SOC)

Management Services

ArmorPoint will provide SOC Platform management services which include:

  • Platform Health, Security, and Maintenance
  • Platform Support
  • Standard Dashboard and Report Configuration (standard dashboards and reports from ArmorPoint’s standard catalog; custom dashboards or reports are available through ArmorPoint Advise or via Contract Change Request)
  • Alert Rule Generation
  • Event-Handling
  • Log Parsing

Monitoring

ArmorPoint will provide 24x7x365 monitoring of Alerts and Incidents (definitions below) within the SOC Platform. This will include:

  • Alert assignment and management of all generated and open alerts
  • Initial alert investigation to determine if any suspicious behavior is occurring
  • Upon alert investigation, ArmorPoint will action the alert, which may include any of the following:
    • Closing the alert with the following documentation inside the platform: Resolution Type, Resolution Synopsis, Resolution Actions, Resolution Notes
    • Engage and notify Customer via pre-built notification policies with investigation notes and confirmation of activity (Customer is responsible for responding to that engagement with direction on how to proceed)
    • Escalate the alert into an Incident to be worked by the ArmorPoint Incident Management Team and notify Customer via pre-built notification policies of such escalation
  • Incident escalation, assignment and management of all escalated and created Incidents

Alert Definition

An Alert is an observable, measurable anomalous occurrence in a system or network. An example of an alert is an instance of unsuccessful logon, system crash, unplanned reboot, degradation in service performance, or network traffic spike. Alerts are monitored, reviewed, and analyzed by the ArmorPoint SOC Team and either confirmed to be benign or escalated to the level of an Incident.

Incident Definition

An Incident is an observable, measurable event taking place in a system or network that deviates from the normal behavior and implies harm or threat to do harm. Additionally, an event involving accidental loss of sensitive information is also classified as an Incident. An example of an Incident would be any unauthorized access and/or disclosure of confidential information, successful or repeated network intrusion attempt, or detection of any unwanted / malicious application or process. Upon confirmation of an Incident, ArmorPoint Incident Response services are invoked.

Monitoring and Remediation Process

ArmorPoint maintains a Security Incident Response Plan (IRP) that will be reviewed and tested annually. Appropriate training will be provided to any staff with responsibilities as part of the Security Incident Response Team (IRT).

ArmorPoint’s SOC bases its IRP on the SANS Institute’s Incident Handling methodology. The SANS Incident Handling methodology divides the response process into six phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The basic premise of this methodology is that organizations are constantly in a state of Incident response and are responsible for performing actions based on the phase they are in; the default phase is Preparation. Remediation — the work of fixing what an Incident affected — is not a separate phase under this methodology; remediation activities occur within Containment (short-term), Eradication (root-cause), and Recovery (long-term).

The Incident response process is determined by the severity level of the Incident. As the impact of an Incident becomes more significant or widespread, the escalation level increases, bringing more resources to assist in addressing the Incident. At each escalation level, individuals who will be needed at the next higher level of escalation are alerted to the Incident so they will be ready to respond when they are needed. The ArmorPoint SOC maintains 24x7 availability of IT individuals with additional on-call support as required for Incident response and monitoring coverage for any evidence of unauthorized activity, unauthorized system use, and alerts.

How ArmorPoint Delivers Response

ArmorPoint’s actions in response to a confirmed Security Incident are referred to collectively as Response. ArmorPoint delivers each response action in one of two ways. Active means ArmorPoint performs the action itself through the managed EDR, the ArmorPoint platform, or an available integration. Guided means ArmorPoint provides recommendations and the Customer performs the action. Under ArmorPoint MDR, ArmorPoint provides and manages the EDR, so endpoint actions — including host isolation, process termination, and file quarantine — are performed by ArmorPoint (Active). Active remediation through ArmorPoint’s own integrations (such as disabling an account or resetting a password) is available where the integration is in place. Actions outside ArmorPoint’s tooling or available integrations are Guided: ArmorPoint recommends and the Customer performs them.

The specific actions available in any environment depend on the tooling and integrations in use. Nothing in this Agreement obligates ArmorPoint to perform security engineering, security architecture, compliance management, or general hands-on administration of Customer systems. Active response performed during an Incident is included in the Services and is not subject to the hour limits in the Post-Eradication Scope section; ongoing remediation is subject to that section and to the Exclusions. Where active-response demand becomes sustained and materially exceeds normal operating conditions, ArmorPoint may address the additional effort through a Contract Change Request.

The Customer authorizes ArmorPoint to take automated and analyst-initiated containment actions at the endpoint through the managed EDR (including host isolation, process termination, and file quarantine) without obtaining the Customer’s approval for each individual action. Active remediation that ArmorPoint performs through an integration (such as disabling an account or resetting a password) is taken with the Customer’s approval unless the Parties agree otherwise in writing. Guided actions are performed by the Customer. The Customer may modify or revoke this standing authorization by written notice, in which case ArmorPoint’s response capability and Acknowledgement Targets are adjusted accordingly.

ArmorPoint shall have no liability for any loss, interruption, or damage arising from a containment or response action taken in good faith under the standing authorization in this section — including isolation, process termination, or quarantine of a host or file later determined to be non-malicious — except to the extent caused by ArmorPoint’s gross negligence or willful misconduct. The Customer’s sole and exclusive remedy for an erroneous containment action is ArmorPoint’s reversal of that action (for example, un-isolating the affected host or removing the applicable block) as promptly as commercially reasonable after the action is determined to have been erroneous. This remedy does not extend to data restoration, system reconstruction, or any consequential effects, which remain subject to the limitation of liability in the ArmorPoint Terms of Service.

Preparation

The Preparation phase for an Incident takes place before the Incident is identified and establishes the capability to identify Security Incidents in a timely manner and provide guidance to minimize damage from identified Incidents.

The ArmorPoint SOC IRT is authorized to leverage all necessary equipment, communication methods, offices, conference rooms, and other ArmorPoint resources for handling an Incident. This includes contacting all available on-call support personnel.

Identification

The objective of the Identification phase is to determine if a Security Incident has occurred and determine its severity based on the impact and scope of the Incident.

The ArmorPoint SOC Team is responsible for the monitoring of events and identification of suspicious activity on information systems and networks. The SOC monitors events and alerts from provided security tools and notifies the Customer in the event that suspicious activity is identified, in line with the Acknowledgement Targets set out in this Agreement and corresponding to the determined event criticality.

All Security Incidents / notifications are documented and tracked within the ArmorPoint platform. Where communication is required, the SOC will reference an Incident Response Plan (IRP) contact list provided by the Customer to ensure the appropriate individual or group is getting the appropriate level of communication.

If it is suspected that the email system has been compromised, this communication will not take place via email unless email encryption not controlled by the email server is used. Alternatively, other secure communication methods may be utilized.

Containment

The objective of the Containment phase is to mitigate risk of additional exposure or damage from a Security Incident (short-term remediation). Containment efforts may include isolating or quarantining a host, terminating a process, quarantining a file, blocking a file hash, maintaining a platform-level IP block list, and, where integrated, disabling a compromised user account or resetting a password. All Incident response activities must be carried out in a manner which does not further jeopardize the confidentiality, availability, or integrity of systems and information.

ArmorPoint performs endpoint containment actions – host isolation, process termination, file quarantine, and file-hash blocking – actively through the managed EDR and the ArmorPoint platform, under the standing authorization in the Monitoring and Remediation Process section. Off-endpoint containment steps are performed by the Customer with ArmorPoint’s guidance, and ArmorPoint provides containment recommendations and supporting information to the Customer’s designated support team for those Guided steps.

Eradication

The objective of the Eradication phase is to directly address the Security Incident and eliminate its root cause (root-cause remediation). Eradication efforts may include removing malware and attacker persistence, guidance around uninstalling affected software, applying or recommending patches, and consulting on creating or modifying firewall rules. ArmorPoint provides eradication recommendations and supporting information to the Customer’s designated support team. Off-endpoint steps, such as uninstalling affected software or modifying firewall rules, are performed by the Customer with ArmorPoint’s guidance.

Post-Eradication Scope

Once the threat has been confirmed as being contained and is no longer active, this Service includes five (5) “use it or lose it” hours per month of post-eradication remediation assistance. Any hours above the originating five (5) hours will be billed at $300.00/Hour. Included hours do not roll over from month to month.

Recovery

The objective of the Recovery phase is to resume normal operations and return any compromised systems, applications, and devices into production (long-term remediation and validation). After the system has been returned to production, its operation must be monitored to ensure the compromise does not recur and the system(s) are operating properly. ArmorPoint performs recovery actions on the ArmorPoint platform and managed EDR, such as un-isolating a host or removing a platform-level IP or file-hash block. Off-endpoint steps are performed by the Customer with ArmorPoint’s guidance, consistent with the Monitoring and Remediation Process section.

Lessons Learned

The objective of the Lessons Learned phase is to identify root causes of the Incident and develop a plan for preventing similar Incidents from occurring in the future.

A post incident report will be accessible within the ArmorPoint platform. Reporting will include information on how the incident was identified, the impact of the incident, any persons notified of the incident, and steps taken to remediate the incident. Customer follow-up will be initiated before incident closure.

If necessary, a closing meeting should occur no later than two weeks after completion of the Recovery phase. This meeting should review the incident report and is an opportunity to reflect on the incident response process to identify opportunities for improvement.

Customer Responsibilities

By accepting this agreement, the Customer understands that the below items are the responsibility of the Customer to implement and maintain. In the event that these best practices are not initiated, Customer understands that they are operating in a non-supported manner, and ArmorPoint is not responsible or liable for any performance impacts or security incidents that may occur:

  • Deploy the ArmorPoint-provided EDR agents to in-scope Endpoints and Servers, keep them at a current supported version, and keep those Endpoints and Servers in a state that allows the agents to run
  • Set EDR agent in prevention mode with appropriate modules, not detection mode
  • ArmorPoint is not responsible for security incidents originating from unmonitored devices
  • Designate authorized contacts and an escalation/notification list, and keep the Incident Response Plan contact list current; ArmorPoint relies on this list for all incident communications
  • Provide and maintain an accurate inventory of in-scope assets, and notify ArmorPoint of material changes to the environment
  • Grant and maintain the access, permissions, and network egress/firewall allowances required for the ArmorPoint-provided EDR agents to operate and communicate with the ArmorPoint platform
  • Provide the standing authorization (or revocation) for automated endpoint containment described in the Monitoring and Remediation Process section and acknowledge and respond to SOC engagement promptly. The Customer understands that ArmorPoint’s ability to perform Guided actions and to progress an Incident depends on timely Customer response.
  • System Requirements are as follows; if system requirements are unable to be met, an alternative agentless approach will be discussed with Customer (additional fees may apply):
    • Machine RAM: 4GB
    • CPU: Dual Core 2GHz Core i3 and above or equivalent
    • Available Disk Space: 1.5 GB Minimum
    • Network Connectivity: Ethernet or Wi-Fi

Important Disclaimers

  • The functional capabilities listed in this Agreement describe features of the tooling provided. They are functional descriptions, not warranties of outcome; no detection, prevention, or breach-prevention result is guaranteed.
  • ArmorPoint does not guarantee compliance outcomes.
  • ArmorPoint does not imply full automation without human SOC involvement.
  • ArmorPoint does not assume legal liability for customer compliance.
  • Running multiple EDR/MDR/AV tools may cause resource conflicts and visibility limitations — the ArmorPoint SOC operates on a commercially reasonable basis in such scenarios.

Multiple EDR Risk Acceptance Agreement

The Parties agree to the following relating to operating multiple “EDR” (Endpoint Detection and Response) or “MDR” (Managed Detection and Response) or “AV” (Anti-Virus) Tools.

ArmorPoint’s solution includes its own EDR tool that can be run in conjunction with a previously installed EDR, MDR or AV tool.

ArmorPoint recommends all Customers to singularly use the EDR tool provided as part of the ArmorPoint solution and discontinue use of multiple EDR, MDR or AV tools as part of their security stack.

With this understanding, Customer accepts this risk if dual EDRs are in use and acknowledges the following:

  • Customer is choosing to run multiple EDR, MDR or AV tools in their current deployment.
  • Customer acknowledges that running multiple EDR, MDR or AV tools can cause the following challenges:
    • Resource consumption issues on the device with multiple tools.
    • There is risk that the competing tools could interfere with each other’s processes.
    • Customer is responsible for setting exceptions and assigning policies to allow the ArmorPoint EDR tool to operate and ensure there are no conflicts.
    • There are scenarios where one tool may interfere with collection of data and block files, giving off the illusion one tool did not block against it, when the competing tool never had the opportunity to assess the data as potentially malicious.
    • Having two security products running simultaneously can cause unexpected behavior.

Customer hereby acknowledges the ArmorPoint SOC team will work on a commercially reasonable basis to support the Customer environment but may be hindered by a lack of visibility due to multiple tools being operated.

End of Life Device and Operating System Risk Acceptance Agreement

The Parties agree to the following relating to End of Life Devices and Operating Systems:

  • ArmorPoint aligns with the manufacturers when classifying End of Life devices.
  • ArmorPoint does not provide agent or collector installers for end of life devices and/or operating systems. ArmorPoint recommends all Customers upgrade to supported versions as soon as possible.
  • End of life devices and/or operating systems are unable to continue to be patched from a security perspective and are high risk security profiles for both Customer and ArmorPoint to support.

With this understanding, Customer accepts this risk and acknowledges the following:

  • ArmorPoint does not provide installers or collectors for device logs to be collected by the ArmorPoint platform;
  • ArmorPoint will provide EDR agent to devices where an EDR package has an approved installer on specific end of life devices;
  • If the EDR agent does not install properly on an end of life device, troubleshooting becomes the responsibility of the Customer;
  • ArmorPoint will provide an EDR agent and installer, but there is no guarantee on performance or protection of those devices;
  • Any such non-supported devices are not included in the bucket of support hours provided by ArmorPoint; and
  • Any remediation work specifically tied to end of life devices and/or operating systems will be billed at $300.00 / hour by ArmorPoint.

*End of Life Devices and/or Operating Systems are defined as any device or operating system that has ended or limited support on the product and/or version from the originating manufacturer or software company for maintenance purposes (software updates and security patches) and/or troubleshooting. See Appendix A for the In-Scope and Out-of-Scope Operating Systems provisions.

Customer Environment Failures

Customer agrees that ArmorPoint will not be liable for any failure to provide the SOC Services if such failure is caused by Customer’s failure to meet the applicable requirements for each Service. At a minimum, Customer is responsible for ensuring the following environmental failures do not negatively impact the Services:

  • Service interruptions or degradations due to any Customer supplied internet or private access whether provided by Customer or third parties engaged by Customer, or equipment when provided by Customer or third parties engaged by Customer.
  • Failure to completely deploy the ArmorPoint scoped solution across the in-scope environment.
  • Failure or deficient performance of Customer-supplied power, equipment, services, or systems.
  • Customer’s failure to adhere to SOC recommended configurations on managed or unmanaged equipment that affects the Service.
  • Failure to provide a secure environment for on-premise devices, including, but not limited to, secure mounting/racking, appropriate cooling and air handling, secure from theft, etc.
  • Service interruptions or degradations in Service caused by a piece of equipment, configuration, routing event or technology required to be operative in order to perform that is under the management and control of Customer.

Contractual Changes

This Agreement may be amended only by the mutual written agreement of the Parties through the Contract Change Process described below; ArmorPoint will not unilaterally modify the terms of this Agreement. ArmorPoint may update the externally maintained references expressly identified in this Agreement and its Appendices (such as any Supported Products list) strictly in accordance with the notice and version-controlled procedures stated in the applicable Appendix. Such updates take effect as provided in that Appendix and do not constitute amendments to this agreement. This Agreement is incorporated into and governed by the ArmorPoint Terms of Service. The limitation of liability, exclusion of consequential and indirect damages, disclaimer of warranties, indemnification, and insurance provisions of the ArmorPoint Terms of Service apply to this Agreement in full, and nothing in this Agreement expands ArmorPoint’s liability beyond the cap stated in the Terms of Service. In the event of a conflict among the documents that comprise the agreement between the Parties, the order of precedence is: (1) the ArmorPoint Terms of Service; (2) this Service Agreement; and (3) the applicable Order Form, provided that the fees, quantities, and term set out in the Order Form control over any conflicting commercial terms.

The following Governance structure defines the Contract Change Process:

Change To Process Vehicle
Service scope Change of scope presented with justification and supporting data. Changes that cause a change to the monthly cost to Customer of more than $1,000 will require further Executive Approval through a Contract Change process. Order Form
New project or effort Each proposed effort or initiative will be presented to executive leadership and/or board with supporting charter, solution outline and estimates. Order Form
Change to the overall service requirements and performances Each change will be presented to the Executive and be processed with further Executive Approval. Contract CCR or Addendum
Change to the scope, terms and conditions of the current Contract Each change will be presented to the Executive and be processed with further Executive Approval. Contract Addendum

Exclusions

The following exclusions apply to the scope of the work stated above and have been incorporated into the pricing set out in the Order Form:

  • Implementation of technology, including software agents, is not included within this Agreement
  • Any work or services not expressly provided for herein
  • Any application development or integration efforts not expressly provided for herein
  • Any actual hardware purchases for on-premise needs
  • Any migration or upgrade of Customer infrastructure (servers, network, etc.)
  • Any actual implementation of the recommendations made by ArmorPoint unless specified in this document
  • Any efforts tied to re-installing OS due to virus or malware or any system instability after the removal of a virus
  • Any decryption, data recovery, restoration, or rebuild work arising from a ransomware or crypto-locking event. For the avoidance of doubt, ArmorPoint may, as a containment measure under the Monitoring and Remediation Process, block at the network edge and/or isolate affected hosts; doing so does not obligate ArmorPoint to perform the excluded work described in this item.
  • Digital forensics, incident root-cause investigation beyond the data recorded in the ArmorPoint platform, malware reverse-engineering, breach-notification and regulatory-response services, and expert or litigation testimony.
  • Any data recovery and forensics work due to purposeful or malicious Customer or application errors
  • Any software license or physical hardware expenses
  • Any software license that is not explicitly mentioned, and not covered by ArmorPoint
  • All travel and lodging costs
  • Any fees related to shipping, handling, customs, duties and/or taxes
  • Any additional work requested beyond the scope of this Agreement will be expressly set forth by subsequent agreement, including, but not limited to, a Contract Change Request (“CCR”)

Service Level Targets

The following constitutes the reference for performance and expectations regarding this entire agreement. Updates to the Service Level Targets are effective only upon the mutual written approval of both Customer and ArmorPoint through the Contract Change Process, unless otherwise specified in the Order Form.

Hours of Operation – 24x7x365 Support

Service Guidelines

ArmorPoint Security Operations uses a Triaged Response Metrics system to prioritize Customer Alerts or Incidents. The below Triaged Response Metrics outline our standard service level targets for communicating the Alert or Incident status to Customer.

Ticket Priority Definitions

Priority of a ticket is defined by its impact and the criticality of the affected system. Support tickets are handled in priority order based on impact and system criticality, on a commercially reasonable basis, and not a guaranteed service level. Impact and system criticality are determined according to the chart below and assigned by ArmorPoint:

Impact \ System Criticality Tertiary System Secondary System Core Business Service
All users High High Critical
Group of users Medium High Critical
One User Low Medium High

Acknowledgement Target Metrics for Alerts and Incidents

ArmorPoint’s “Acknowledgement Target” is the time for a SOC analyst to acknowledge and begin investigating an alert or incident after it has been created. The Acknowledgement Target measures the time to begin work and is distinct from the response actions described in the Monitoring and Remediation Process section.

Priority Acknowledgement Target
High or Critical Priority 30 Minutes
Medium Priority 2 Hours
Low Priority 4 Hours

Appendix A — In-Scope Operating Systems and Supported EDR

In-Scope Event Source Operating Systems

In-scope operating systems are those that, at the relevant time, (a) remain within their originating manufacturer’s or publisher’s standard support lifecycle and are receiving security updates from that manufacturer or publisher (excluding paid extended or custom security-update programs unless ArmorPoint agrees otherwise in writing), and (b) are supported by the ArmorPoint platform and the applicable ArmorPoint agent or collector. ArmorPoint does not maintain a separate list of in-scope operating systems; supportability is determined by the manufacturer’s published support lifecycle together with ArmorPoint’s then-current platform and agent compatibility. Order Form quantities continue to control pricing.

Out-Of-Scope Operating Systems

Any operating system or version that has reached end-of-life or end-of-support from its originating manufacturer or publisher (no longer receiving security updates), or that is not supported by the ArmorPoint platform or the applicable ArmorPoint agent or collector, is out of scope and is governed by the End of Life Device and Operating System Risk Acceptance Agreement. ArmorPoint will use commercially reasonable efforts to notify the Customer before in-scope event sources lose coverage because operating system has reached manufacturer end-of-support.

ArmorPoint-Provided EDR (Supported Products)

Where ArmorPoint provides the EDR, the supported products are:

  • Cybereason EDR
  • SentinelOne Complete
  • CrowdStrike Defend

Document history

ArmorPoint is the security outcome layer for midsize enterprises and their partners, connecting detection, response, exposure, and compliance in one cloud-delivered platform with a 24/7 U.S.-based SOC. AI accelerates triage; human analysts stay in the loop.

Detection · Response · Compliance

Platform

  • Overview
  • GRC
  • Attack Surface Mgmt
  • Extended Detection and Response
  • Vulnerability Mgmt
  • Threat Intelligence
  • Integrations

Services

  • Compare all
  • MXDR
  • MDR
  • XDR
  • Advise
  • Guided Implementation

Solutions

  • Compare all
  • For MSPs
  • Federal & CMMC
  • Healthcare
  • Financial Services
  • Cyber Insurance
  • Compliance Cert.

Resources

  • Resource library
  • Blog
  • Press Releases

Company

  • About
  • Partners
  • Find a partner
  • Become a partner
  • Request a demo
  • Platform login

Legal

  • Trust Center
  • Privacy notice
  • Terms of service
  • Status page
SC Awards 2026 Excellence Award Winner MSSP Alert Top 250 MSSP 2024 Honoree CRN 5-Star Partner Program Guide Winner 2025 CRN 5-Star Partner Program Guide Winner 2024
© 2026 ArmorPoint, LLC. All rights reserved.
Privacy Terms Trust