Platform
Platform OverviewStart here — see how the hubs fit together.
Security Operations
SIEMCorrelation engine, not just a log lake. Threat IntelligencePre-correlated to your environment. Not shelfware. Incident ResponseA structured six-phase workflow, not a chat thread.
Exposure Management
Attack Surface ManagementDiscovery plus correlation against your live stack.Asset & IdentityEvery endpoint and identity you run, tied to your threats. Vulnerability ManagementThreat-weighted prioritization. CVSS alone isn't enough.
Govern & Report
GRCContinuous evidence collection. No screenshot factory. Reporting & DashboardsLive dashboards and client-branded reports, on a schedule.
Connect
IntegrationsPre-built connectors across the major security categories.
Inside the platform

Connected hubs, one operations plane

Detection, response, and compliance running on one platform. Not separate tools stitched together with dashboards.

POSTURE DASHBOARD / analyst-view LIVE · 24H POSTURE SCORE 87 ↑ 4 vs 7d 88 ↑ 5 vs 7d 89 ↑ 6 vs 7d 91 ↑ 8 vs 7d OPEN RISKS 142 ↓ 12 vs 7d 138 ↓ 16 vs 7d 131 ↓ 23 vs 7d 127 ↓ 27 vs 7d COVERAGE 94% 5/5 sources 95% 5/5 sources 96% 5/5 sources 97% 5/5 sources CONTROL GAPS 14 3 critical 12 2 critical 11 2 critical 9 1 critical Detection volume EVENTS / HOUR · LAST 24H 24H 7D 30D 00:00 06:00 12:00 18:00 now
Services
Compare ServicesFrom self-run to fully managed, plus advisory and onboarding.
Managed SOC
MXDROur SOC runs detection and response across your whole environment. MDRA managed SOC on your endpoints. Start here, grow into more.
Platform only
XDRThe full platform, run by your team.
Advisory layer
AdviseGet more from ArmorPoint, at the level you need.
Implementation
Guided ImplementationExpert-led, consultative onboarding to go-live.
Managed by ArmorPoint

A 24/7 SOC behind your stack

A U.S.-based SOC and the platform it runs on, watching, investigating, and responding to what matters. Security operations run for you, not handed to you.

ArmorPoint · SOC Console LIVE THREAT RADAR Signals / 24h 2,051 Analysts on shift 6 U.S. Coverage 24/7 always on
Solutions
Compare SolutionsFind your fit by industry or by the problem on your desk.
By industry
For MSPsRun a SOC across every client without standing one up for each. Federal & CMMCCMMC readiness on the same platform that runs your SOC.HealthcareProtect patient data without slowing patient care. See All Industries →Finance, Manufacturing, Utilities, Education, and more.
By need
Cyber Insurance ReadinessAnswer the renewal questionnaire with evidence, not guesses. Compliance CertificationGet certification-ready on the evidence you already produce. Post-BreachA disciplined response when you have been breached.
Built for your mandate

What you actually answer for

Healthcare, finance, federal, MSPs — mapped to the obligations you're measured against.

What you answer for HIPAA Healthcare privacy and security MAPPED PCI-DSS Cardholder data protection MAPPED CMMC Federal contractor readiness MAPPED Cyber insurance Renewal evidence, on demand MAPPED
Resources
Resource LibraryField-tested writing, frameworks, and customer stories from the SOC.
Read
BlogPractical writing on operations, compliance, and incidents. Press ReleasesPartner announcements, awards, and milestones. ArmorPoint in the news.
Latest content

Field notes from the SOC

180+ posts. 40+ press releases. 40+ downloadable guides. Practitioner-grade writing on the work that actually matters.

BLOG · 6 MIN READ STRATEGY · MAY 2026 PRESS RELEASE ANNOUNCEMENT · MAY 2026 LIBRARY · REPORT DOWNLOAD · 24 PAGES
Partners
Partner Program OverviewFind the track that fits how you sell and deliver.
Program tracks
Service ProviderDeliver managed security with your brand on every report and your team on the relationship. ResellerAdd cybersecurity to your portfolio. Skip the operational lift.
Distribution
TD SYNNEXSell or buy ArmorPoint through TD SYNNEX distribution.
Tech alliances
Tech AlliancesEDR partners that run inside ArmorPoint: CrowdStrike, SentinelOne, Cybereason.
Get started
Become a PartnerTell us about your practice and we'll route the right program.
Partner ecosystem

We sell with you, never around you

Sold and delivered through partners who own the customer relationship. Multiple tracks, one platform.

Partner YOU Your customer THE RELATIONSHIP ArmorPoint THE PLATFORM NEVER AROUND YOU
ArmorPoint Platform Partner Portal
Request a demo
Platform Overview
Security Operations
SIEMThreat IntelligenceIncident Response
Exposure Management
Attack Surface ManagementAsset & IdentityVulnerability Management
Govern & Report
GRCReporting & Dashboards
Connect
Integrations
Compare Services
Managed SOC
MXDRMDR
Platform only
XDR
Advisory layer
Advise
Implementation
Guided Implementation
Compare Solutions
By industry
For MSPsFederal & CMMCHealthcareSee All Industries →
By need
Cyber Insurance ReadinessCompliance CertificationPost-Breach
Resource Library
Read
BlogPress Releases
Partner Program Overview
Program tracks
Service ProviderReseller
Distribution
TD SYNNEX
Tech alliances
Tech Alliances
Get started
Become a Partner
ArmorPoint Platform Partner Portal Request a demo
Home/Legal/DataView Service Agreement

Legal

DataView Service Agreement

ArmorPoint DataView Service Scope

ARMORPOINT PLATFORM AND USER ACCESS

DataView Access

ArmorPoint DataView provides Users with the ability to search and analyze historical security events and response actions across the different event types (alerts, incidents, tickets, and vulnerability data – if applicable) that was generated during the Client’s previously Managed SOC service term (“DataView Access”). ArmorPoint DataView may be used by the Client to support their organization's specific data retention requirements, whether for compliance mandates (e.g., PCI DSS, HIPAA, SOX) or internal policies.

ArmorPoint Platform and User Permissions for the ArmorPoint DataView service is:

  • DataView Access:
    • DataView version of the web-based ArmorPoint Platform with a focused/limited view

Historical Data Access

HISTORICAL DATA ACCESS

Historical Data

Historical Data is defined as data that was collected and retained by ArmorPoint during the Client’s previously Managed SOC service contract term.

Types of Historical Data include:

  • Alerts and their related log data
  • Incidents and their related log data
  • Tickets
  • Vulnerabilities (if applicable)
  • Raw Data
    • Raw Data is defined as collected logs that may or may not be related to Alerts, Incidents, Vulnerabilities, or Tickets. This could include, but not limited to Windows Event logs, Network Device logs, and/or Agent Performance logs.

Historical Data Retention

Historical Data with an age exceeding that of the retention period defined in the Client’s previously Managed SOC service contract is not retained by ArmorPoint, and therefore not able to be retrieved or restored.

For example, the standard retention policy for Managed SOC services includes 365 days of data retention that begins on the date the data was collected by ArmorPoint. Additional data retention time was available for purchase during the Managed SOC service at an additional cost.

Historical Data Retrieval and Restoration

Historical Data retrieval and restoration is facilitated through the web-based ArmorPoint Platform. Users can retrieve different types of Historical Data differently, depending on the Data Type:

  • Alert, Incident, Ticket, or Vulnerability (if applicable) events are immediately accessible in the ArmorPoint Platform for self-service query by the Client and does not require the Client to submit a Retrieval Request ticket.
  • Raw Data is securely located in cold storage. Retrieving Raw Data from cold storage and subsequently restoring it to the ArmorPoint Platform for self-service query by the Client will require the Client to submit a Data Retrieval Request Ticket via the ArmorPoint Platform. Once the Data Retrieval Request Ticket is received, ArmorPoint will work to restore the data in alignment with the Service Level Targets defined in this Service Agreement.
  • Each Data Retrieval Request Ticket is limited to a 30-day window of Historical Data. Multiple Data Retrieval Request Tickets can be submitted to cover a longer time frame.

Service Level Targets (SLT)

ArmorPoint will respond to a received Data Retrieval Request Ticket via support ticket communication with a 24-hour service level target that begins upon ticket receipt.

Data Type Storage Details Data Retrieval and Restoration Details Retrieval Request Service Level Target
Alerts Online and searchable in Platform Self-Service Retrieval N/A; Immediately available in Platform
Incidents Online and searchable in Platform Self-Service Retrieval N/A; Immediately available in Platform
Tickets Online and searchable in Platform Self-Service Retrieval N/A; Immediately available in Platform
Vulnerabilities (if applicable) Online and searchable in Platform Self-Service Retrieval N/A; Immediately available in Platform
Raw Data Retained in secure cold storage Requires Data Retrieval Ticket to Restore Data restored within 24 hours of ticket submission*

*The 24-hour SLT for Data Retrieval Requests is a Service Level Target (SLT) rather than a Service Level Agreement (SLA). This is because the time required to restore large volumes of data can vary. While we strive to restore Historical Data within the 24-hour target for all requests, events outside ArmorPoint’s control could impact service delivery. Clients with exceptionally large data sets may experience longer retrieval and restoration times. ArmorPoint will provide daily status updates of your data request via ticket communication.

Contractual Changes

This Service Agreement may change and ArmorPoint may update this Service Agreement from time to time. It is your responsibility to check this Service Agreement periodically for changes.

The following Governance structure defines the Contract Change Process:

Change To Vehicle Process
Service scope Change of scope presented with justification and supporting data. Changes that cause a change to the monthly cost to Client of more than $1,000 will require further Executive Approval through a Contract Change process. Order Form
New project or effort Each proposed effort or initiative will be presented to executive leadership and/or board with supporting charter, solution outline and estimates. Order Form
Change to the overall service requirements and performances Each change will be presented to the Executive and be processed with further Executive Approval Contract CCR or Addendum
Change to the scope, terms and conditions of the current Each change will be presented to the Executive and be processed with further Executive Approval Contract Addendum

Exclusions

The following exclusions apply to the scope of the work stated above and have been incorporated into the pricing stated below:

  • Ingestion of any new log data or activity into the ArmorPoint Platform
  • Monitoring or alerting by the ArmorPoint Platform or ArmorPoint SOC
  • Custom data analysis, reporting or investigation services
  • Data exports exceeding the 30-day range per request, or bulk exports of all historical data
  • Implementation of technology, including software agents, is not included within the Service Agreement
  • Any work or services not expressly provided for herein
  • Any application development or integration efforts not expressly provided for herein
  • Any actual hardware purchases for on-premises needs
  • Any migration or upgrade of Client infrastructure (servers, network, etc.)
  • Any actual implementation of the recommendations made by ArmorPoint unless specified in this document
  • Any data recovery and forensics work due to purposeful or malicious Client or application errors
  • Any software license or physical hardware expenses
  • Any software license that’s not explicitly mentioned, and not covered by ArmorPoint
  • All Travel and lodging costs
  • Any fees related to shipping, handling, customs, duties and/or taxes
  • Any additional work requested beyond the scope of this Agreement will be expressly set forth by subsequent agreement, including, but not limited to, a Contract Change Request (“CCR”)

Revision History

Document Version Published Date Description or Notes
1.0 06.27.2025 Initial Publication Date

On this page

  • ArmorPoint DataView Service Scope
  • Historical Data Access
  • Service Level Targets (SLT)
  • Contractual Changes
  • Exclusions
  • Revision History

ArmorPoint is a cloud-native managed security operations platform for midsize enterprises and their partners, uniting detection, response, risk, and compliance with a 24/7 U.S.-based SOC. AI-accelerated triage, human analysts in the loop. Resilience that's provable, not just promised.

Detection · Response · Compliance

Platform

  • Overview
  • GRC
  • Attack Surface Mgmt
  • SIEM
  • Vulnerability Mgmt
  • Threat Intelligence
  • Integrations

Services

  • Compare all
  • MXDR
  • MDR
  • XDR
  • Advise
  • Guided Implementation

Solutions

  • Compare all
  • For MSPs
  • Federal & CMMC
  • Healthcare
  • Financial Services
  • Cyber Insurance
  • Compliance Cert.

Resources

  • Resource library
  • Blog
  • Press Releases

Company

  • About
  • Partners
  • Find a partner
  • Become a partner
  • Request a demo
  • Platform login

Legal

  • Trust Center
  • Privacy notice
  • Terms of service
  • Status page
SC Awards 2026 Excellence Award Winner MSSP Alert Top 250 MSSP 2024 Honoree CRN 5-Star Partner Program Guide Winner 2025 CRN 5-Star Partner Program Guide Winner 2024
© 2026 ArmorPoint, LLC. All rights reserved.
Privacy Terms Trust