However you run security, ArmorPoint fits.
Run ArmorPoint fully managed by our 24/7 U.S.-based SOC, or run the same platform with your own team. Same detection, response, and compliance, deployed to fit how you operate.
Choose how you run ArmorPoint
Extended Detection & Response.
The full ArmorPoint platform, without the managed service. Unified detection, correlation, and compliance evidence, operated by your security team.
Managed Detection & Response.
Our 24/7 U.S.-based SOC managing detection and response across your endpoints. Foundational coverage, with room to grow.
Managed Extended Detection & Response.
Our 24/7 U.S.-based SOC running the full ArmorPoint platform across endpoint, identity, cloud, SaaS, and network. The whole operation, end to end.
It's all the ArmorPoint platform underneath. MDR focuses it on your endpoints, MXDR runs the full stack, and XDR is the whole platform, self-run. Start anywhere, scale up without re-implementation.
Turn data into action.
MXDR and MDR include 24/7 U.S.-based SOC monitoring, full incident response, and managed detection. ArmorPoint Advise builds on that managed baseline with recurring meetings designed to help you get the most out of your platform.
Explore Advise in detailStrategic
+ DEDICATED SECURITY ENGINEERCustom detection engineering, threat hunting, compliance program support, architecture review, and executive briefings. A virtual extension of your team.
Active
+ NAMED TECHNICAL SPECIALISTOperations reviews, detection tuning, IR runbook development, and incident post-mortems. Monthly or quarterly.
Foundations
+ ENHANCED PLATFORM ACCESSBranded posture dashboards, a live MITRE ATT&CK coverage map, vulnerability trends, environment-scored threat intel, and automated monthly reports. No added headcount.
24/7 U.S.-based SOC, full incident response, managed detection.
Pricing scales with tier and scope, defined during discovery. Tabletop exercises and threat hunts available as add-ons.
Three ways to run the same platform.
Every tier runs on the ArmorPoint platform. What changes is who operates it and how much we cover.
| XDRYour platform, your team | MDRManaged protection, endpoint-first | MXDRSecOps as-a-Service | |
|---|---|---|---|
| Best for | You have your own team and want the platform without the managed service | You want managed detection and response anchored on the endpoint | You want your security run for you, end to end |
| Who runs it | Your team | ArmorPoint SOC | ArmorPoint SOC |
| 24/7 U.S.-based SOC | You monitor, self-run | Included | Included |
| What we watch | Endpoint, network, identity, cloud, logs | Endpoint-focused | Endpoint, network, identity, cloud, logs |
| Endpoint protection (EDR) | Use your own | Included & fully managed | Included, or bring your own |
| Threat detection & alerting | Yes, automated | Yes | Yes |
| Investigation & triage | Your team | ArmorPoint analysts | ArmorPoint analysts |
| Hands-on threat response | You act | ArmorPoint acts | ArmorPoint acts* |
| Automated threat blocking | Yes | Yes | Yes |
| Incident response | You lead, with our playbook | ArmorPoint-led | ArmorPoint-led |
| Response-time targets | You set the pace | 30 min for critical threats | 30 min for critical threats |
| Compliance-aligned reporting | Yes | Yes | Yes |
* BYO-EDR on MXDR is endpoint response advisory: we recommend, you act. ArmorPoint acts directly through its own platform integrations, such as disabling an account. Coverage and response targets are confirmed during discovery; service-agreement drafts are not yet executed.
Let's find how it fits for you.
Bring your stack and a sense of where you want coverage. We'll walk through which service fits the operation you run, and whether Advise belongs in the conversation.