ArmorPoint says, "Security without response is just surveillance." And this is on point with its latest platform expansion.
ArmorPoint has expanded its security operations platform with new incident response, risk and compliance capabilities aimed at MSPs, MSSPs, and resellers managing security for midsize customers.
The update brings alert investigation, asset and identity data, threat intelligence, vulnerability information and compliance into one platform. ArmorPoint is also adding AI-assisted alert triage, a Response Center for managing incidents and a Governance Hub for compliance reporting and audit evidence.
For service providers, this is to make security easier to manage across multiple customers. Partners can also decide how much of the day-to-day work they want to handle themselves and how much they want ArmorPoint’s SOC to take on.
ArmorPoint CEO David Trapp told MSSP Alert, “There are plenty of products that can help an MSP or MSSP detect a threat. What we think is still underserved is everything that has to happen after detection: investigation, response, documentation, and ultimately proving what was done."
ArmorPoint has built the platform around that broader workflow, bringing detection and response together with asset and identity context, threat intelligence, risk information, and compliance evidence. Its 24/7 U.S.-based SOC works in the same environment alongside partners.
Managing security across multiple customers
That same setup also gives service providers one view across all of their customers. ArmorPoint is multi-tenant, so partners can see alerts, risks, assets, and security status across their customer base, then drill into a specific account. Each customer's environment remains separate, with its own access controls and permissions.
“For service providers, that environment is multi-tenant by design,” Trapp said. “A partner can see posture, risk, alerts, assets, and operational status across their entire customer base, then drill into an individual client with per-client isolation and role-based access.”
That becomes especially relevant for MSPs and MSSPs trying to scale security services. Analysts can work across multiple customers from one system rather than maintaining separate operating environments for each account.
At the individual customer level, ArmorPoint is also trying to reduce the amount of context gathering analysts have to do during an investigation.
“An analyst investigating an incident does not have to reconstruct the story across a SIEM, an endpoint console, a vulnerability tool, a ticketing system, and a compliance platform before making a decision,” Trapp said.
Bringing more context into alert investigation
ArmorPoint puts asset details, identity data, vulnerabilities, threat intelligence and logs alongside each alert, giving analysts the context they need in one place. AI is used to help triage incoming alerts by assigning a confidence score and explaining the reasoning behind it. Each automated step is logged, and AI-assisted verdicts still go to an analyst for review before any action is taken.
For MSPs and MSSPs, that can cut down on routine investigation work while keeping people in control of response decisions.
“The difference is operational context at both levels: across the partner's customer base and inside each individual client,” Trapp said. “That context carries from detection through investigation and response, all the way into the evidence that proves the work happened.”
Partners can choose how much of the SOC they want to own
ArmorPoint is keeping the platform itself unified, but partners have several ways to package and deliver the service.
“There is one platform underneath, but there are multiple ways for a partner to consume and deliver it,” Trapp said.
Partners using ArmorPoint's XDR offering can operate the platform with their own security teams. MDR adds ArmorPoint's 24/7 SOC around endpoint detection and response, while MXDR extends the managed service across a broader set of sources, including endpoint, identity, cloud, SaaS and network data.
Advisory, implementation and integration services can also be added depending on the partner and customer.
That gives MSPs room to change the service model as a customer's security needs grow without moving to a different underlying platform.
“It is not one rigid bundle, and it is also not a shelf of disconnected security modules,” Trapp said. “Partners can match the delivery model to their own maturity and the needs of each client while keeping the same underlying security operation as they expand.”
For MSPs building out a security practice gradually, that flexibility can matter. A provider can use its own analysts where it has the staff and expertise, rely more heavily on ArmorPoint's SOC where it does not, and change the mix over time.
“That is especially important for MSPs because they do not have to rebuild the stack every time a customer matures or needs broader coverage,” Trapp said. “They can start with what that customer needs today and expand the operation over time.”
Incident response gets its own workflow
ArmorPoint has also added a Response Center that follows six stages of incident handling: detection, analysis, containment, eradication, recovery and lessons learned. Its SOC can handle 24/7 AI-assisted triage, investigation, validation, escalation and approved containment actions. Partners remain involved in remediation and customer communication. On more sensitive response actions, the approval process is set at the account level during onboarding.
“Containment or remediation moves only through an approved path, and who has that approval authority, the partner or the client, is defined for each account during onboarding,” Trapp said.
That creates room for different partner operating models. An MSSP with its own analysts may use ArmorPoint to add capacity or overnight coverage. An MSP without a staffed SOC can hand more of the day-to-day operation to ArmorPoint.
“A partner with its own analysts can work much more directly in the platform and use ArmorPoint to extend its capacity,” Trapp said. “A partner that does not want to staff a 24/7 SOC can put more of the day-to-day security operation in our hands. The model can change as the partner's practice grows.”
Connecting security work and compliance
The new Governance Hub connects day-to-day security work with compliance requirements. ArmorPoint says it maps activity to frameworks including CMMC Level 2, PCI DSS 4.0, the HIPAA Security Rule, SOC 2 and NIST Cybersecurity Framework 2.0. It can also generate system security plans, risk assessments and supporting evidence from work already happening inside the platform.
For MSPs and MSSPs, that creates another service opportunity around compliance. The same monitoring, investigation and response work they already do can help produce the documentation customers need for audits and regulatory requirements, while also making the value of the service easier to show.
MSPs keep control of the customer relationship
ArmorPoint is also drawing a clear line around who owns the customer. “The partner owns the customer relationship, full stop,” Trapp said. “They determine how they package the service for their clients, set their own customer-facing pricing and commercial terms, and remain the primary point of communication.”
Partners can use their own branding on customer-facing reports and determine their own service tiers and pricing. They also retain visibility across customers, while each account keeps its own permissions, escalation paths, workflows and rules of engagement.
That matters in a market where MSPs often depend on vendors behind the scenes but still want to remain the customer's primary security provider.
“We are the operation behind the provider, not a vendor inserting itself between the provider and their customer,” Trapp said. “The provider stays the company the customer knows, calls, and trusts.”