Supply-chain risk
Find the sub-processors your vendors did not disclose
Argus reconciles what a vendor claims in its DPA against what outside-in scanning actually detects. Undisclosed dependencies and concentration risk surface before they become an audit finding or a breach headline.
Undisclosed detected
3
Sub-processors in scan results absent from the contractual DPA list for a single vendor assessment.
Concentration alert
5 / 12
Vendors in portfolio depend on the same cloud provider. Portfolio-level view, not one vendor at a time.
How it works
Eight specialist agents, one orchestrated assessment
A planner coordinates research, scanning, evidence review, questionnaire generation, 4th-party reconciliation, scoring, and report drafting. Each agent has a narrow job and a versioned tool allowlist you control from the operator console.
01
Scout
Maps public surface, trust center, and DPA URLs. Suggests initial risk tier.
02
Recon
DNS, email auth, TLS, certificates, and breach signals for hygiene scoring.
03
Surface
Outside-in exposure scan: ports, CVEs, CISA KEV matches on detected IPs.
04
Librarian
Reads uploaded evidence and extracts control claims with citations.
05
Interrogator
Generates a tailored questionnaire from gaps the evidence did not close.
06
Lineage
Reconciles DPA sub-processor lists against scan-detected dependencies.
07
Scorer
Scores residual risk against NIST CSF controls with corroboration rules.
08
Scribe
Drafts a board-ready report. Nothing ships until a human approves.
Differentiator
4th-party reconciliation, not another questionnaire
Most tools stop at the vendor boundary. Argus fuses contractual sub-processor lists from the DPA with what reconnaissance and lineage agents detect in the wild. Gaps become findings. Shared providers become concentration alerts across your portfolio.
- Match disclosed vs detected dependencies in four buckets
- Flag undisclosed sub-processors as audit-ready findings
- Surface portfolio concentration before a single provider outage hits everyone
Disclosed in DPA
Amazon Web Services · hosting · US
Detected in scan
Cloudflare · CDN · global
Undisclosed detected
Cloudflare · CDN · not on DPA list
Finding: undisclosed dependency
Portfolio concentration
5 of 12 vendors
Depend on Amazon Web Services as a sub-processor chain anchor.
Trust
Built for buyers who read security pages before they book a demo
The same questions you ask vendors are the questions Argus answers about itself.
Human approval gate
Every assessment report stays draft until an approver on your team signs off. The gate is server-side and cannot be bypassed from the UI.
Append-only audit trail
Agent actions, approvals, impersonation sessions, and operator changes write to an immutable audit log. Export evidence packages for your own auditors.
Tenant isolation
Every row carries tenant scope. Cross-tenant data access is blocked at the repository layer, not just hidden in the UI.
Residency options
SaaS deployment on Azure with Canadian residency available for single-tenant mode. Your data stays in-region when contract requires it.
Guidance, not rulings
Compliance outputs are sourced, dated, and hedged. Argus helps you investigate and document posture; it does not replace counsel.
Processor transparency
Argus publishes its own sub-processor list and security posture the same way it expects from the vendors you assess.
See undisclosed dependencies on your vendor list
Walk through a live assessment flow with your team. We will show reconciliation, concentration alerts, and the approval gate on real contract shapes.