Features
Eight agents, one approval gate, one board PDF
Argus runs a fixed specialist pipeline per vendor. The planner orchestrates research, scanning, evidence, questionnaire, 4th-party reconciliation, scoring, and report drafting. Your team approves before anything publishes.
Pipeline
Planner through Scribe
Each agent has a narrow job and a versioned tool allowlist you control from the operator console. Outputs land in one assessment run your analysts review in context.
01
Planner
Chooses which agents run, in what order, based on vendor tier and assessment scope. You see the plan before work starts.
02
Scout
Maps the vendor public surface: trust center, security page, DPA URLs, and initial risk tier from what is published.
03
Recon
Scores hygiene from DNS, SPF/DKIM/DMARC, TLS certificates, crt.sh history, and breach signals where keys are configured.
04
Surface
Outside-in exposure scan: open ports, CVE matches, CISA KEV hits on detected IPs, and header posture.
05
Librarian
Reads uploaded SOC reports and DPAs. Extracts control claims with citations so analysts can trace every sentence.
06
Interrogator
Generates a tailored questionnaire only for gaps the evidence did not close. No generic 200-question export.
07
Lineage
Reconciles contractual sub-processors against scan-detected dependencies. Undisclosed providers become findings.
08
Scorer
Maps posture to NIST CSF 2.0 controls with corroboration rules. A control is not marked met on vendor prose alone.
09
Scribe
Drafts the board-ready PDF with sourced findings, score summary, and concentration notes for your review.
Human gate
Nothing publishes without sign-off
Scribe produces a draft PDF. An approver on your team reviews findings, edits notes, and approves or sends back for revision. The gate is server-side and audit-logged.
Delivery path
Draft report → analyst review → approve → customer delivery
Rejected drafts return to the assessment with revision notes. No silent auto-send.
Read the security modelWedge
4th-party sub-processor reconciliation
Lineage compares the DPA sub-processor table to dependencies Recon and Surface detect. When scanning finds a provider the contract never named, Argus records an undisclosed_detected finding with both sides cited.
- Disclosed in DPA, detected in scan: matched
- Disclosed only: monitor for drift on the next run
- Detected only: undisclosed_detected finding for analyst review
- Shared across vendors: concentration alert on the portfolio
DPA list
Amazon Web Services · hosting
Scan detected
Cloudflare · CDN · global
Finding type
undisclosed_detected
Cloudflare appears in headers and DNS but not on the signed sub-processor schedule.
Corroboration
Controls score as met only with evidence and scan agreement
Scorer will not mark a NIST CSF control met from vendor marketing copy alone. A control needs an extraction from uploaded evidence and a matching external signal from Recon or Surface where the control is observable from the outside.
Evidence only
Vendor SOC claims encryption at rest
Needs evidence
Scan only
TLS 1.0 detected on api.vendor.example
Finding open
Evidence + scan
DMARC reject aligned with published policy
Met
See the pipeline on a live vendor
Book a demo walkthrough of Planner through approval on a sample assessment.