Fidential Argus
Sign inBook a demo

Features

Eight agents, one approval gate, one board PDF

Argus runs a fixed specialist pipeline per vendor. The planner orchestrates research, scanning, evidence, questionnaire, 4th-party reconciliation, scoring, and report drafting. Your team approves before anything publishes.

Pipeline

Planner through Scribe

Each agent has a narrow job and a versioned tool allowlist you control from the operator console. Outputs land in one assessment run your analysts review in context.

  1. 01

    Planner

    Chooses which agents run, in what order, based on vendor tier and assessment scope. You see the plan before work starts.

  2. 02

    Scout

    Maps the vendor public surface: trust center, security page, DPA URLs, and initial risk tier from what is published.

  3. 03

    Recon

    Scores hygiene from DNS, SPF/DKIM/DMARC, TLS certificates, crt.sh history, and breach signals where keys are configured.

  4. 04

    Surface

    Outside-in exposure scan: open ports, CVE matches, CISA KEV hits on detected IPs, and header posture.

  5. 05

    Librarian

    Reads uploaded SOC reports and DPAs. Extracts control claims with citations so analysts can trace every sentence.

  6. 06

    Interrogator

    Generates a tailored questionnaire only for gaps the evidence did not close. No generic 200-question export.

  7. 07

    Lineage

    Reconciles contractual sub-processors against scan-detected dependencies. Undisclosed providers become findings.

  8. 08

    Scorer

    Maps posture to NIST CSF 2.0 controls with corroboration rules. A control is not marked met on vendor prose alone.

  9. 09

    Scribe

    Drafts the board-ready PDF with sourced findings, score summary, and concentration notes for your review.

Human gate

Nothing publishes without sign-off

Scribe produces a draft PDF. An approver on your team reviews findings, edits notes, and approves or sends back for revision. The gate is server-side and audit-logged.

Delivery path

Draft report → analyst review → approve → customer delivery

Rejected drafts return to the assessment with revision notes. No silent auto-send.

Read the security model

Wedge

4th-party sub-processor reconciliation

Lineage compares the DPA sub-processor table to dependencies Recon and Surface detect. When scanning finds a provider the contract never named, Argus records an undisclosed_detected finding with both sides cited.

  • Disclosed in DPA, detected in scan: matched
  • Disclosed only: monitor for drift on the next run
  • Detected only: undisclosed_detected finding for analyst review
  • Shared across vendors: concentration alert on the portfolio

DPA list

Amazon Web Services · hosting

Scan detected

Cloudflare · CDN · global

Finding type

undisclosed_detected

Cloudflare appears in headers and DNS but not on the signed sub-processor schedule.

Corroboration

Controls score as met only with evidence and scan agreement

Scorer will not mark a NIST CSF control met from vendor marketing copy alone. A control needs an extraction from uploaded evidence and a matching external signal from Recon or Surface where the control is observable from the outside.

  • Evidence only

    Vendor SOC claims encryption at rest

    Needs evidence

  • Scan only

    TLS 1.0 detected on api.vendor.example

    Finding open

  • Evidence + scan

    DMARC reject aligned with published policy

    Met

See the pipeline on a live vendor

Book a demo walkthrough of Planner through approval on a sample assessment.

Book a demo

Fidential Argus

Agentic vendor risk assessment with 4th-party reconciliation. Built for security teams who need defensible answers, not checkbox surveys.

Product

  • Product overview
  • Features
  • Use cases
  • Security
  • Pricing
  • Resources

Company

  • About
  • FAQ
  • Status

Legal

  • Terms of service
  • Privacy policy
  • Sub-processors

Get started

  • Book a demo
  • Sign in

© 2026 Fidential. Guidance, not legal advice.