SCOUT / MANAGED SERVICE

TPRM without the headcount.

Hand off the operations of your TPRM program to the team that built the platform. We continuously map vendor connections, monitor risk, surface exposure when an incident hits a fourth or fifth party, and give your GRC team an AI analyst that does not sleep.

▲ YOUR PROGRAM, OUR EXECUTION

You own the decisions. We run the program.

Most security teams know they need a mature TPRM program. Few have the dedicated headcount to operate one. Managed Scout closes that gap without adding headcount. We configure the platform around your risk appetite and compliance requirements, then run it on your behalf. Vendor risk decisions remain yours. The operational load does not.

Vendor onboarding and assessments. We intake your vendor portfolio, send assessments, chase responses, and apply Archer's analysis to every return. Your team sees scored results, not raw questionnaires.
Continuous monitoring. External posture signals tracked across your full vendor portfolio. Alerts triaged before they reach you. Genuine issues escalated with context, not noise.
Incident response support. When a vendor breach or supply chain event hits, we immediately surface what is exposed in your portfolio, which data is at risk, and the recommended posture. Hours, not days.
01
Onboarding and configuration
We learn your vendor landscape, risk appetite, and compliance requirements. Your Scout instance is configured with the right templates, tiers, and monitoring thresholds for your environment.
02
Vendor intake
We onboard your existing vendors into Scout, establish baseline risk scores, and identify the highest-priority gaps in your current program.
03
Ongoing operations
Assessments, monitoring triage, finding remediation follow-up, and document tracking handled on an ongoing basis. Your platform stays current without pulling your team into operational work.
04
Reporting on your cadence
Monthly executive summaries and quarterly board-ready reports delivered to your specifications. Portfolio risk trends, open findings, remediation status, and forward-looking recommendations included as standard.
▲ ANALYST OPERATIONS

What a Pylon analyst does as part of Managed Scout.

Specific operational work covered in every Managed Scout engagement.

01 / ASSESS Assessment lifecycle

Assessments sent, followed up on, scored by Archer, reviewed by an analyst, and returned to you with findings and recommended responses.

02 / MONITOR Monitoring triage

External posture alerts reviewed on a regular cadence. False positives cleared. Genuine changes escalated with a plain-language summary of what changed and why it matters.

03 / FINDINGS Remediation chase-down

Risk findings tracked through closure. Vendors followed up on remediations. Nothing sits in an open state indefinitely because a queued task went unworked.

04 / REPORT Monthly board reports

Executive-ready summaries produced on your cadence. Portfolio risk posture, trends, top risks, and remediation progress delivered in a format boards and auditors can use.

05 / DOCUMENTS Certification tracking

SOC 2, ISO certificates, and policy documents tracked for expiry. Renewal requests sent proactively. Archer extracts controls on upload so the analysis is current when the cert is.

06 / SUPPLY CHAIN Sub-processor mapping

Fourth and fifth-party relationships documented and monitored. Concentration risk identified. When a shared dependency hits an incident, you know immediately which of your vendors are exposed.

07 / INCIDENTS Ad-hoc investigations

When a vendor breach or industry event warrants a deeper look, we investigate using Scout and Archer. Exposure summary, recommended posture, and talking points for your leadership ready within hours.

08 / ACCESS Full platform visibility

You have complete access to your Scout instance at all times. See everything we see. Export anything we build. Override any call we make. It is your data and your program.

▲ SELF-SERVICE VS MANAGED

Same platform. Different operational model.

Both tiers run on Scout with Archer and the Trust Network. Managed is a superset: every Self-Service capability plus Pylon analysts running the day-to-day.

Self-Service Managed Scout
Full Scout platform access
Archer AI analyst
Trust Network and assessment auto-fill
Continuous external monitoring
Supply-chain and sub-processor mapping
Vendor onboarding and intake Your team runs it We handle it
Assessment send, follow-up, and scoring Your team runs it We handle it
Monitoring alert triage Your team runs it We handle it
Finding and remediation tracking Your team runs it We handle it
Certification and document expiry tracking Your team runs it We handle it
Monthly executive reports You build them Delivered on schedule
Incident triage and ad-hoc investigations Your team runs it We handle it
Dedicated Pylon analyst team
▲ QUESTIONS

Common questions.

How does pricing work?

Scoped per engagement based on portfolio size, assessment cadence, and on-call expectations. Pricing is an annual flat fee, not per-seat. We share a quote on the discovery call. No meaningful Managed Service engagement looks identical, so we don't publish a price card.

Who owns the data?

You do. Scout is your single source of truth for vendor risk. Export anytime, retention is your choice, no lock-in clauses. Full platform access is yours throughout the engagement, not just at the end.

What happens when an incident hits a vendor in my portfolio?

Standard Managed engagements include incident triage hours each month. When a breach or supply chain event touches a vendor in your portfolio, we surface what is exposed, what data is at risk, and the recommended posture within hours rather than days. You get a summary you can take directly to leadership, not a raw intelligence feed to interpret yourself.

Can we start on Self-Service and move to Managed later?

Yes. Self-Service customers move to Managed without losing data, configurations, or the Trust Network profiles built up over time. Migration is a conversation, not a re-implementation. The same is true in reverse: Managed customers who build internal capacity can transition to Self-Service and keep everything in place.

What is the SLA on assessment turnaround?

Five business days for standard assessments from the point a vendor begins responding. Critical vendors can be expedited. Where the Trust Network has an existing profile for that vendor, auto-fill handles the majority of the work upfront and the clock shortens considerably.

▲ GET STARTED

Ready to hand off the operations?

Book a 30-minute call. We will walk through your current vendor portfolio, your compliance requirements, and what a scoped Managed engagement looks like for your environment.

Request a demo →