# Armor

**Canonical:** https://apis.io/providers/armor/  
**Website:** https://www.armor.com/  
**APIs profiled:** 70

Armor (legal name Armor Defense Inc.) is a cybersecurity company headquartered in Plano, Texas, founded as FireHost in 2009 by Chris Drake and rebranded as Armor as its portfolio expanded from secure cloud hosting into managed security. Armor sells vendor-agnostic, cloud-native managed detection and response (Armor MDR), compliant managed private cloud (Armor Enterprise Cloud), the Armor Agent workload protection agent (formerly Armor Anywhere), and compliance and offensive-security professional services, to more than 1,700 organizations across 40 countries with a 24/7 follow-the-sun SOC operating from Plano, London, Singapore and Pune. Armor publishes a public developer portal at developer.armor.com that serves sixteen machine-readable contracts through ReDoc: four Swagger 2.0 documents for the original v1 Armor Services API on api.armor.com (account management, infrastructure, security and support, 254 operations) and twelve OpenAPI 3.0.3 documents for the v2 platform on *.api.secure-prod.services (accounts, agent management, compliance and CSPM, container security, incident management, infrastructure management, log management, notifications, webhooks, the unified MDR public API, and the ARMOR-PSK and FH-AUTH authentication contracts). Armor also publishes a detailed first-party llms.txt at armor.com/llms.txt and holds SOC 2 Type II, HITRUST CSF, PCI DSS Level 1 Service Provider, ISO 27001, TX-RAMP Level 2, HIPAA and Data Privacy Framework attestations.

## Kin Score — 50.9 / 100 (developing)

Scored 2026-08-12 under rubric 0.11.0. Trend: flat (+0.0 from 50.9).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 64.9 |
| Governance | 20.8 |
| Operational Transparency | 28.9 |
| Developer Ergonomics | 51.6 |
| Commercial Clarity | 52.6 |

## Agent readiness — 50.7 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | yes |

## APIs (70)

- **Armor Access Control Lists API** — Operations for managing ACLs (deprecated)
- **Armor Account API** — Account management operations
- **Armor Account Management API** — The Account Management API from Armor — 47 operation(s) for account management.
- **Armor Account Primary Billing API** — The AccountPrimaryBilling API from Armor — 1 operation(s) for accountprimarybilling.
- **Armor Active Response API** — The ActiveResponse API from Armor — 1 operation(s) for activeresponse.
- **Armor Advanced Backup API** — The Advanced Backup API from Armor — 38 operation(s) for advanced backup.
- **Armor AIP - Entity Intelligence API** — Threat intelligence data for security entities
- **Armor AIP - Incident Data API** — AI-processed incident data and analytics
- **Armor Assessments API** — Assessment account management
- **Armor Authentication API** — FH-AUTH authentication flow endpoints. ## Flow Overview 1. POST `/auth/authorize` with credentials → receive authorization code 2. POST `/auth/token` with code → receive access ...
- **Armor Cloud Connections API** — Cloud connection management operations
- **Armor Connector API** — Connector management operations
- **Armor CSPM Connector API** — Cloud Security Posture Management cloud connectors
- **Armor CSPM Control Remediation API** — CSPM control remediation information
- **Armor CSPM Policies API** — CSPM policy management
- **Armor CSPM Policy Controls API** — CSPM policy controls management
- **Armor CSPM Report API** — CSPM report operations
- **Armor CSPM Report Configuration API** — CSPM report configuration management
- **Armor CSPM Resources API** — CSPM resource management
- **Armor CSPM Summary API** — CSPM cloud connector summary
- **Armor CSPM Usage API** — CSPM cloud connector usage
- **Armor Defender - Investigation API** — Investigation package and live response operations
- **Armor Defender - Machine Actions API** — Execute and manage actions on Microsoft Defender machines
- **Armor Defender - Machines API** — Microsoft Defender machine/device management
- **Armor Detection Rules API** — Operations for retrieving and managing detection rules
- **Armor Detections API** — The detection resource enables an API customer to build a webhook detection configuration.
- **Armor EDR API** — Endpoint Detection and Response operations
- **Armor Events API** — The event-type resource enables an API user to maintain the event types.
- **Armor Flow Sources API** — Operations for managing flow sources
- **Armor Health API** — Service health and monitoring endpoints
- **Armor Health Monitoring Status API** — Health monitoring status operations
- **Armor Image API** — Image management operations
- **Armor Infrastructure API** — The Infrastructure API from Armor — 35 operation(s) for infrastructure.
- **Armor JSM - Incidents API** — Security incident management
- **Armor JSM - Metrics API** — Metrics aggregation and reporting
- **Armor JSM - Organizations API** — JSM organization management
- **Armor JSM - Service Requests API** — Service request management
- **Armor Keys API** — The Keys API from Armor — 2 operation(s) for keys.
- **Armor Log Endpoints API** — Operations for managing log endpoints
- **Armor Log Groups API** — Operations for managing log groups
- …and 30 more, listed in full on the page.

## MCP servers (1)

- **armor-mcp.yml**

## Agentic access (1)

- **Armor Agentic Access** — 427 operations · 172 acting · 5 human-in-the-loop

## Security (2)

- **Armor Authentication** — apiKey/http/oauth2 · 6 schemes
- **Armor Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Cybersecurity, Managed Detection and Response, Cloud Security, Compliance, SIEM, Vulnerability Management, Endpoint Security, Threat Intelligence, Managed Private Cloud, CSPM, Container Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/armor/). Scores are computed from the provider's own public artifacts under a published rubric.
