NFR Program
Full Open XDR, 24/7 SOC, and a named Fractional Security Director. Not a sandbox, not a trial license. The complete production architecture running in your environment.
Best fit
Who this is for
For MSPs and IT services firms at the point where endpoint-only coverage is no longer enough for the clients they are taking on.
END-CLIENT BASE
MSPs and IT services firms whose clients are moving into mid-market, regulated-industry, or enterprise work where endpoint-only coverage stops being credible.
OPERATIONAL ENVIRONMENT
MSPs and IT services firms taking on OT, industrial IoT, building automation, or any environment where half the kit on the network cannot run an agent.
COMMERCIAL DECISION
Operators evaluating channel-only SOC alternatives to Arctic Wolf, Huntress, CrowdStrike, Darktrace, or building the capability in-house.
What you get
Full deployment, no sandbox, no limits
Full Open XDR architecture deployed on your own network.
Endpoint, network, identity, cloud, IoT, OT. Not a sample, not a sandbox. Full production architecture.
A named Fractional Security Director assigned from day one.
CISSP-certified, your point of contact for the 90 days. Joins calls, walks through findings, briefs your team.
24/7 SOC monitoring across all surfaces.
The same SOC posture our paying partners receive. Real analysts, real escalations, real runbooks for your environment.
Audit-ready compliance reporting.
Sample evidence mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, and HIPAA.
Hardening and tuning, not just monitoring.
Across the 90 days we tune detections to your environment and harden the surfaces we find. What you see at day 90 is a configured deployment, not a default install.
What we need from you is light. Complete the onboarding forms, grant environment access, and push agents through your existing tooling.
Parallel deployment
Onboard a client during the same window
If you have a client ready to onboard during the same 90-day window, both deployments run in parallel. You get to demonstrate the architecture in front of a real end-client engagement, with our SOC and your named Fractional Security Director supporting you on every call.
We implemented the platform internally first. That helped us understand its value before we took it to market, and the support from enhanced.io made it easy to launch.
Steve Pezzani, CEO, Shinka IT
NFR partner
Already deployed across these environments
MSPs moving upstream.
Endpoint-only coverage stops being credible at a certain client size and sector. We work with MSPs at that inflection point, whether or not their environment has OT or IoT.
OT, IoT, and regulated sectors.
Deployed across manufacturing, building management, industrial IoT, and regulated industries where half the network cannot run an endpoint agent.
Multi-site and hybrid cloud.
Deployed across organizations running workloads across multiple sites, cloud tenants, and data centers where a single-pane view across all surfaces is not optional.
Available across our core regions
The NFR program is open to MSPs and IT services firms across our core regions.
EMEA
NORTH AMERICA
APAC
After day 90
Three ways to exit - no pressure on any of them
Convert to a paid partnership.
Same architecture, same named Fractional Security Director, same SOC. No re-onboarding. One subscription fee covers everything.
Take the findings and continue independently.
You keep the compliance evidence and findings shared with you across the 90 days. We retain none of your data after exit. No contract, no follow-up obligation.
Walk away.
No obligation. No ongoing contract. No commercial follow-up unless you want one.
What a paid partnership includes
If you choose to convert, here is what the paid partnership looks like. The same architecture, the same team, no re-onboarding.
One subscription, not three line items.
The platform, the 24/7 SOC, and your named Fractional Security Director are bundled in one fee. No platform-plus-SOC-plus-FSD line items.
Per-endpoint or per user pricing.
You quote your clients with confidence because the underlying cost does not move when telemetry volume changes. We absorb the ingestion variability. No surprises.
Channel-only by commercial commitment.
enhanced.io never goes direct to your clients. Your relationship, your renewal, your margin.
Continuity.
The same architecture, the same SOC analysts, the same named Fractional Security Director who ran your 90 days. No re-onboarding.
Frequently asked questions
Questions we get asked
Is the 90 days actually free?
Yes. No fee, no trial license, no sandbox. The full production architecture runs in your environment for 90 days. The only cost is your time.
What exactly is deployed during the NFR?
The complete enhanced.io stack. Full Open XDR covering endpoint, network, identity, cloud, IoT, and OT. 24/7 SOC monitoring at the same level our paying partners receive. A named, CISSP-certified Fractional Security Director assigned from day one. And audit-ready compliance reporting mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, and HIPAA.
How long does deployment take?
Deployment is scoped to what is being onboarded, typically 30 to 45 days. The biggest driver of speed is how quickly you return the information we need. You complete the onboarding forms, we run the deployment, agents go out through your own tooling, and where there is no virtualization we may need a physical sensor or a firewall change. Deployment is the start, not the whole 90 days. Across the window we harden the surfaces we find and tune detections to your environment.
What do you need from us during the 90 days?
Not much. Complete the onboarding forms, give us access to the environment, and push agents through your existing tooling. We run the deployment, the hardening, the tuning, and the monitoring.
Do you need access to our clients during the NFR?
No. The NFR runs on your own network. Client involvement is entirely optional. If you have a client ready to onboard during the same window, we can run both deployments in parallel.
What happens to our data if we do not convert at day 90?
We retain none of your data after the 90 days end. Standard data handling terms apply.
Will our Fractional Security Director change if we convert to a paid partnership?
No. The named Fractional Security Director you have on day one is the same Director you keep. Continuity is built into the model.
Do you sell direct to our clients?
No. enhanced.io is channel-only by commercial commitment, not policy alone. We never approach your clients, never accept inbound from them, and never compete with you on a renewal.
What if our client wants to talk to you directly?
We support you in front of your client when you want it. Your named Fractional Security Director can join your calls while your team owns the relationship. This is optional and entirely up to you. We never go direct to your clients.
How many NFR slots are available?
Limited. We size the NFR cohort to maintain the SOC and Fractional Security Director service levels our paying partners expect. Talk to us for current availability.
Ready to deploy?
We cap NFR slots each quarter so every deployment is well supported.
Hannah Lloyd, our co-founder, walks you through scope, timing, and the architectural fit for your environment.


