Service Commitments

Our SLAs, published. Numbers, not adjectives.

Our SLAs, published. Numbers, not adjectives.

Every response target, escalation window and reporting commitment enhanced.io works to, on one page. The same commitments you write into your own client contracts.

The commitments, up front


enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a SOC that operates 24x7x365. Critical escalations reach your nominated contacts by email within 30 minutes of triage confirmation, with telephone escalation at 15-minute intervals if no response arrives. Measured platform availability stands at 99.99%.


enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.


Every commitment on this page is the standard managed service, written into partner agreements. Not a marketing target.

The questions arrive in writing now.


A security questionnaire lands from a client's cyber insurer asking for documented response times. An auditor wants your incident process on paper, with evidence. A prospect's procurement team sends a due diligence pack with a row for every SLA. And AI tools now run the same research automatically, reporting back exactly what a provider has published and exactly what it has not.


Every one of those answers depends on the provider behind you. You need numbers you write into your own client contracts with confidence. Here are ours.

Alert response targets


Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.

SEVERITY EXAMPLE EVENTS INITIAL RESPONSE
Critical Active breach, ransomware, data exfiltration in progress 30 minutes
High Confirmed compromise, lateral movement detected 1 hour
Medium Suspicious activity requiring investigation 4 hours
Low Policy violations, reconnaissance activity 24 hours


Severity classification follows good industry practice, and you request reclassification where you disagree. Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, and no serious provider commits to a fixed resolution time.

Escalation: what happens and when


TRIGGER

Critical alert confirmed

ACTION


Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.

TRIGGER

No response within 15 minutes on a Critical escalation or developing threat

ACTION


We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.

TRIGGER

Problem affecting the service itself

ACTION


Notification within 4 hours of detection.

TRIGGER

General enquiries

ACTION


Initial response within 4 business hours, into a SOC mailbox monitored 24x7 where every email creates a ticket automatically.

The best-of-breed MSP


SentinelOne or CrowdStrike on endpoints. Fortinet, Sophos or Cisco at the edge. enhanced.io pulls detection and host data from your EDR and log and event data from your firewalls, correlates across both, and your Fractional Security Director tells you which incidents matter and why.

THE BEST-OF-BREED MSP
SOC
  • SentinelOne and CrowdStrike detections ingested natively

  • FortiGate, Sophos and Cisco firewall log and event data correlated

  • Two-way platform integrations support containment actions from the platform

  • One correlated view across EDR and network

The MSP with an existing SIEM or MDR


You have a SIEM collecting logs or an MDR watching endpoints, and gaps everywhere else. enhanced.io takes feeds from your existing tooling, adds the surfaces it does not see, and gives you one correlated view with a 24/7 SOC behind it.

THE MSP WITH
SOC
  • Existing SIEM and MDR feeds ingested and extended

  • Network traffic, cloud, identity and IoT/OT gaps filled

  • Most partners replace the endpoint-only monitoring service on their timeline

  • Your Fractional Security Director maps the transition route during onboarding

Replace or coexist? That is your decision. enhanced.io does not supply EDR or firewalls, so those stay yours by definition. Identity threat detection comes built into the platform, so a standalone identity security tool is often the first thing partners retire. The MDR or SOCaaS that only watched one surface is what most partners replace, on your timeline, not ours.

What we connect across the five surfaces

Endpoint

Native integrations with SentinelOne, Microsoft Defender for Endpoint, CrowdStrike, Sophos Central, Bitdefender, Trend Micro and more. We ingest detections and host telemetry, correlate them against every other surface, and trigger containment through two-way integrations.

Network

Firewall and network integrations across Fortinet, Sophos, Cisco, Palo Alto Networks, WatchGuard, SonicWall, Check Point, Meraki and pfSense, plus east-west traffic visibility through network sensors. This is the traffic no endpoint agent sees.

Identity

Entra ID, Active Directory, Okta, Duo, OneLogin and JumpCloud. Sign-in anomalies, MFA events and privilege changes get correlated with endpoint and cloud activity, because most modern attacks start with a credential, not malware.

Cloud and SaaS

Microsoft 365, AWS CloudTrail and GuardDuty, Azure, Google Cloud, Google Workspace, Salesforce and Box. Cloud alerts stop living in a console nobody checks.

Email

Telemetry from email security tools including Mimecast, Proofpoint and Barracuda feeds the same correlation engine, so a phishing event connects to the sign-in and the endpoint activity that followed it.

IoT and OT

Agentless visibility for the devices no agent will ever run on: building management, manufacturing, medical and connected devices, through network-level monitoring and integrations with tools like Ordr, Dragos and Claroty Medigate.

Your tooling

Your RMM is one of the most attacked platforms in the MSP world, so we monitor its front door and its back door. Confirmed incidents flow into your PSA as tickets, so response runs inside the workflow your team already uses.

400+ integrations, one platform


Every tool named on this page is a fraction of the list. Endpoint, network, cloud, identity, IoT/OT, and the PSA and RMM tools that run your business.

See all 400+ integrations

What it takes from you


Onboarding is scoped to what is being onboarded and typically runs 30 to 45 days. The biggest driver of speed is how fast you supply information about your client environments. You complete structured onboarding forms, your Fractional Security Director runs the plan, and we do the onboarding work. Agents and connectors deploy through your own tooling. Some environments need a firewall reconfiguration, and sites with no virtualization need a physical sensor.


Your engineers do not learn a new console to get value. The platform's agentic AI triages and closes false positives automatically, our analysts investigate what remains, and incidents arrive with the noise already removed.

Your Fractional Security Director

A multi-stack estate does not need another dashboard. It needs a person who understands the whole picture.


Every enhanced.io partnership runs through a named Fractional Security Director. On a multi-vendor estate, that means one person who knows which client runs which EDR, which sites have sensors, and which incidents deserve a phone call rather than a ticket. They translate what the SOC finds into what you tell your client and own the reporting rhythm: a weekly data pack, a monthly report, and a quarterly business review they present with you, built from evidence your clients hand to auditors. They sit in on client calls when you want them there and carry the security conversations your team would rather not carry alone.


The full reporting schedule and our published SLAs are at enhanced.io/service-commitments.


Not a support queue. A named person, on every partnership, from day one.

Proof


400+

Native integrations, live and listed at enhanced.io/integrations

Named in the Top 250 MSSPs for 2025


“We evaluated providers who wanted to sell us a platform and wish us luck. enhanced.io offered to become our security operations team.”

Val KingCEO,
Whitehat Virtual Technologies

“We evaluated providers who wanted to sell us a platform and wish us luck. enhanced.io offered to become our security operations team.”

Val KingCEO,
Whitehat Virtual Technologies

Frequently asked questions

Questions about multi-stack integration

What SLAs does enhanced.io commit to for alert triage and incident response?

enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a 24x7x365 SOC. Critical escalations reach your nominated contacts within 30 minutes of triage confirmation, and every commitment is written into the partner agreement.

What is the difference between response and resolution in enhanced.io's SLAs?

What availability does the enhanced.io platform deliver?

How does escalation work when enhanced.io finds a Critical threat?

How does enhanced.io balance AI automation with human analysts?

Does enhanced.io offer co-managed SOC options?

Does enhanced.io act automatically or wait for approval?

What reports does enhanced.io deliver and how often?

Where is enhanced.io data hosted?

What threat intelligence feeds does enhanced.io use?

Take this page into your next security questionnaire, audit or renewal. Then talk it through with Hannah, our co-founder, or test the commitments yourself on the NFR.