Service Commitments
Every response target, escalation window and reporting commitment enhanced.io works to, on one page. The same commitments you write into your own client contracts.

The commitments, up front
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.
Every commitment on this page is the standard managed service, written into partner agreements. Not a marketing target.
The questions arrive in writing now.
A security questionnaire lands from a client's cyber insurer asking for documented response times. An auditor wants your incident process on paper, with evidence. A prospect's procurement team sends a due diligence pack with a row for every SLA. And AI tools now run the same research automatically, reporting back exactly what a provider has published and exactly what it has not.
Every one of those answers depends on the provider behind you. You need numbers you write into your own client contracts with confidence. Here are ours.
Alert response targets
Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.
| SEVERITY | EXAMPLE EVENTS | INITIAL RESPONSE |
|---|---|---|
| Critical | Active breach, ransomware, data exfiltration in progress | 30 minutes |
| High | Confirmed compromise, lateral movement detected | 1 hour |
| Medium | Suspicious activity requiring investigation | 4 hours |
| Low | Policy violations, reconnaissance activity | 24 hours |
Severity classification follows good industry practice, and you request reclassification where you disagree. Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, and no serious provider commits to a fixed resolution time.
Threat intelligence: what feeds the detections
Threat intelligence is built into the platform, not sold as an add-on. The platform aggregates commercial, open-source and government threat intelligence feeds, alongside the platform's own emerging threat research. Feeds are consolidated and distributed in near real-time, and every event is enriched with that intelligence at ingestion, so detections carry threat context from the moment they land.
Partners with specific requirements bring their own feeds. The platform supports additional commercial and custom feeds through the STIX and TAXII standards, contained to your deployment.
AI filters the noise. Humans make the calls.
The alert volume problem is real, and we solve it with both halves of the equation working together.
The platform's agentic AI triages and closes false positives automatically, so they never reach your inbox as individual alerts. Every closure is reviewed collectively with you in the weekly service review, backed by a running tuning log, so the automation stays accountable to a human conversation.
What remains after the noise goes is handled by analysts. Confirmed threats get human investigation, human judgment on escalation, and a human on the phone within 15-minute intervals when it matters. Your Fractional Security Director sits above both, translating what the SOC finds into what you tell your client.
AI does the toil. People make the decisions. You get the output of both without staffing either.
You decide how much authority we get
You choose the balance between autonomous action and approval with one of three response postures, set at onboarding and changeable by agreement.
Operational commitments
Cases confirmed as benign or false positive
Closed within 24 hours of your confirmation.
Agreed tuning rules, suppressions and whitelist entries
Implemented within 48 hours of agreement.
Weekly service call
Video call covering active items, open actions, tuning review and escalations. Standard cadence for every live engagement.
Reporting: what lands in your inbox, and who walks you through it
Every report below comes with a person attached. Your Fractional Security Director owns the reporting rhythm, presents the numbers with you, and turns SOC output into the evidence your clients and their auditors ask for. Beyond the standard schedule, we build custom reports around what your clients or their auditors ask for.
Weekly data pack
Every Friday
Cases, escalations, tuning actions and open items, plus detections mapped to the kill chain and the highest-severity cases ranked.
Monthly incident report
By the 5th of the month
Full SOC activity by severity, escalations, false positives, tuning changes, SLA performance and threat trends.
Monthly executive summary
Monthly
Deployment, cases, alerts, assets and visibility, written for the person who does not read logs.
Post-incident report
Within 5 business days of closure
Timeline, root cause, indicators of compromise, containment actions and recommendations.
Quarterly business review
Quarterly
Trend analysis and strategic recommendations, presented by your Fractional Security Director.
Compliance reporting
Monthly and on demand
Mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, HIPAA, PCI-DSS, GDPR, SOC 2, DFARS and CMMC, with detections mapped to MITRE ATT&CK. Your Fractional Security Director walks your team through the evidence as standard.
Real-time dashboards run continuously alongside all scheduled reporting.
EU-hosted instances run from Frankfurt. North American hosting is US-based. Partners in other regions are served from these locations today, and instances in additional regions are available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.
enhanced.io is channel-only. We sell through MSP partners and never direct to end clients. These commitments exist so you design your own downstream SLAs on top of them with confidence. Your Fractional Security Director maps each commitment to what you promise your clients.
Frequently asked questions
Questions about service commitments
What SLAs does enhanced.io commit to for alert triage and incident response?
enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a 24x7x365 SOC. Critical escalations reach your nominated contacts within 30 minutes of triage confirmation, and every commitment is written into the partner agreement.
What is the difference between response and resolution in enhanced.io's SLAs?
What availability does the enhanced.io platform deliver?
How does escalation work when enhanced.io finds a Critical threat?
How does enhanced.io balance AI automation with human analysts?
Does enhanced.io offer co-managed SOC options?
Does enhanced.io act automatically or wait for approval?
What reports does enhanced.io deliver and how often?
Where is enhanced.io data hosted?
What threat intelligence feeds does enhanced.io use?
Take this page into your next security questionnaire, audit or renewal. Then talk it through with Hannah, our co-founder, or test the commitments yourself on the NFR.