Service Commitments
Every response target, escalation window and reporting commitment enhanced.io works to, on one page. Written into partner agreements, so you can quote them in your own client contracts and in the questionnaires your clients send you.

The commitments, up front
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Every commitment on this page is the standard managed service, written into partner agreements.
Alert response targets
Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.
| SEVERITY | EXAMPLE EVENTS | INITIAL RESPONSE |
|---|---|---|
| Critical | Active breach, ransomware, data exfiltration in progress | 30 minutes |
| High | Confirmed compromise, lateral movement detected | 1 hour |
| Medium | Suspicious activity requiring investigation | 4 hours |
| Low | Policy violations, reconnaissance activity | 24 hours |
Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, so we commit to response times and report resolution case by case.
Threat intelligence: what feeds the detections
Threat intelligence is built into the platform. It aggregates commercial, open-source and government feeds alongside the platform's own emerging threat research. Feeds are consolidated and distributed in near real-time, and every event is enriched with that intelligence at ingestion, so detections carry threat context from the moment they land.
Partners with specific requirements bring their own feeds. The platform supports additional commercial and custom feeds through the STIX and TAXII standards, contained to your deployment.
Threat intelligence: what feeds the detections
AUTOMATED
The platform's agentic AI triages and closes false positives automatically, so they never reach your inbox as individual alerts. Every closure is reviewed with you in the weekly service review, backed by a running tuning log.
HUMAN-LED
What remains goes to analysts. They investigate, they decide what gets escalated, and they work your escalation chain by phone at 15-minute intervals. Your Fractional Security Director sits above both and translates what the SOC finds into what you tell your client.
You decide how much authority we get
You choose the balance between autonomous action and approval with one of three response postures, set at onboarding and changeable by agreement.
Operational commitments
Cases confirmed as benign or false positive
Closed within 24 hours of your confirmation.
Agreed tuning rules, suppressions and whitelist entries
Implemented within 48 hours of agreement.
Weekly service call
Video call covering active items, open actions, tuning review and escalations. Standard cadence for every live engagement.
Reporting: what lands in your inbox, and who walks you through it
Your Fractional Security Director owns the reporting rhythm, presents the numbers with you, and turns SOC output into the evidence your clients and their auditors ask for. Beyond the standard schedule, we build custom reports around what your clients or their auditors ask for.
Weekly data pack
Every Friday
Cases, escalations, tuning actions and open items, plus detections mapped to the kill chain and the highest-severity cases ranked.
Monthly incident report
By the 5th of the month
Full SOC activity by severity, escalations, false positives, tuning changes, SLA performance and threat trends.
Monthly executive summary
Monthly
Deployment, cases, alerts, assets and visibility, written for a non-technical audience.
Post-incident report
Within 5 business days of closure
Timeline, root cause, indicators of compromise, containment actions and recommendations.
Quarterly business review
Quarterly
Trend analysis and strategic recommendations, presented by your Fractional Security Director.
Compliance reporting
Monthly and on demand
Mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, HIPAA, PCI-DSS, GDPR, SOC 2, DFARS and CMMC, with detections mapped to MITRE ATT&CK. Your Fractional Security Director walks your team through the evidence as standard.
Real-time dashboards run continuously alongside all scheduled reporting.
EU-hosted instances run from Frankfurt. North American hosting is US-based. Partners in other regions are served from these locations today, and instances in additional regions are available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.
enhanced.io is channel-only. We sell through MSP partners and never direct to end clients. These commitments exist so you design your own downstream SLAs on top of them with confidence. Your Fractional Security Director maps each commitment to what you promise your clients.
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Every surface is ingested as independent telemetry and correlated together, not bolted on as an afterthought.
400+ native integrations across the tools MSPs already run.
5 surfaces covered as independent telemetry: endpoint, network, cloud, identity and IoT/OT.
Cross-surface correlation into a single prioritized incident, not 5 separate alerts.
No endpoint rip and replace. We ingest from the EDR your clients already run rather than displacing it.
When an MSP puts a SOC in front of its clients, that SOC becomes part of the MSP’s own supply chain. These are the facts a partner, a client or an auditor asks for, in one place.
Operating since 2019, exclusively in security operations for MSPs.
Privately held and independently owned. Headquartered in Edinburgh, United Kingdom.
Data is processed in one of two regions. North American data is processed in the United States. UK, European, Australian, New Zealand and rest of world data is processed in the European Union. Specific regional or contractual data requirements can be reviewed on request.
The Open XDR platform underpinning the service is certified to ISO 27001 and SOC 2. The full certification list and named certificates are provided in the partner diligence pack under NDA.
Channel-only. We contract with the MSP, never with your clients directly, so we cannot compete with you for the account.
Where your data is stored and processed, in full: see Data residency above.
Frequently asked questions
Questions about service commitments
What SLAs does enhanced.io commit to for alert triage and incident response?
enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a 24x7x365 SOC. Critical escalations reach your nominated contacts within 30 minutes of triage confirmation, and every commitment is written into the partner agreement.
What is the difference between response and resolution in enhanced.io's SLAs?
The response target is the time within which a SOC analyst acknowledges an alert and starts triage. Resolution depends on the nature, complexity and root cause of the incident, so it is managed case by case rather than committed as a fixed number. Publishing an honest response commitment beats publishing a resolution number nobody keeps.
What availability does the enhanced.io platform deliver?
Measured platform availability stands at 99.99%. Availability commitments and remedies are written into every partner agreement, measured per instance.
How does escalation work when enhanced.io finds a Critical threat?
An escalation email reaches your nominated escalation group within 30 minutes of triage confirmation, with a full case report attached. If no response arrives within 15 minutes on a Critical escalation, the SOC initiates telephone escalation through your agreed chain at 15-minute intervals.
How does enhanced.io balance AI automation with human analysts?
The platform's agentic AI triages and closes false positives automatically, and human analysts investigate everything that remains. Automated closures are reviewed collectively in the weekly service review, confirmed threats get human judgment on escalation and response, and a named Fractional Security Director translates the findings for your team. You also set the remediation authority through one of three response postures.
Does enhanced.io offer co-managed SOC options?
Yes. Partners with in-house security staff work directly with our SOC, with escalation paths agreed during onboarding. Partners without in-house security get the full service, with the Fractional Security Director as the bridge into their team.
Does enhanced.io act automatically or wait for approval?
You decide, through one of three response postures set at onboarding. Active gives the SOC direct remediation authority on confirmed true positives, Measured adds analyst-discretion escalation on Critical scenarios, and Cautious requires your approval before any remediation. Pre-approved endpoints are contained within the 30-minute Critical response window.
What reports does enhanced.io deliver and how often?
A weekly data pack every Friday, a monthly incident report by the 5th of the following month, a monthly executive summary, a post-incident report within 5 business days of incident closure, and a quarterly business review presented by your Fractional Security Director. Compliance reporting runs monthly and on demand, custom reports are built around what your clients or their auditors ask for, and real-time dashboards run continuously.
Where is enhanced.io data hosted?
EU-hosted instances run from Frankfurt and North American hosting is US-based. Partners in other regions are served from these locations today, with instances in additional regions available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.
What threat intelligence feeds does enhanced.io use?
Threat intelligence is built into the platform at no additional cost, aggregating commercial, open-source and government feeds including AlienVault OTX, DHS, Emerging Threats Pro, PhishTank, Abuse.ch and OpenPhish, plus the platform's own emerging threat research. Every event is enriched with this intelligence at ingestion, and partners bring additional feeds through the STIX and TAXII standards where required.
How many integrations does enhanced.io support, and across which surfaces?
400+ native integrations across endpoint, network, cloud, identity and IoT/OT, ingested as independent telemetry and correlated across all 5 surfaces into a single prioritized incident.
How long has enhanced.io been operating, and who owns the company?
enhanced.io has been operating since 2019 and is privately held and independently owned. The company is headquartered in Edinburgh, United Kingdom. Data is processed in one of two regions: North American data in the United States, and UK, European, Australian, New Zealand and rest of world data in the European Union.
These are the commitments we work to. Talk them through with Hannah, our co-founder, or test them yourself on the NFR