Service Commitments

Our SLAs, in full.

Our SLAs, in full.

Every response target, escalation window and reporting commitment enhanced.io works to, on one page. Written into partner agreements, so you can quote them in your own client contracts and in the questionnaires your clients send you.

The commitments, up front


Critical
30 minutes
High
1 hour
Medium
4 hours
Low
24 hours
SOC operating hours
24x7x365
Measured platform availability
99.99%


enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Every commitment on this page is the standard managed service, written into partner agreements.

Alert response targets


Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.

SEVERITY EXAMPLE EVENTS INITIAL RESPONSE
Critical Active breach, ransomware, data exfiltration in progress 30 minutes
High Confirmed compromise, lateral movement detected 1 hour
Medium Suspicious activity requiring investigation 4 hours
Low Policy violations, reconnaissance activity 24 hours


Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, so we commit to response times and report resolution case by case.

Escalation: what happens and when


Escalation: what happens and when

1

TRIGGER

Critical alert confirmed

ACTION

Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.

2

TRIGGER

No response within 15 minutes on a Critical escalation or developing threat

ACTION

We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.

3

TRIGGER

Problem affecting the service itself

ACTION

Notification within 4 hours of detection.

1

TRIGGER

Critical alert confirmed

ACTION

Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.

2

TRIGGER

No response within 15 minutes on a Critical escalation or developing threat

ACTION

We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.

3

TRIGGER

Problem affecting the service itself

ACTION

Notification within 4 hours of detection.

99.99%

Measured platform availability

99.99%
Measured platform availability

Platform availability


Measured platform availability stands at 99.99%. Availability commitments are written into every partner agreement, measured per instance, with remedies defined in the service level schedule every partner signs. Standard exclusions apply for scheduled maintenance and factors outside the platform's control.

99.99%
Measured platform availability

Platform availability


Measured platform availability stands at 99.99%. Availability commitments are written into every partner agreement, measured per instance, with remedies defined in the service level schedule every partner signs. Standard exclusions apply for scheduled maintenance and factors outside the platform's control.

Threat intelligence: what feeds the detections


Threat intelligence is built into the platform. It aggregates commercial, open-source and government feeds alongside the platform's own emerging threat research. Feeds are consolidated and distributed in near real-time, and every event is enriched with that intelligence at ingestion, so detections carry threat context from the moment they land.


Partners with specific requirements bring their own feeds. The platform supports additional commercial and custom feeds through the STIX and TAXII standards, contained to your deployment.

AlienVault OTX

AlienVault OTX

Emerging Threats Pro

Emerging Threats Pro

DHS

DHS

PhishTank

PhishTank

Abuse.ch

Abuse.ch

OpenPhish

OpenPhish

Threat intelligence: what feeds the detections


AUTOMATED


The platform's agentic AI triages and closes false positives automatically, so they never reach your inbox as individual alerts. Every closure is reviewed with you in the weekly service review, backed by a running tuning log.

HUMAN-LED


What remains goes to analysts. They investigate, they decide what gets escalated, and they work your escalation chain by phone at 15-minute intervals. Your Fractional Security Director sits above both and translates what the SOC finds into what you tell your client.

You decide how much authority we get


You choose the balance between autonomous action and approval with one of three response postures, set at onboarding and changeable by agreement.

Active
We proceed directly to remediation on confirmed true positives. On Critical scenarios like ransomware or an active attacker, we act immediately and notify you in parallel.
Measured
We remediate confirmed true positives autonomously, and on Critical scenarios the analyst escalates to you before acting where judgment says so.
Cautious
Nothing is remediated without your approval, even on confirmed true positives.


Endpoints you pre-approve for containment are contained within the 30-minute Critical response, no approval step. Endpoints you have not pre-approved get escalated within 30 minutes, and containment runs within 1 hour of your approval arriving.

Endpoints you pre-approve for containment are contained within the 30-minute Critical response, no approval step. Endpoints you have not pre-approved get escalated within 30 minutes, and containment runs within 1 hour of your approval arriving.

Operational commitments

Cases confirmed as benign or false positive

Closed within 24 hours of your confirmation.

Agreed tuning rules, suppressions and whitelist entries

Implemented within 48 hours of agreement.

Weekly service call

Video call covering active items, open actions, tuning review and escalations. Standard cadence for every live engagement.

Reporting: what lands in your inbox, and who walks you through it


Your Fractional Security Director owns the reporting rhythm, presents the numbers with you, and turns SOC output into the evidence your clients and their auditors ask for. Beyond the standard schedule, we build custom reports around what your clients or their auditors ask for.

Weekly data pack

Every Friday

Cases, escalations, tuning actions and open items, plus detections mapped to the kill chain and the highest-severity cases ranked.

Monthly incident report

By the 5th of the month

Full SOC activity by severity, escalations, false positives, tuning changes, SLA performance and threat trends.

Monthly executive summary

Monthly

Deployment, cases, alerts, assets and visibility, written for a non-technical audience.

Post-incident report

Within 5 business days of closure

Timeline, root cause, indicators of compromise, containment actions and recommendations.

Quarterly business review

Quarterly

Trend analysis and strategic recommendations, presented by your Fractional Security Director.

Compliance reporting

Monthly and on demand

Mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, HIPAA, PCI-DSS, GDPR, SOC 2, DFARS and CMMC, with detections mapped to MITRE ATT&CK. Your Fractional Security Director walks your team through the evidence as standard.

Real-time dashboards run continuously alongside all scheduled reporting.


Data residency


Data residency

EU-hosted instances run from Frankfurt. North American hosting is US-based. Partners in other regions are served from these locations today, and instances in additional regions are available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.

EU

Frankfurt

EU

Frankfurt

North America

US-based

North America

US-based

Other regions

Available on request

Other regions

Available on request

Channel model


Channel model

enhanced.io is channel-only. We sell through MSP partners and never direct to end clients. These commitments exist so you design your own downstream SLAs on top of them with confidence. Your Fractional Security Director maps each commitment to what you promise your clients.

Coverage, by the numbers 


Channel model

enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Every surface is ingested as independent telemetry and correlated together, not bolted on as an afterthought. 


  • 400+ native integrations across the tools MSPs already run. 

  • 5 surfaces covered as independent telemetry: endpoint, network, cloud, identity and IoT/OT. 

  • Cross-surface correlation into a single prioritized incident, not 5 separate alerts. 

  • No endpoint rip and replace. We ingest from the EDR your clients already run rather than displacing it.

     

See the full integration list

The company behind the SOC 


Channel model

When an MSP puts a SOC in front of its clients, that SOC becomes part of the MSP’s own supply chain. These are the facts a partner, a client or an auditor asks for, in one place. 


  • Operating since 2019, exclusively in security operations for MSPs. 

  • Privately held and independently owned. Headquartered in Edinburgh, United Kingdom. 

  • Data is processed in one of two regions. North American data is processed in the United States. UK, European, Australian, New Zealand and rest of world data is processed in the European Union. Specific regional or contractual data requirements can be reviewed on request. 

  • The Open XDR platform underpinning the service is certified to ISO 27001 and SOC 2. The full certification list and named certificates are provided in the partner diligence pack under NDA. 

  • Channel-only. We contract with the MSP, never with your clients directly, so we cannot compete with you for the account. 


Where your data is stored and processed, in full: see Data residency above. 

Frequently asked questions

Questions about service commitments

What SLAs does enhanced.io commit to for alert triage and incident response?

enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a 24x7x365 SOC. Critical escalations reach your nominated contacts within 30 minutes of triage confirmation, and every commitment is written into the partner agreement.

What is the difference between response and resolution in enhanced.io's SLAs?

The response target is the time within which a SOC analyst acknowledges an alert and starts triage. Resolution depends on the nature, complexity and root cause of the incident, so it is managed case by case rather than committed as a fixed number. Publishing an honest response commitment beats publishing a resolution number nobody keeps.

What availability does the enhanced.io platform deliver?

Measured platform availability stands at 99.99%. Availability commitments and remedies are written into every partner agreement, measured per instance.

How does escalation work when enhanced.io finds a Critical threat?

An escalation email reaches your nominated escalation group within 30 minutes of triage confirmation, with a full case report attached. If no response arrives within 15 minutes on a Critical escalation, the SOC initiates telephone escalation through your agreed chain at 15-minute intervals.

How does enhanced.io balance AI automation with human analysts?

The platform's agentic AI triages and closes false positives automatically, and human analysts investigate everything that remains. Automated closures are reviewed collectively in the weekly service review, confirmed threats get human judgment on escalation and response, and a named Fractional Security Director translates the findings for your team. You also set the remediation authority through one of three response postures.

Does enhanced.io offer co-managed SOC options?

Yes. Partners with in-house security staff work directly with our SOC, with escalation paths agreed during onboarding. Partners without in-house security get the full service, with the Fractional Security Director as the bridge into their team.

Does enhanced.io act automatically or wait for approval?

You decide, through one of three response postures set at onboarding. Active gives the SOC direct remediation authority on confirmed true positives, Measured adds analyst-discretion escalation on Critical scenarios, and Cautious requires your approval before any remediation. Pre-approved endpoints are contained within the 30-minute Critical response window.

What reports does enhanced.io deliver and how often?

A weekly data pack every Friday, a monthly incident report by the 5th of the following month, a monthly executive summary, a post-incident report within 5 business days of incident closure, and a quarterly business review presented by your Fractional Security Director. Compliance reporting runs monthly and on demand, custom reports are built around what your clients or their auditors ask for, and real-time dashboards run continuously.

Where is enhanced.io data hosted?

EU-hosted instances run from Frankfurt and North American hosting is US-based. Partners in other regions are served from these locations today, with instances in additional regions available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.

What threat intelligence feeds does enhanced.io use?

Threat intelligence is built into the platform at no additional cost, aggregating commercial, open-source and government feeds including AlienVault OTX, DHS, Emerging Threats Pro, PhishTank, Abuse.ch and OpenPhish, plus the platform's own emerging threat research. Every event is enriched with this intelligence at ingestion, and partners bring additional feeds through the STIX and TAXII standards where required.

How many integrations does enhanced.io support, and across which surfaces?

400+ native integrations across endpoint, network, cloud, identity and IoT/OT, ingested as independent telemetry and correlated across all 5 surfaces into a single prioritized incident.

How long has enhanced.io been operating, and who owns the company?

enhanced.io has been operating since 2019 and is privately held and independently owned. The company is headquartered in Edinburgh, United Kingdom. Data is processed in one of two regions: North American data in the United States, and UK, European, Australian, New Zealand and rest of world data in the European Union.

These are the commitments we work to. Talk them through with Hannah, our co-founder, or test them yourself on the NFR