Service Commitments

Our SLAs, published. Numbers, not adjectives.

Our SLAs, published. Numbers, not adjectives.

Every response target, escalation window and reporting commitment enhanced.io works to, on one page. The same commitments you write into your own client contracts.

The commitments, up front


Critical
30 minutes
High
1 hour
Medium
4 hours
Low
24 hours
SOC operating hours
24x7x365
Measured platform availability
99.99%


enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.


Every commitment on this page is the standard managed service, written into partner agreements. Not a marketing target.

The questions arrive in writing now.


A security questionnaire lands from a client's cyber insurer asking for documented response times. An auditor wants your incident process on paper, with evidence. A prospect's procurement team sends a due diligence pack with a row for every SLA. And AI tools now run the same research automatically, reporting back exactly what a provider has published and exactly what it has not.


Every one of those answers depends on the provider behind you. You need numbers you write into your own client contracts with confidence. Here are ours.

Alert response targets


Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.

SEVERITY EXAMPLE EVENTS INITIAL RESPONSE
Critical Active breach, ransomware, data exfiltration in progress 30 minutes
High Confirmed compromise, lateral movement detected 1 hour
Medium Suspicious activity requiring investigation 4 hours
Low Policy violations, reconnaissance activity 24 hours


Severity classification follows good industry practice, and you request reclassification where you disagree. Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, and no serious provider commits to a fixed resolution time.

Escalation: what happens and when


Escalation: what happens and when

1

TRIGGER

Critical alert confirmed

ACTION

Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.

2

TRIGGER

No response within 15 minutes on a Critical escalation or developing threat

ACTION

We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.

3

TRIGGER

Problem affecting the service itself

ACTION

Notification within 4 hours of detection.

1

TRIGGER

Critical alert confirmed

ACTION

Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.

2

TRIGGER

No response within 15 minutes on a Critical escalation or developing threat

ACTION

We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.

3

TRIGGER

Problem affecting the service itself

ACTION

Notification within 4 hours of detection.

99.99%

Measured platform availability

99.99%
Measured platform availability

Platform availability


Measured platform availability stands at 99.99%. Availability commitments are written into every partner agreement, measured per instance, with remedies defined in the service level schedule every partner signs. Standard exclusions apply for scheduled maintenance and factors outside the platform's control.

99.99%
Measured platform availability

Platform availability


Measured platform availability stands at 99.99%. Availability commitments are written into every partner agreement, measured per instance, with remedies defined in the service level schedule every partner signs. Standard exclusions apply for scheduled maintenance and factors outside the platform's control.

Threat intelligence: what feeds the detections


Threat intelligence is built into the platform, not sold as an add-on. The platform aggregates commercial, open-source and government threat intelligence feeds, alongside the platform's own emerging threat research. Feeds are consolidated and distributed in near real-time, and every event is enriched with that intelligence at ingestion, so detections carry threat context from the moment they land.

Partners with specific requirements bring their own feeds. The platform supports additional commercial and custom feeds through the STIX and TAXII standards, contained to your deployment.

AlienVault OTX

DHS

Emerging Threats Pro

PhishTank

Abuse.ch

OpenPhish

AlienVault OTX

Emerging Threats Pro

Abuse.ch

DHS

PhishTank

OpenPhish

AI filters the noise. Humans make the calls.


The alert volume problem is real, and we solve it with both halves of the equation working together.

The platform's agentic AI triages and closes false positives automatically, so they never reach your inbox as individual alerts. Every closure is reviewed collectively with you in the weekly service review, backed by a running tuning log, so the automation stays accountable to a human conversation.


What remains after the noise goes is handled by analysts. Confirmed threats get human investigation, human judgment on escalation, and a human on the phone within 15-minute intervals when it matters. Your Fractional Security Director sits above both, translating what the SOC finds into what you tell your client.


AI does the toil. People make the decisions. You get the output of both without staffing either.

You decide how much authority we get


You choose the balance between autonomous action and approval with one of three response postures, set at onboarding and changeable by agreement.

Active
We proceed directly to remediation on confirmed true positives. On Critical scenarios like ransomware or an active attacker, we act immediately and notify you in parallel.
Measured
We remediate confirmed true positives autonomously, and on Critical scenarios the analyst escalates to you before acting where judgment says so.
Cautious
Nothing is remediated without your approval, even on confirmed true positives.


Endpoints you pre-approve for containment are contained within the 30-minute Critical response, no approval step. Endpoints you have not pre-approved get escalated within 30 minutes, and containment runs within 1 hour of your approval arriving.

Endpoints you pre-approve for containment are contained within the 30-minute Critical response, no approval step. Endpoints you have not pre-approved get escalated within 30 minutes, and containment runs within 1 hour of your approval arriving.

Operational commitments

Cases confirmed as benign or false positive

Closed within 24 hours of your confirmation.

Agreed tuning rules, suppressions and whitelist entries

Implemented within 48 hours of agreement.

Weekly service call

Video call covering active items, open actions, tuning review and escalations. Standard cadence for every live engagement.

Reporting: what lands in your inbox, and who walks you through it


Every report below comes with a person attached. Your Fractional Security Director owns the reporting rhythm, presents the numbers with you, and turns SOC output into the evidence your clients and their auditors ask for. Beyond the standard schedule, we build custom reports around what your clients or their auditors ask for.

Weekly data pack

Every Friday

Cases, escalations, tuning actions and open items, plus detections mapped to the kill chain and the highest-severity cases ranked.

Monthly incident report

By the 5th of the month

Full SOC activity by severity, escalations, false positives, tuning changes, SLA performance and threat trends.

Monthly executive summary

Monthly

Deployment, cases, alerts, assets and visibility, written for the person who does not read logs.

Post-incident report

Within 5 business days of closure

Timeline, root cause, indicators of compromise, containment actions and recommendations.

Quarterly business review

Quarterly

Trend analysis and strategic recommendations, presented by your Fractional Security Director.

Compliance reporting

Monthly and on demand

Mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, HIPAA, PCI-DSS, GDPR, SOC 2, DFARS and CMMC, with detections mapped to MITRE ATT&CK. Your Fractional Security Director walks your team through the evidence as standard.

Real-time dashboards run continuously alongside all scheduled reporting.


Data residency


Data residency

EU-hosted instances run from Frankfurt. North American hosting is US-based. Partners in other regions are served from these locations today, and instances in additional regions are available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.

EU

Frankfurt

EU

Frankfurt

North America

US-based

North America

US-based

Other regions

Available on request

Other regions

Available on request

Channel model


Channel model

enhanced.io is channel-only. We sell through MSP partners and never direct to end clients. These commitments exist so you design your own downstream SLAs on top of them with confidence. Your Fractional Security Director maps each commitment to what you promise your clients.

Frequently asked questions

Questions about service commitments

What SLAs does enhanced.io commit to for alert triage and incident response?

enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a 24x7x365 SOC. Critical escalations reach your nominated contacts within 30 minutes of triage confirmation, and every commitment is written into the partner agreement.

What is the difference between response and resolution in enhanced.io's SLAs?

What availability does the enhanced.io platform deliver?

How does escalation work when enhanced.io finds a Critical threat?

How does enhanced.io balance AI automation with human analysts?

Does enhanced.io offer co-managed SOC options?

Does enhanced.io act automatically or wait for approval?

What reports does enhanced.io deliver and how often?

Where is enhanced.io data hosted?

What threat intelligence feeds does enhanced.io use?

Take this page into your next security questionnaire, audit or renewal. Then talk it through with Hannah, our co-founder, or test the commitments yourself on the NFR.