Service Commitments

Our SLAs, published. Numbers, not adjectives.

Every response target, escalation window and reporting commitment enhanced.io works to, on one page. The same commitments you write into your own client contracts.

The commitments, up front

enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a SOC that operates 24x7x365. Critical escalations reach your nominated contacts by email within 30 minutes of triage confirmation, with telephone escalation at 15-minute intervals if no response arrives. Measured platform availability stands at 99.99%.

enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.

Every commitment on this page is the standard managed service, written into partner agreements. Not a marketing target.

The questions arrive in writing now.

A security questionnaire lands from a client's cyber insurer asking for documented response times. An auditor wants your incident process on paper, with evidence. A prospect's procurement team sends a due diligence pack with a row for every SLA. And AI tools now run the same research automatically, reporting back exactly what a provider has published and exactly what it has not.

Every one of those answers depends on the provider behind you. You need numbers you write into your own client contracts with confidence. Here are ours.

Alert response targets

Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.

SeverityExample eventsInitial response
CriticalActive breach, ransomware, data exfiltration in progress30 minutes
HighConfirmed compromise, lateral movement detected1 hour
MediumSuspicious activity requiring investigation4 hours
LowPolicy violations, reconnaissance activity24 hours

Severity classification follows good industry practice, and you request reclassification where you disagree. Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, and no serious provider commits to a fixed resolution time.

Escalation: what happens and when

Trigger

Critical alert confirmed

Action

Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.

Trigger

No response within 15 minutes on a Critical escalation or developing threat

Action

We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.

Trigger

Problem affecting the service itself

Action

Notification within 4 hours of detection.

Trigger

General enquiries

Action

Initial response within 4 business hours, into a SOC mailbox monitored 24x7 where every email creates a ticket automatically.

99.99%

Measured platform availability

Platform availability

Measured platform availability stands at 99.99%. Availability commitments are written into every partner agreement, measured per instance, with remedies defined in the service level schedule every partner signs. Standard exclusions apply for scheduled maintenance and factors outside the platform's control.

Threat intelligence: what feeds the detections

Threat intelligence is built into the platform, not sold as an add-on. The platform aggregates commercial, open-source and government threat intelligence feeds, alongside the platform's own emerging threat research. Feeds are consolidated and distributed in near real-time, and every event is enriched with that intelligence at ingestion, so detections carry threat context from the moment they land.

AlienVault OTXDHSEmerging Threats ProPhishTankAbuse.chOpenPhish

Partners with specific requirements bring their own feeds. The platform supports additional commercial and custom feeds through the STIX and TAXII standards, contained to your deployment.

AI filters the noise. Humans make the calls.

The alert volume problem is real, and we solve it with both halves of the equation working together.

The platform's agentic AI triages and closes false positives automatically, so they never reach your inbox as individual alerts. Every closure is reviewed collectively with you in the weekly service review, backed by a running tuning log, so the automation stays accountable to a human conversation.

What remains after the noise goes is handled by analysts. Confirmed threats get human investigation, human judgment on escalation, and a human on the phone within 15-minute intervals when it matters. Your Fractional Security Director sits above both, translating what the SOC finds into what you tell your client.

AI does the toil. People make the decisions. You get the output of both without staffing either.

You decide how much authority we get

You choose the balance between autonomous action and approval with one of three response postures, set at onboarding and changeable by agreement.

Active

We proceed directly to remediation on confirmed true positives. On Critical scenarios like ransomware or an active attacker, we act immediately and notify you in parallel.

Measured

We remediate confirmed true positives autonomously, and on Critical scenarios the analyst escalates to you before acting where judgment says so.

Cautious

Nothing is remediated without your approval, even on confirmed true positives.

Endpoints you pre-approve for containment are contained within the 30-minute Critical response, no approval step. Endpoints you have not pre-approved get escalated within 30 minutes, and containment runs within 1 hour of your approval arriving.

Operational commitments

Cases confirmed as benign or false positive

Closed within 24 hours of your confirmation.

Agreed tuning rules, suppressions and whitelist entries

Implemented within 48 hours of agreement.

Weekly service call

Video call covering active items, open actions, tuning review and escalations. Standard cadence for every live engagement.

Reporting: what lands in your inbox, and who walks you through it

Every report below comes with a person attached. Your Fractional Security Director owns the reporting rhythm, presents the numbers with you, and turns SOC output into the evidence your clients and their auditors ask for. Beyond the standard schedule, we build custom reports around what your clients or their auditors ask for.

Weekly data pack

Every Friday

Cases, escalations, tuning actions and open items, plus detections mapped to the kill chain and the highest-severity cases ranked.

Monthly incident report

By the 5th of the month

Full SOC activity by severity, escalations, false positives, tuning changes, SLA performance and threat trends.

Monthly executive summary

Monthly

Deployment, cases, alerts, assets and visibility, written for the person who does not read logs.

Post-incident report

Within 5 business days of closure

Timeline, root cause, indicators of compromise, containment actions and recommendations.

Quarterly business review

Quarterly

Trend analysis and strategic recommendations, presented by your Fractional Security Director.

Compliance reporting

Monthly and on demand

Mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, HIPAA, PCI-DSS, GDPR, SOC 2, DFARS and CMMC, with detections mapped to MITRE ATT&CK. Your Fractional Security Director walks your team through the evidence as standard.

Real-time dashboards run continuously alongside all scheduled reporting.

Data residency

EU-hosted instances run from Frankfurt. North American hosting is US-based. Partners in other regions are served from these locations today, and instances in additional regions are available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.

EUFrankfurt
North AmericaUS-based
Other regionsAvailable on request

Channel model

enhanced.io is channel-only. We sell through MSP partners and never direct to end clients. These commitments exist so you design your own downstream SLAs on top of them with confidence. Your Fractional Security Director maps each commitment to what you promise your clients.

Frequently asked questions

Questions about our SLAs

Take this page into your next security questionnaire, audit or renewal. Then talk it through with Hannah, our co-founder, or test the commitments yourself on the NFR.