Every response target, escalation window and reporting commitment enhanced.io works to, on one page. The same commitments you write into your own client contracts.
enhanced.io commits to an initial response of 30 minutes for Critical alerts, 1 hour for High, 4 hours for Medium and 24 hours for Low, from a SOC that operates 24x7x365. Critical escalations reach your nominated contacts by email within 30 minutes of triage confirmation, with telephone escalation at 15-minute intervals if no response arrives. Measured platform availability stands at 99.99%.
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.
Every commitment on this page is the standard managed service, written into partner agreements. Not a marketing target.
A security questionnaire lands from a client's cyber insurer asking for documented response times. An auditor wants your incident process on paper, with evidence. A prospect's procurement team sends a due diligence pack with a row for every SLA. And AI tools now run the same research automatically, reporting back exactly what a provider has published and exactly what it has not.
Every one of those answers depends on the provider behind you. You need numbers you write into your own client contracts with confidence. Here are ours.
Initial response is the time within which a SOC analyst acknowledges the alert and starts triage.
| Severity | Example events | Initial response |
|---|---|---|
| Critical | Active breach, ransomware, data exfiltration in progress | 30 minutes |
| High | Confirmed compromise, lateral movement detected | 1 hour |
| Medium | Suspicious activity requiring investigation | 4 hours |
| Low | Policy violations, reconnaissance activity | 24 hours |
Severity classification follows good industry practice, and you request reclassification where you disagree. Response and resolution are different commitments. Resolution depends on the nature and root cause of the incident, and no serious provider commits to a fixed resolution time.
Critical alert confirmed
Escalation email to your nominated escalation group within 30 minutes of triage confirmation, with a case escalation report attached covering all alerts, the timeline, affected assets and analyst findings.
No response within 15 minutes on a Critical escalation or developing threat
We pick up the phone and work your agreed escalation chain at 15-minute intervals until we reach someone.
Problem affecting the service itself
Notification within 4 hours of detection.
General enquiries
Initial response within 4 business hours, into a SOC mailbox monitored 24x7 where every email creates a ticket automatically.
99.99%
Measured platform availability
Measured platform availability stands at 99.99%. Availability commitments are written into every partner agreement, measured per instance, with remedies defined in the service level schedule every partner signs. Standard exclusions apply for scheduled maintenance and factors outside the platform's control.
Threat intelligence is built into the platform, not sold as an add-on. The platform aggregates commercial, open-source and government threat intelligence feeds, alongside the platform's own emerging threat research. Feeds are consolidated and distributed in near real-time, and every event is enriched with that intelligence at ingestion, so detections carry threat context from the moment they land.
Partners with specific requirements bring their own feeds. The platform supports additional commercial and custom feeds through the STIX and TAXII standards, contained to your deployment.
The alert volume problem is real, and we solve it with both halves of the equation working together.
The platform's agentic AI triages and closes false positives automatically, so they never reach your inbox as individual alerts. Every closure is reviewed collectively with you in the weekly service review, backed by a running tuning log, so the automation stays accountable to a human conversation.
What remains after the noise goes is handled by analysts. Confirmed threats get human investigation, human judgment on escalation, and a human on the phone within 15-minute intervals when it matters. Your Fractional Security Director sits above both, translating what the SOC finds into what you tell your client.
AI does the toil. People make the decisions. You get the output of both without staffing either.
You choose the balance between autonomous action and approval with one of three response postures, set at onboarding and changeable by agreement.
We proceed directly to remediation on confirmed true positives. On Critical scenarios like ransomware or an active attacker, we act immediately and notify you in parallel.
We remediate confirmed true positives autonomously, and on Critical scenarios the analyst escalates to you before acting where judgment says so.
Nothing is remediated without your approval, even on confirmed true positives.
Endpoints you pre-approve for containment are contained within the 30-minute Critical response, no approval step. Endpoints you have not pre-approved get escalated within 30 minutes, and containment runs within 1 hour of your approval arriving.
Cases confirmed as benign or false positive
Closed within 24 hours of your confirmation.
Agreed tuning rules, suppressions and whitelist entries
Implemented within 48 hours of agreement.
Weekly service call
Video call covering active items, open actions, tuning review and escalations. Standard cadence for every live engagement.
Every report below comes with a person attached. Your Fractional Security Director owns the reporting rhythm, presents the numbers with you, and turns SOC output into the evidence your clients and their auditors ask for. Beyond the standard schedule, we build custom reports around what your clients or their auditors ask for.
Weekly data pack
Every Friday
Cases, escalations, tuning actions and open items, plus detections mapped to the kill chain and the highest-severity cases ranked.
Monthly incident report
By the 5th of the month
Full SOC activity by severity, escalations, false positives, tuning changes, SLA performance and threat trends.
Monthly executive summary
Monthly
Deployment, cases, alerts, assets and visibility, written for the person who does not read logs.
Post-incident report
Within 5 business days of closure
Timeline, root cause, indicators of compromise, containment actions and recommendations.
Quarterly business review
Quarterly
Trend analysis and strategic recommendations, presented by your Fractional Security Director.
Compliance reporting
Monthly and on demand
Mapped to NIST CSF, CIS Controls, NIS2, ISO 27001, HIPAA, PCI-DSS, GDPR, SOC 2, DFARS and CMMC, with detections mapped to MITRE ATT&CK. Your Fractional Security Director walks your team through the evidence as standard.
Real-time dashboards run continuously alongside all scheduled reporting.
EU-hosted instances run from Frankfurt. North American hosting is US-based. Partners in other regions are served from these locations today, and instances in additional regions are available on request at additional cost. Data residency is agreed at onboarding and written into the partner agreement.
enhanced.io is channel-only. We sell through MSP partners and never direct to end clients. These commitments exist so you design your own downstream SLAs on top of them with confidence. Your Fractional Security Director maps each commitment to what you promise your clients.
Take this page into your next security questionnaire, audit or renewal. Then talk it through with Hannah, our co-founder, or test the commitments yourself on the NFR.