SLA
SOC SLA and Response Times
Buyers deserve clear targets before they subscribe. These are the response commitments by edition. Cybersecurity reduces risk; it does not guarantee zero incidents.
Protection is best-effort in business hours. MDR targets an 8 business-hour response on qualified alerts. MPR targets 4 business hours, with 24×7 handling for criticals. Managed SOC targets a 1-hour response on critical incidents with full 24×7 analyst coverage.
Comparison at a glance
| Target | Protection | MDR | MPR | Managed SOC |
|---|---|---|---|---|
| Monitoring | Endpoint protection and basic alerts | 24/7 SIEM monitoring and alerting | 24/7 monitoring plus threat hunting | 24/7 analyst-led monitoring and response |
| Human support | Business hours | Business hours | 24×7 for criticals | 24×7 |
| Response SLA | Best effort | 8 business hours | 4 business hours | 1 hour (critical) |
| Active containment | No | Guided next steps | Remote IR assistance | Yes (edition scope) |
What “response” means
Response time is the target window from when a qualified alert is raised in our monitoring stack to when an analyst (or automated playbook under analyst oversight) acknowledges and begins investigation or customer notification, whichever your edition includes. It is not a promise that every attack is blocked, or that full remediation finishes inside the same window.
Severity levels we use
Critical: active ransomware behaviour, confirmed compromise, or widespread account takeover. High: likely malicious activity needing same-day attention. Medium: suspicious activity needing investigation. Low / informational: tuning, vulnerability context, or awareness items. Only Critical and High normally consume the published SLA clocks; Medium and Low are handled in priority order during support hours for your edition.
Business hours vs 24/7
MDR and above keep automated monitoring and alerting around the clock. Human investigation and customer callbacks follow each edition’s support model. MPR escalates criticals 24×7. Managed SOC keeps analyst-led response 24×7 with the tightest critical SLA.
Honest limits
Missed coverage from revoked access, outdated contact lists, or out-of-scope assets is outside the SLA. Service credits, if any, are handled case by case under your order terms, not as an unlimited warranty.
Common questions
Are SLAs the same as uptime guarantees?
No. These targets cover analyst response to qualified security alerts. Platform maintenance windows are scheduled to minimise monitoring gaps.
Which edition should I pick for overnight ransomware risk?
MDR and above monitor 24/7. For overnight human response and containment, choose MPR (criticals) or Managed SOC (1-hour critical target).
Where do I see this at checkout?
Each plan card on Pricing lists monitoring, support hours, and SLA. This page defines severity and what the clock measures.
Ready to scope your environment?
Tell us endpoint count and cloud platforms, we recommend a tier within 24 hours.