Managed EDR with SentinelOne
Claranet’s Managed EDR with SentinelOne delivers 24×7 detection, investigation, and response across Windows, macOS, and Linux endpoints. Our SOC triages alerts, contains threats, and restores devices (including ransomware rollback), with policy tuning, threat hunting and monthly reporting. Delivered as a managed service using SentinelOne’s cloud platform and Claranet Online.
Features
- 24×7 SOC monitoring, triage, containment, and response.
- AI‑driven prevention, ActiveEDR, and ransomware rollback.
- Rapid isolation and remote remediation actions.
- Threat hunting and continuous policy tuning.
- Rapid rollback to known‑good state after attacks.
- Claranet Online portal for visibility and communications.
- Integration with SIEM/MDR where required.
- Coverage for servers and endpoints.
- Onboarding, baselining, exclusions, and tuning included.
- Service credits linked to SLA adherence.
Benefits
- Reduce breach likelihood and impact.
- Contain threats in minutes, not hours.
- Recover endpoints with automated rollback
- 24×7 expert coverage without hiring.
- Lower alert fatigue via expert filtering.
- Meet governance and reporting expectations.
- Scale protection per endpoint, as needed.
- Align policies to your risk profile.
- Integrate with wider detection and response.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 1 4 2 5 7 1 4 3 9 0 6 9 5
Contact
CLARANET LIMITED
Claranet UK Bid Team
Telephone: 020 7685 8000
Email: Uk-bidteam@claranet.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- SentinelOne Singularity Endpoint Platform (agent and management console).
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
-
Requires installing the SentinelOne agent and allowing outbound connectivity from protected assets to the SentinelOne management plane.
Conflicting legacy AV/EDR products must be removed or excluded.
Supported OS and kernel versions apply.
Kubernetes deployments use the vendor Helm chart and require cluster access.
Claranet’s service availability is independent from the vendor’s SaaS console availability.
Planned maintenance and change control follow our standard processes; emergency changes are communicated via Claranet Online and ticketing. - System requirements
-
- Install SentinelOne agent on supported Windows, macOS, Linux.
- Allow egress to SentinelOne management URLs and ports.
- Remove conflicting antivirus/EDR or configure exclusions appropriately.
- Local admin or remote management rights for deployment.
- Supported hypervisor/VDI gold image preparation steps.
- Kubernetes nodes deploy via official Helm chart.
- Maintain supported OS/kernel versions per vendor matrix.
- Internet access for signature, policy, and telemetry updates.
- Endpoint resources meeting vendor minimum CPU/RAM.
- Approved change window for agent rollout and reboots.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our SOC operates 24×7×365. Incidents and requests are prioritised using the Response Matrix in the service description. Priority‑1 threats trigger immediate analyst engagement and customer notification; lower‑priority requests are handled within defined service levels during business hours or 24×7, depending on impact and category.
Communications, updates, and escalations are delivered via Claranet Online and ticketing, with documented hand‑offs to L2/L3 security engineers when required. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is included as part of the Managed EDR service. The UK SOC provides Level 1 monitoring, triage, and containment 24×7; Levels 2–3 analysis, investigation, and complex response are performed by senior security engineers.
Buyers receive onboarding, baselining, policy tuning, and continuous optimisation.
Operational communications and case management run through Claranet Online and email, with defined escalation paths.
Pricing for support is packaged within the Managed EDR service; where buyers need enhanced governance (for example, a dedicated Service Delivery Manager, bespoke reports, or extended service reviews), these can be added as options and are priced per the order form/CPQ. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We run a scene‑setting/kick‑off to confirm scope, access, and success criteria. Technical onboarding covers agent deployment (including VDI/gold‑image patterns), policy grouping, exclusions, and initial tuning. We align escalation and communications, then validate detection and response flows end‑to‑end with test events. Documentation includes runbooks, how‑to guides, and contact/escalation details published via Claranet Online. Optional enablement sessions cover console orientation and reporting.
For buyers also taking MDR, we coordinate log source onboarding, correlation rules, and joint playbooks. We complete a readiness review before entering steady‑state operations, with early‑life support checks to ensure KPIs are on track. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Buyers can export device inventories, detections, and incident data from the SentinelOne console or via API before termination.
Claranet can provide an offboarding checklist, time‑boxed access, and optional assisted exports. We supply guidance for agent removal and confirm endpoint coverage is decommissioned. If the buyer requires a consolidated data package (for example, CSV/JSON exports of detections over a defined period), we can produce this as a professional service.
After offboarding, residual data in our service systems is sanitised per our data handling and retention policies; vendor tenancy data follows the vendor’s platform processes. - End-of-contract process
-
Included: coordinated offboarding, disabling response automation, confirming agent removal guidance, and standard data export via console/API by the buyer.
Additional cost (if required): engineer‑assisted data exports, bespoke report packs, extended access periods, and on‑site support. If there are outstanding service credits, they are applied as per the Service Description/Agreement.
Any vendor subscription components are terminated or transferred subject to licensing terms. We provide a closure report summarising assets offboarded, actions taken, and any residual risks. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
The onboarding and offboarding documentation for the EDR with SentinelOne service is provided through standard, widely accessible formats—primarily PDF and DOCX—ensuring customers can open, read, and interact with the content using common desktop productivity tools and browser‑based viewers.
Key onboarding materials, including the EDR - SOP Onboarding Process Group Model v2 and the SOP - EDR - Complete Onboarding Process, are distributed via SharePoint links, allowing customers and internal teams to access them securely through any modern web browser without requiring specialist software. These documents contain step‑by‑step instructions, templated forms, and clearly structured information, making them easy to navigate and compatible with assistive technologies such as screen readers and magnification tools.
Offboarding guidance is integrated into the broader service lifecycle documentation, where decommissioning processes are handled using standard forms, which are also provided in accessible, editable formats.
Supporting documentation is reinforced by communication through Teams channels and email, offering multiple accessible pathways for users to obtain, review, and submit required materials. Together, these mechanisms ensure onboarding and offboarding documentation is easy to access, read, and use across a range of user needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Claranet Online provides service‑level visibility, ticketing, updates, and documents. Buyers can view incidents, actions, and reports, and collaborate with SOC analysts via comments and notifications. Where appropriate, buyers may also access the SentinelOne management console for policy reviews, device status, and incident details. Role‑based access is applied to restrict functions and data per buyer policy. Integrations with email and optional APIs support notifications and automation.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
The EDR for SentinelOne service is accessed through two browser‑based platforms: the Claranet Online portal for ticketing, reporting, and incident interaction, and the SentinelOne Singularity Console for endpoint management.
As web interfaces, both portals can be used with standard browser and operating‑system assistive technologies, including screen readers, magnification, keyboard navigation, and high‑contrast modes. The service does not provide a mobile interface or dedicated accessibility features.
Users also benefit from 24×7 SOC support and incident notifications, offering additional accessible channels for receiving information. - Accessibility testing
-
Claranet Online and the SentinelOne console are modern web interfaces that support keyboard navigation and common browser accessibility features.
Internally, we validate readability, colour contrast, and keyboard operability during portal changes. However, we have not completed a formal WCAG conformance audit with external assistive technology users for this service.
On request, we will facilitate a buyer‑led accessibility review (for example, with screen readers) and provide remediation plans for any issues identified.
We can also arrange vendor‑supplied accessibility statements for the SentinelOne console. - API
- Yes
- What users can and can't do using the API
-
Using SentinelOne’s APIs, authorised users can retrieve alert and telemetry data, list and manage devices, trigger response actions (e.g., isolate, kill, remediate), and manage policy objects in scope.
Buyers can set up machine‑to‑machine access by generating API credentials in the console, then call endpoints for data export, enrichment, or automation workflows.
Changes to core platform configuration, tenant provisioning, licensing, and certain advanced settings remain restricted to console workflows and/or Claranet operational processes.
Where buyers request automation (for example, auto‑isolation on specific detections), Claranet will review, implement, and test changes via change control.
API rate limits and endpoint availability are governed by the vendor; some features may be subject to role‑based permissions and environment constraints. - API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Customisation begins during onboarding: we agree in‑scope assets, risk priorities, and response authorities. We baseline detections and create policy groups for different device classes, then tune exclusions and behavioural rules to minimise false positives.
Response automation (e.g., auto‑quarantine on high‑confidence detections) is configured per buyer appetite.
Notification recipients, severity thresholds, and escalation paths are defined in Claranet Online.
Ongoing changes are requested via ticket, reviewed by the SOC, and implemented under change control with a rollback plan.
Where buyers wish to self‑serve in the SentinelOne console, role‑based access can be granted for specific actions (e.g., viewing devices, approving actions) while high‑risk changes remain restricted to Claranet engineers.
Scaling
- Independence of resources
-
We apply capacity management across underlying platforms and internal systems to ensure appropriate sizing and performance.
The vendor platform enforces tenant isolation and horizontal scaling; our SOC resource planning and on‑call structures protect response SLAs during demand peaks.
We review consumption and scale accordingly, engaging the buyer if utilisation trends require plan changes.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Typical metrics include: endpoints onboarded/active, agent coverage by group, detections by severity/type, actions taken (containment, remediation, rollback), time to triage/contain/close, top talkers/assets, policy changes, ticket volumes/SLA performance, and recommendations delivered/accepted. Reports are available through Claranet Online and in service reviews, with options for export and schedule.
- Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Through the SentinelOne console (built‑in export) or the REST API, buyers can export device, detection, and incident datasets in common formats for archiving or import to other systems. Claranet can script recurring exports on request, subject to change control. Rate limits and available fields follow vendor capabilities.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
SentinelOne provides a highly available cloud platform with redundant infrastructure across multiple regions. The service is designed for continuous operation with automated failover and distributed telemetry ingestion. Claranet’s SOC operates 24/7 with continuous monitoring to maintain service integrity. Availability levels align with SentinelOne’s published SLAs, typically exceeding 99.9% uptime.
If availability falls below guaranteed levels, service credits may be provided according to the contractual terms between the customer and Claranet. Customers are notified of major platform outages, and Claranet coordinates communication, giving updates and expected resolution times. Claranet maintains operational resilience through redundant tooling, resilient connectivity and multiple monitoring points ensuring uninterrupted alert review, triage and containment actions. SLAs cover response times, incident communication and platform access.
Should outages occur, Claranet uses alternate processes—such as direct SIEM telemetry or backup tooling—to maintain visibility during console downtime. Recovery procedures ensure data continuity and synchronisation once the platform stabilises. These measures ensure customers retain reliable endpoint protection and timely operational support. - Approach to resilience
-
The SentinelOne cloud platform is built on distributed, redundant infrastructure with multiple availability zones, ensuring resilience against component or datacentre failures. Telemetry ingestion and processing are load‑balanced across independent clusters. Automated scaling ensures capacity is maintained during peak demand or large‑scale incident events. Data is stored redundantly with safeguards against corruption or loss.
Claranet SOC operations are designed for resilience through redundant SIEM pipelines, high‑availability monitoring tools, and mirrored alerting channels. Analysts operate across multiple sites to ensure continuity during local outages. Playbooks and automation run across distributed systems to maintain operational capability.
Further design details are available to buyers on request under NDA. - Outage reporting
-
Outages affecting the SentinelOne platform are communicated through their public status dashboard, email alerts and in‑platform notifications. Customers can subscribe to service updates for real‑time status changes. Claranet monitors these channels and coordinates communication to customers during incidents, providing context, impact analysis and expected recovery timelines.
Claranet SOC tooling outages are communicated directly through agreed communication channels such as email or ticketing systems. Customers are informed of any degradation to monitoring, response actions or reporting functions. Where possible, alternative monitoring methods are used to maintain visibility. Major incidents include periodic updates and a post‑incident summary.
Claranet may also provide API‑based status feeds or integration with customer monitoring tools where required.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through role‑based access controls, MFA and least‑privilege policies. Administrative roles are tightly controlled and monitored. Support channels require authentication before account‑specific information is shared. All actions are logged, and sensitive operations require elevated permissions. Network access may be restricted by IP allowlisting or VPN where required. Claranet ensures support personnel access only what is necessary for SOC operations.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Claranet follows a comprehensive information security management system aligned with ISO/IEC 27001 and industry best practice. Policies govern access control, data protection, incident response, vulnerability management, change management and secure logging. A defined reporting structure ensures accountability, with security roles assigned across operational and management teams.
Compliance is enforced through regular audits, internal reviews and continuous monitoring. Staff undergo mandatory security training and role‑specific awareness programmes. Policies are reviewed annually or following significant changes to technology or threat landscapes. Enforcement includes technical controls, access reviews, segregation of duties and approval workflows. Deviations or breaches are escalated through the incident management process and overseen by senior leadership within Claranet’s security governance framework. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Claranet maintains an inventory of all service components, tracking them through their lifecycle. Changes are assessed for security impact, documented, tested and approved before deployment. High‑risk changes undergo additional review and may be scheduled during maintenance windows. Version control and configuration baselines ensure consistency across environments. Automated monitoring detects unauthorised changes. All changes are recorded in the change management system and reviewed regularly to ensure compliance with security policies.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Claranet continuously monitors threat intelligence, vendor advisories and security feeds to identify emerging vulnerabilities. Potential threats are assessed for relevance and impact to the service. Patches and updates are deployed according to severity, with critical updates prioritised for rapid implementation. Automated scanning and manual assessments validate patch status and identify exposures. SOC analysts monitor for signs of exploitation and escalate where necessary. Vulnerabilities in customer environments detected through service telemetry are reported with recommended remediation steps.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Claranet monitors systems for potential compromise through SIEM analytics, behavioural detection, and automated alerting. Indicators of compromise trigger investigation and containment actions. Suspicious activity is escalated to analysts for review. Response actions follow predefined playbooks to ensure rapid handling. Incidents are triaged and prioritised, with updates provided to affected customers. Claranet responds to high‑severity incidents within minutes, maintaining round‑the‑clock monitoring through the SOC.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Claranet maintains predefined processes for common incident types including malware infections, suspicious behaviour and unauthorised changes. Customers report incidents via support channels, which are logged, triaged and escalated as required. Incident handlers investigate, document findings and coordinate containment or recovery actions. Post‑incident reports summarise root cause, impact and recommended improvements. Major incidents receive coordinated communication and regular updates until closure.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A time‑limited PoC includes deployment of SentinelOne agents, basic policy configuration, access to the console, and monitoring of detections. It excludes full SOC response, forensic investigation, custom integrations, or extended reporting. The PoC validates deployment, visibility and detection performance before committing to the full service.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Intertek
- ISO/IEC 27001 accreditation date
- Wednesday 22 May 2024
- What the ISO/IEC 27001 doesn’t cover
- This certification covers everything we do applicable to ISO/IEC 27001, no exclusions.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Intertek
- ISO 9001 accreditation date
- Wednesday 7 June 2023
- What the ISO 9001 doesn’t cover
- This certification covers everything we do applicable to ISO 9001, no exclusions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Pen Test Partners
- PCI DSS accreditation date
- Friday 13 December 2024
- What the PCI DSS doesn’t cover
- N/a
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 4377ebef-31ac-49ef-9943-13c7f3e3f9a5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 66b24695-ed3f-4797-bb2c-65b58932576d
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-