Skip to main content

Help us improve the Digital Marketplace - send your feedback

CLARANET LIMITED

Managed EDR with SentinelOne

Claranet’s Managed EDR with SentinelOne delivers 24×7 detection, investigation, and response across Windows, macOS, and Linux endpoints. Our SOC triages alerts, contains threats, and restores devices (including ransomware rollback), with policy tuning, threat hunting and monthly reporting. Delivered as a managed service using SentinelOne’s cloud platform and Claranet Online.

Features

  • 24×7 SOC monitoring, triage, containment, and response.
  • AI‑driven prevention, ActiveEDR, and ransomware rollback.
  • Rapid isolation and remote remediation actions.
  • Threat hunting and continuous policy tuning.
  • Rapid rollback to known‑good state after attacks.
  • Claranet Online portal for visibility and communications.
  • Integration with SIEM/MDR where required.
  • Coverage for servers and endpoints.
  • Onboarding, baselining, exclusions, and tuning included.
  • Service credits linked to SLA adherence.

Benefits

  • Reduce breach likelihood and impact.
  • Contain threats in minutes, not hours.
  • Recover endpoints with automated rollback
  • 24×7 expert coverage without hiring.
  • Lower alert fatigue via expert filtering.
  • Meet governance and reporting expectations.
  • Scale protection per endpoint, as needed.
  • Align policies to your risk profile.
  • Integrate with wider detection and response.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Uk-bidteam@claranet.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 0 1 4 2 5 7 1 4 3 9 0 6 9 5

Contact

CLARANET LIMITED Claranet UK Bid Team
Telephone: 020 7685 8000
Email: Uk-bidteam@claranet.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
SentinelOne Singularity Endpoint Platform (agent and management console).
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Requires installing the SentinelOne agent and allowing outbound connectivity from protected assets to the SentinelOne management plane.
Conflicting legacy AV/EDR products must be removed or excluded.
Supported OS and kernel versions apply.
Kubernetes deployments use the vendor Helm chart and require cluster access.
Claranet’s service availability is independent from the vendor’s SaaS console availability.
Planned maintenance and change control follow our standard processes; emergency changes are communicated via Claranet Online and ticketing.
System requirements
  • Install SentinelOne agent on supported Windows, macOS, Linux.
  • Allow egress to SentinelOne management URLs and ports.
  • Remove conflicting antivirus/EDR or configure exclusions appropriately.
  • Local admin or remote management rights for deployment.
  • Supported hypervisor/VDI gold image preparation steps.
  • Kubernetes nodes deploy via official Helm chart.
  • Maintain supported OS/kernel versions per vendor matrix.
  • Internet access for signature, policy, and telemetry updates.
  • Endpoint resources meeting vendor minimum CPU/RAM.
  • Approved change window for agent rollout and reboots.

User support

Email or online ticketing support
Yes
Support response times
Our SOC operates 24×7×365. Incidents and requests are prioritised using the Response Matrix in the service description. Priority‑1 threats trigger immediate analyst engagement and customer notification; lower‑priority requests are handled within defined service levels during business hours or 24×7, depending on impact and category.
Communications, updates, and escalations are delivered via Claranet Online and ticketing, with documented hand‑offs to L2/L3 security engineers when required.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is included as part of the Managed EDR service. The UK SOC provides Level 1 monitoring, triage, and containment 24×7; Levels 2–3 analysis, investigation, and complex response are performed by senior security engineers.
Buyers receive onboarding, baselining, policy tuning, and continuous optimisation.
Operational communications and case management run through Claranet Online and email, with defined escalation paths.
Pricing for support is packaged within the Managed EDR service; where buyers need enhanced governance (for example, a dedicated Service Delivery Manager, bespoke reports, or extended service reviews), these can be added as options and are priced per the order form/CPQ.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We run a scene‑setting/kick‑off to confirm scope, access, and success criteria. Technical onboarding covers agent deployment (including VDI/gold‑image patterns), policy grouping, exclusions, and initial tuning. We align escalation and communications, then validate detection and response flows end‑to‑end with test events. Documentation includes runbooks, how‑to guides, and contact/escalation details published via Claranet Online. Optional enablement sessions cover console orientation and reporting.
For buyers also taking MDR, we coordinate log source onboarding, correlation rules, and joint playbooks. We complete a readiness review before entering steady‑state operations, with early‑life support checks to ensure KPIs are on track.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Buyers can export device inventories, detections, and incident data from the SentinelOne console or via API before termination.
Claranet can provide an offboarding checklist, time‑boxed access, and optional assisted exports. We supply guidance for agent removal and confirm endpoint coverage is decommissioned. If the buyer requires a consolidated data package (for example, CSV/JSON exports of detections over a defined period), we can produce this as a professional service.
After offboarding, residual data in our service systems is sanitised per our data handling and retention policies; vendor tenancy data follows the vendor’s platform processes.
End-of-contract process
Included: coordinated offboarding, disabling response automation, confirming agent removal guidance, and standard data export via console/API by the buyer.
Additional cost (if required): engineer‑assisted data exports, bespoke report packs, extended access periods, and on‑site support. If there are outstanding service credits, they are applied as per the Service Description/Agreement.
Any vendor subscription components are terminated or transferred subject to licensing terms. We provide a closure report summarising assets offboarded, actions taken, and any residual risks.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The onboarding and offboarding documentation for the EDR with SentinelOne service is provided through standard, widely accessible formats—primarily PDF and DOCX—ensuring customers can open, read, and interact with the content using common desktop productivity tools and browser‑based viewers.
Key onboarding materials, including the EDR - SOP Onboarding Process Group Model v2 and the SOP - EDR - Complete Onboarding Process, are distributed via SharePoint links, allowing customers and internal teams to access them securely through any modern web browser without requiring specialist software. These documents contain step‑by‑step instructions, templated forms, and clearly structured information, making them easy to navigate and compatible with assistive technologies such as screen readers and magnification tools.
Offboarding guidance is integrated into the broader service lifecycle documentation, where decommissioning processes are handled using standard forms, which are also provided in accessible, editable formats.
Supporting documentation is reinforced by communication through Teams channels and email, offering multiple accessible pathways for users to obtain, review, and submit required materials. Together, these mechanisms ensure onboarding and offboarding documentation is easy to access, read, and use across a range of user needs.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Claranet Online provides service‑level visibility, ticketing, updates, and documents. Buyers can view incidents, actions, and reports, and collaborate with SOC analysts via comments and notifications. Where appropriate, buyers may also access the SentinelOne management console for policy reviews, device status, and incident details. Role‑based access is applied to restrict functions and data per buyer policy. Integrations with email and optional APIs support notifications and automation.
Accessibility standards
None or don’t know
Description of accessibility
The EDR for SentinelOne service is accessed through two browser‑based platforms: the Claranet Online portal for ticketing, reporting, and incident interaction, and the SentinelOne Singularity Console for endpoint management.
As web interfaces, both portals can be used with standard browser and operating‑system assistive technologies, including screen readers, magnification, keyboard navigation, and high‑contrast modes. The service does not provide a mobile interface or dedicated accessibility features.
Users also benefit from 24×7 SOC support and incident notifications, offering additional accessible channels for receiving information.
Accessibility testing
Claranet Online and the SentinelOne console are modern web interfaces that support keyboard navigation and common browser accessibility features.
Internally, we validate readability, colour contrast, and keyboard operability during portal changes. However, we have not completed a formal WCAG conformance audit with external assistive technology users for this service.
On request, we will facilitate a buyer‑led accessibility review (for example, with screen readers) and provide remediation plans for any issues identified.
We can also arrange vendor‑supplied accessibility statements for the SentinelOne console.
API
Yes
What users can and can't do using the API
Using SentinelOne’s APIs, authorised users can retrieve alert and telemetry data, list and manage devices, trigger response actions (e.g., isolate, kill, remediate), and manage policy objects in scope.
Buyers can set up machine‑to‑machine access by generating API credentials in the console, then call endpoints for data export, enrichment, or automation workflows.
Changes to core platform configuration, tenant provisioning, licensing, and certain advanced settings remain restricted to console workflows and/or Claranet operational processes.
Where buyers request automation (for example, auto‑isolation on specific detections), Claranet will review, implement, and test changes via change control.
API rate limits and endpoint availability are governed by the vendor; some features may be subject to role‑based permissions and environment constraints.
API documentation
No
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Customisation begins during onboarding: we agree in‑scope assets, risk priorities, and response authorities. We baseline detections and create policy groups for different device classes, then tune exclusions and behavioural rules to minimise false positives.
Response automation (e.g., auto‑quarantine on high‑confidence detections) is configured per buyer appetite.
Notification recipients, severity thresholds, and escalation paths are defined in Claranet Online.
Ongoing changes are requested via ticket, reviewed by the SOC, and implemented under change control with a rollback plan.
Where buyers wish to self‑serve in the SentinelOne console, role‑based access can be granted for specific actions (e.g., viewing devices, approving actions) while high‑risk changes remain restricted to Claranet engineers.

Scaling

Independence of resources
We apply capacity management across underlying platforms and internal systems to ensure appropriate sizing and performance.
The vendor platform enforces tenant isolation and horizontal scaling; our SOC resource planning and on‑call structures protect response SLAs during demand peaks.
We review consumption and scale accordingly, engaging the buyer if utilisation trends require plan changes.

Analytics

Service usage metrics
Yes
Metrics types
Typical metrics include: endpoints onboarded/active, agent coverage by group, detections by severity/type, actions taken (containment, remediation, rollback), time to triage/contain/close, top talkers/assets, policy changes, ticket volumes/SLA performance, and recommendations delivered/accepted. Reports are available through Claranet Online and in service reviews, with options for export and schedule.
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Through the SentinelOne console (built‑in export) or the REST API, buyers can export device, detection, and incident datasets in common formats for archiving or import to other systems. Claranet can script recurring exports on request, subject to change control. Rate limits and available fields follow vendor capabilities.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
SentinelOne provides a highly available cloud platform with redundant infrastructure across multiple regions. The service is designed for continuous operation with automated failover and distributed telemetry ingestion. Claranet’s SOC operates 24/7 with continuous monitoring to maintain service integrity. Availability levels align with SentinelOne’s published SLAs, typically exceeding 99.9% uptime.
If availability falls below guaranteed levels, service credits may be provided according to the contractual terms between the customer and Claranet. Customers are notified of major platform outages, and Claranet coordinates communication, giving updates and expected resolution times. Claranet maintains operational resilience through redundant tooling, resilient connectivity and multiple monitoring points ensuring uninterrupted alert review, triage and containment actions. SLAs cover response times, incident communication and platform access.
Should outages occur, Claranet uses alternate processes—such as direct SIEM telemetry or backup tooling—to maintain visibility during console downtime. Recovery procedures ensure data continuity and synchronisation once the platform stabilises. These measures ensure customers retain reliable endpoint protection and timely operational support.
Approach to resilience
The SentinelOne cloud platform is built on distributed, redundant infrastructure with multiple availability zones, ensuring resilience against component or datacentre failures. Telemetry ingestion and processing are load‑balanced across independent clusters. Automated scaling ensures capacity is maintained during peak demand or large‑scale incident events. Data is stored redundantly with safeguards against corruption or loss.
Claranet SOC operations are designed for resilience through redundant SIEM pipelines, high‑availability monitoring tools, and mirrored alerting channels. Analysts operate across multiple sites to ensure continuity during local outages. Playbooks and automation run across distributed systems to maintain operational capability.
Further design details are available to buyers on request under NDA.
Outage reporting
Outages affecting the SentinelOne platform are communicated through their public status dashboard, email alerts and in‑platform notifications. Customers can subscribe to service updates for real‑time status changes. Claranet monitors these channels and coordinates communication to customers during incidents, providing context, impact analysis and expected recovery timelines.
Claranet SOC tooling outages are communicated directly through agreed communication channels such as email or ticketing systems. Customers are informed of any degradation to monitoring, response actions or reporting functions. Where possible, alternative monitoring methods are used to maintain visibility. Major incidents include periodic updates and a post‑incident summary.
Claranet may also provide API‑based status feeds or integration with customer monitoring tools where required.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted through role‑based access controls, MFA and least‑privilege policies. Administrative roles are tightly controlled and monitored. Support channels require authentication before account‑specific information is shared. All actions are logged, and sensitive operations require elevated permissions. Network access may be restricted by IP allowlisting or VPN where required. Claranet ensures support personnel access only what is necessary for SOC operations.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Claranet follows a comprehensive information security management system aligned with ISO/IEC 27001 and industry best practice. Policies govern access control, data protection, incident response, vulnerability management, change management and secure logging. A defined reporting structure ensures accountability, with security roles assigned across operational and management teams.
Compliance is enforced through regular audits, internal reviews and continuous monitoring. Staff undergo mandatory security training and role‑specific awareness programmes. Policies are reviewed annually or following significant changes to technology or threat landscapes. Enforcement includes technical controls, access reviews, segregation of duties and approval workflows. Deviations or breaches are escalated through the incident management process and overseen by senior leadership within Claranet’s security governance framework.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Claranet maintains an inventory of all service components, tracking them through their lifecycle. Changes are assessed for security impact, documented, tested and approved before deployment. High‑risk changes undergo additional review and may be scheduled during maintenance windows. Version control and configuration baselines ensure consistency across environments. Automated monitoring detects unauthorised changes. All changes are recorded in the change management system and reviewed regularly to ensure compliance with security policies.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Claranet continuously monitors threat intelligence, vendor advisories and security feeds to identify emerging vulnerabilities. Potential threats are assessed for relevance and impact to the service. Patches and updates are deployed according to severity, with critical updates prioritised for rapid implementation. Automated scanning and manual assessments validate patch status and identify exposures. SOC analysts monitor for signs of exploitation and escalate where necessary. Vulnerabilities in customer environments detected through service telemetry are reported with recommended remediation steps.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Claranet monitors systems for potential compromise through SIEM analytics, behavioural detection, and automated alerting. Indicators of compromise trigger investigation and containment actions. Suspicious activity is escalated to analysts for review. Response actions follow predefined playbooks to ensure rapid handling. Incidents are triaged and prioritised, with updates provided to affected customers. Claranet responds to high‑severity incidents within minutes, maintaining round‑the‑clock monitoring through the SOC.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Claranet maintains predefined processes for common incident types including malware infections, suspicious behaviour and unauthorised changes. Customers report incidents via support channels, which are logged, triaged and escalated as required. Incident handlers investigate, document findings and coordinate containment or recovery actions. Post‑incident reports summarise root cause, impact and recommended improvements. Major incidents receive coordinated communication and regular updates until closure.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
A time‑limited PoC includes deployment of SentinelOne agents, basic policy configuration, access to the console, and monitoring of detections. It excludes full SOC response, forensic investigation, custom integrations, or extended reporting. The PoC validates deployment, visibility and detection performance before committing to the full service.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Intertek
ISO/IEC 27001 accreditation date
Wednesday 22 May 2024
What the ISO/IEC 27001 doesn’t cover
This certification covers everything we do applicable to ISO/IEC 27001, no exclusions.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Intertek
ISO 9001 accreditation date
Wednesday 7 June 2023
What the ISO 9001 doesn’t cover
This certification covers everything we do applicable to ISO 9001, no exclusions.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Pen Test Partners
PCI DSS accreditation date
Friday 13 December 2024
What the PCI DSS doesn’t cover
N/a
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4377ebef-31ac-49ef-9943-13c7f3e3f9a5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
66b24695-ed3f-4797-bb2c-65b58932576d
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Uk-bidteam@claranet.com. Tell them what format you need. It will help if you say what assistive technology you use.