Think Smart Inc.

SOC-Monitored MDR Addendum

Terms for the SOC-monitored managed detection and response service.

Last updated: December 9, 2025

← All agreements
Draft — pending review. This document is a working draft adapted for Think Smart Group Inc. and should be confirmed by legal counsel before launch.

This SOC-Monitored MDR Addendum (“Addendum”) supplements and is incorporated into the Master Service Agreement (“MSA”) between Think Smart Group, Inc. (“TSI”) and the Customer. This Addendum applies only if SOC-Monitored Managed Detection & Response (MDR) is purchased on an Order Form. TSI provides MDR using SentinelOne Endpoint Detection & Response (EDR) and a third-party Security Operations Center (SOC). Details of subprocessors are provided in TSI’s Subprocessor List, which may be updated from time to time in accordance with the Data Processing Addendum (DPA).

1. Scope & Components

- EDR agent deployment on in-scope servers/endpoints; behavioral detection and prevention.

- 24×7 SOC monitoring, alert triage, and escalation.

- Runbook-driven containment actions (e.g., network isolation/quarantine) where technically available.

- Incident ticketing and notifications to Customer/ISV technical contacts.

2. Customer/ISV Responsibilities

- Maintain supported OS versions; apply critical patches in a timely manner.

- Ensure EDR agents remain installed, running, and updated; do not disable protections.

- Provide 24×7 reachable on-call contact for P1 escalations.

- Approve in advance any actions that may impact availability (where feasible).

3. Exclusions & Limits

- MDR is not a guarantee against compromise; it is a detection/response service.

- Coverage is limited to endpoints/servers with a healthy agent and connectivity to the SOC.

- Forensics, eDiscovery, and broad incident remediation are out of scope unless purchased via SOW.

4. Incident Handling SLOs (Operational)

  • P1 (active compromise/high confidence): triage start within 60 minutes of SOC alert; notify Customer/ISV promptly.
  • P2 (suspicious activity/medium confidence): triage start within 4 hours.
  • P3 (low confidence/policy): next business day.

SLOs are operational targets only and not tied to SLA credits.

5. Data & Privacy

EDR/SOC may collect telemetry (process, network, file, memory indicators) and transfer it to subprocessor infrastructure for analysis. Processing is governed by the DPA; confidentiality obligations apply.

6. Liability

MDR is subject to the MSA’s limitation of liability. Credits under the SLA do not apply to MDR performance.

7. Changes to this Addendum

TSI may update this Addendum from time to time and will provide notice of material changes. Materially adverse changes will not take effect during a then-current Order Form term; they apply upon renewal, unless earlier required by law or to address security, legal, or system‑integrity risks. Updates will not modify commercial pricing or payment terms.

This Addendum is accepted and agreed to by Customer as of the Effective Date of the Master Service Agreement into which it is incorporated.

Questions?

Prefer to ask a person?

For questions about this document or about Think Smart, reach out and we will help.