ThreatDown's security operations centre
On Elite and Ultimate, ThreatDown's own analysts monitor your endpoint telemetry 24/7/365. They triage detections, hunt for threats across the estate, and take containment action — isolating an endpoint from the network, killing a malicious process, quarantining a file — either automatically under agreed playbooks or after escalating for your approval, depending on how the service is configured.
It is a pooled SOC rather than named analysts assigned to your account, and ThreatDown does not publish a formal committed response time. We would rather tell you that than let you assume an SLA that does not exist.