The offering and operating model

01 · ONE PARTNER PLATFORM, THREE SERVICE LAYERS

Three service layers on one platform.

Layer 1 — Managed preventive signal

High-context alerts from controlled targets, Contact Point and selected non-public signal, SOC enrichment.

Maps to — canary, trap or deception budget; proactive monitoring; a differentiated MDR tier.

Layer 2 — Controlled deep engagement

Live Host engagement, session and artifact analysis, post-access behavior observed separately from production, specialist escalation.

Maps to — advanced threat detection; incident readiness; threat hunting; critical-exposure missions.

Layer 3 — First-party adversary intelligence

Structured Findings, briefing material for the recurring threat briefings your team delivers, detection and hunting content, sector or customer-specific analysis where relevance supports it.

Maps to — CTI enrichment; executive briefings; premium MDR differentiation; regulated-customer services.

These are layers of one product, not three separate deployments. Distribution or resale rights are governed by engagement terms — the page does not imply unrestricted commercialization of raw evidence.
02 · WHAT THE PARTNER CAN OFFER NOW

Concrete offers available today.

Offer A — Early-Signal Service

Selected Contact Points and applicable targets, alerts and structured context, partner-owned L1/L2 handling, OHIIHO platform support.

Best for — clients already asking for canaries or deception; a low-friction first engagement; SOC enrichment.

Offer B — Engagement & Evidence Service

Deeper Live Host interaction where appropriate, session and artifact review, HIIH Findings, OHIIHO L3 support.

Best for — mature SOC/CTI clients; edge-exposure missions; critical-infrastructure and regulated accounts.

Offer C — Intelligence Briefing Material

Briefing material your team delivers: periodic synthesis of observed activity, relevance qualification, operational and executive views, Research-backed context where appropriate.

Best for — recurring executive engagement; CTI retainers; sector or regional service lines.

These are managed-service offers, not a public price list or marketplace.

03 · OPERATING MODEL

You retain the customer and service relationship. OHIIHO operates the specialized environment.

OHIIHOMSSP / PartnerEnd customer
designs, hosts and governs the HIIH Surfaceowns the commercial and service relationshipapproves the exposure and mission scope
operates engagement targets, control and evidence collectionintegrates outputs into SOC workflowsprovides relevant environment and risk context
handles platform support and L3 escalationruns L1/L2 monitoring, triage and responseconsumes Findings and approves actions
provides Research and detection-content support where includeddelivers reporting, briefings and customer successacts through its own governance process
maintains product and deployment truthpackages the managed serviceaccepts engagement-specific data and access terms

OHIIHO does not operate the partner’s SOC and does not promise to replace the partner’s client-facing service. Your team never has to build or run a honeypot engineering practice — OHIIHO operates the specialized environment behind your service.

04 · WHAT THE PARTNER SOC RECEIVES

The same first-party material, flowing into the workflow you already run.

HIIH Findingstructured object
→
MCP · APIpull path
→
Partner L1/L2triage · response
→
Clientescalation · reporting

OHIIHO provides L3 support behind the partner when a case requires it.

The partner SOC receives a preventive alert or Finding summary, Surface and target context, observed facts and assessment, confidence and relevance, related session or artifact links where available, a suggested analyst action, and briefing material or detection content by engagement.

Where delivery stands
Pull-based delivery, one Finding identity
A Finding keeps its identity across the MCP and API pull paths, which the partner retrieves on its own schedule; STIX 2.1 over TAXII 2.1 is available by engagement. The Access Finding family is live and inspectable in the Console. A first deployment is evaluated through deployment, collection, workflow and controlled validation — not through a promise that a rare advanced actor will arrive during that period.