Know when your site breaks, and why.
We watch the websites you are responsible for. Uptime, certificates, traffic, attacks and file changes, and we explain every alert in plain words. From the outside with nothing installed, and much deeper with one PHP file that runs on ordinary shared hosting.
- GET/checkout5023.0 s
- GET/products/kurta-blue5023.0 s
- POST/wp-login.phpBlocked4039 ms
- GET/cart200184 ms
- GET/200142 ms
- GET/products?page=2200231 ms
Why it’s marked down
3 of 3 checks got 502 Bad Gateway after 3.0 s
DNS in 4 ms, certificate valid for 58 days. The network is fine.
The agent is still reporting: CPU 31%, PHP workers 5 of 5 busy.
Likely: PHP-FPM ran out of workers after a plugin update. Restart it, then raise pm.max_children.
The console, replaying an example incident. Example data.
No card. We set it up on your own sites with you, you see your own data, then you choose a plan.
No trial and no price list. Your own sites first.
A trial on a sample site tells you very little, and an account nobody set up is worse than none because it looks like cover. So we set it up on the sites you actually run, with you, and you decide what it is worth once you have seen your own data.
- 1
Book a demo
Tell us which sites, where they are hosted and what prompted it. Two minutes, no card.
- 2
We set it up with you
On a call, on your real sites. Checks, the agent where it earns its place, alerts to the right people.
- 3
You see your own data
Uptime, traffic, attacks, file changes and DPDP findings from your sites, not a demo account.
- 4
Then you choose a plan
Sized to what you now know you need. The price is agreed then, and nothing is charged before.
If your site is built on Growthzi
The outside in checks are already on and they stay free. Uptime, certificates, DNS, headers and blocklists, from the minute you published. A plan is only for going deeper.
If somebody else built it
Which is most of the sites we watch. WordPress, Laravel, a static build, shared cPanel hosting with no SSH. Start with a demo on your real sites rather than a signup form.
Everything it watches, including the gaps
All 25 modules, as the console has them. Where something needs the agent on your server, it says so. A feature list with no boundaries on it is a feature list nobody believes.
Monitoring
What we check from the outside, with no agent.
- Uptime and response time
- Checks as often as every 30 seconds, with DNS, connect, TLS handshake and time to first byte measured separately. Failures collapse into one incident with a start, an end, a timeline and a plain English reason.
- TLS certificates
- Expiry, chain completeness, hostname match and grade. You hear about an expiry weeks ahead, not from a visitor.
- DNS monitoring
- Records as they were, with the date each one moved. The most common site is down that is nobody’s server.
- Security headers
- Each missing or weak header graded, with the exact line for Apache, Nginx or your CDN that fixes it.
- Blocklist monitoring
- Spam and malware lists, Safe Browsing included, so you learn your domain was listed before your email starts bouncing.
- Origin exposure
- Works out which CDN you are behind and whether your origin still answers directly. The misconfiguration that quietly makes a CDN decorative.
Security
Detection and blocking.
- Attack detectionNeeds agent
- A request firewall inside the site: SQL injection, XSS, traversal, scanners and brute force, each with the attacker’s own request and an explanation of what was being tried.
- IP blockingNeeds agent
- Block an address or range straight from the evidence, and let the firewall refuse attacks rather than only record them. Enforced on your server.
- File integrity and malwareNeeds agent
- A hash of every file, compared on a schedule. Changed, added and deleted files with excerpts, and malware signatures on anything executable. A web shell in uploads/ shows the matched line.
- Privacy readiness for DPDP
- Trackers before consent, a named grievance officer, retention statements, forms collecting personal data, cookie behaviour. Rechecked weekly, emailed only on change. Findings and fixes, never a verdict.
Agent insight
What the agent inside the site reports.
- Traffic analyticsNeeds agent
- Every request from the server’s own log: path, status, response time and the real visitor IP behind a CDN. A live view, people separated from bots, server errors and the slowest pages.
- Stack and vulnerabilitiesNeeds agent
- PHP, web server, database, CMS, plugins and packages, discovered rather than declared, matched against published advisories with the version that fixes each one.
- Server postureNeeds agent
- PHP settings that should be off, files that are writable when they should not be, and for WordPress, database hardening checks.
Code audit
Scanning the code a monitored site is deployed from.
- Code audit
- Connect a Git host and scan the repository behind your site for secrets, vulnerable code and dependencies. Findings show only once the repository is verified as yours.
- Scheduled code scans
- Scan tracked branches daily or weekly without anyone pressing a button.
- Scan on push
- A webhook queues a scan whenever a tracked branch is pushed.
- Deep code analysis
- Adds Semgrep, Gitleaks and npm audit to the built in rules and Composer advisories.
- Explain and fix for code
- An AI explanation and a suggested fix for a code finding.
Intelligence and reporting
Explanations and scheduled summaries.
- AI analysis and the assistant
- Ask questions about your own data, such as why the shop was slow on Tuesday, and get AI triage that explains a suspicious file and how to fix it. Metered in credits per month.
- Reports
- Uptime, incidents and security for any period, as a page or a download, and scheduled to your inbox weekly or monthly.
Account and integrations
People, integrations and branding.
- API access
- Bearer token access to the same JSON API the console uses, for your own dashboards and scripts.
- Slack, Teams, Telegram and webhooks
- Signed webhooks, per site and per severity, alongside email and the in app centre.
- Team members
- Owners, managers and viewers. A viewer login is how a client sees their own uptime without being able to change anything.
- White label
- Your colour and logo on the console and reports, so an agency’s clients see the agency.
- Assisted support
- Grant our team time boxed access to look at your data with you. You approve it, it expires, and it is logged.
Three plans, none of them about money
Every teammate gets a login on every plan, and alerts are never a premium feature. The plans differ in how deep it goes and how much of it you get.
| Limit | StarterOutside in only | ProfessionalMost teams start here | BusinessEverything |
|---|---|---|---|
| Monitored sites | 5 | 25 | Unlimited |
| Team members | 3 | 10 | Unlimited |
| Data retention | 30 days | 90 days | 365 days |
| Fastest check interval | 5 min | 1 min | 30 s |
| AI analyses per month | Not included | 500 | 5,000 |
| Code repositories | Not included | 5 | 25 |
| The agent, firewall, file integrity | Not included | Included | Included |
| White label, assisted support | Not included | Not included | Included |
| Price | |||
Unlimited means no limit is set on the plan. Limits can be raised for an account without changing plan, just ask on the call. More than a hundred sites, or an estate that fits none of these? Tell us about it and we will size it.
In every plan, including the smallest
Not upsells. A monitoring product that puts alerting behind a higher tier is selling a dashboard.
Alerts that reach a person
Severity routing, quiet hours and repeat collapsing, so thirteen notifications about one outage arrive as one that says thirteen.
DPDP readiness, weekly
An email only when something actually changed. Findings and fixes, never a compliance verdict.
Reports you can send on
Uptime, incidents and security for any period, as a page or a download.
Proper GST invoices
CGST and SGST within the state, IGST across it, zero rated for exports, with a printable copy for your accountant.
Or, by the question you are asking
Is it up, and was it up?
The question that gets a monitoring tool bought, and the one most tools answer with a green dot and no evidence.
DNS, connect, TLS and first byte, separately, because slow has four causes and three different fixes.
A percentage with the window, the check count and the downtime it came from. A bare 99.9% is unfalsifiable.
Who is visiting, and who is attacking?
Read from the access log by the agent, so it is your server’s own record rather than a tag a visitor can block.
412 attempts on /wp-login.php from one address is evidence. Brute force detected is a mood.
The proxy headers are unwrapped rather than reported as the visitor.
Has anything changed that shouldn’t have?
The question you cannot answer after the fact unless something was watching before.
A finding is readable, the changed lines, rather than a filename and a hash.
Every record change dated, every certificate watched to expiry.
Would we survive being asked?
India’s DPDP penalties begin on 13 May 2027, and the Board moves from guidance to supervision in November 2026. This part of the product exists because of those dates.
Checks that could not run are excluded and counted, and the report says how much a web request can see at all.
No field in the data model holds one. Findings and fixes. The legal opinion stays with your lawyer.
What no plan includes
Worth knowing before a call rather than after a month.
No SMS or phone calls yet
Alerts go to email, Slack, Teams, Telegram and webhooks. If someone must be woken by a ringing phone, we are not the whole answer yet.
No application tracing
We measure what a request cost and what the server was doing. We do not profile your code.
No log aggregation
We read your access log for traffic and attacks. It is not a place to ship application logs.
One probe location
It tells down from slow, not slow in Sydney.
It is not a CDN or an edge firewall
The firewall runs inside your site, on your server, and refuses the request after it arrives.
It does not fix things for you
It tells you a file changed, what changed in it and when. Restoring it is your call, or hand it to our team.
Pick your worst site. Run the free check on it.
If what comes back is not worth a conversation, nothing here will be worth your time either, and you will have lost fifteen seconds. Send us the list and we will come to the call having already looked at them, so it starts with findings rather than a pitch.
Questions about monitoring
The demo, the agent, the plans, and what it deliberately does not do.
Build it here and the watching is free
Every site published on Growthzi gets uptime, certificate, DNS, header and blocklist monitoring from the minute it goes live.