SWR7
Home/Services/Service · Monitor 24/7
Service · Monitor 24/7

Monitor 24/7: continuous security monitoring for your sites

Most incidents are not zero-days. They are the certificate that expired on a Sunday, the header that vanished with a deploy, the subdomain nobody remembered. Monitor is the pair of eyes that notices.

What Monitor does

Monitor 24/7 keeps the exposure view from Detect current, all the time, and tells you when something changes. Think of it as an antivirus for your web surface: it does not wait for the next audit to discover that the world moved.

What it watches

  • Availability and latency from outside your network, against a baseline learned per site — "slow" means slow for you.
  • TLS — expiry countdown, weak protocols, configuration drift after a rotation.
  • Security headers — the ones a redeploy silently removes.
  • Exposed files and paths and subdomain changes.
  • Leaked credentials tied to your domain in public breach corpora.
  • Traffic anomalies against a learned baseline: request rate and latency, confirmed on a second reading before anyone is woken up.
  • Content integrity of critical pages, so a defacement or an injected script is caught within minutes, not when a customer tweets it.

How alerts work

High-severity findings and confirmed anomalies reach your operators within minutes, with numbers, not adjectives: what changed, since when, how far from normal. Everything else lands in the client area and in the periodic PDF report. Alerts are treated as a scarce resource: a threshold that fires on a shared article trains everyone to ignore the pager, so baselines are reviewed monthly and every proposed change is shown to you first.

Where it stops

Monitor observes and alerts. It does not switch anything on your infrastructure — on your systems SWR7 is propose-only. Hardening your edge against DDoS and rehearsing what to switch when a flood starts is the DDoS protection add-on.

SafetyMonitor runs at S0–S1: a handful of lightweight requests per cycle, invisible to your users, allowed on production under the Rules of Engagement.

Frequently asked questions

How fast is an alert?

Checks run in cycles of minutes; a confirmed high-severity change is alerted within minutes of the second reading that confirms it. Single readings do not page anyone.

Can we choose who gets alerted and how?

Yes. Operators and channels are set in the Rules of Engagement and can be changed at any time from the client area.

Does Monitor include DDoS protection?

Monitor detects the anomaly and alerts. Edge hardening, the under-attack runbook and the escalation path to your CDN are the DDoS protection add-on.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call