What Monitor does
Monitor 24/7 keeps the exposure view from Detect current, all the time, and tells you when something changes. Think of it as an antivirus for your web surface: it does not wait for the next audit to discover that the world moved.
What it watches
- Availability and latency from outside your network, against a baseline learned per site — "slow" means slow for you.
- TLS — expiry countdown, weak protocols, configuration drift after a rotation.
- Security headers — the ones a redeploy silently removes.
- Exposed files and paths and subdomain changes.
- Leaked credentials tied to your domain in public breach corpora.
- Traffic anomalies against a learned baseline: request rate and latency, confirmed on a second reading before anyone is woken up.
- Content integrity of critical pages, so a defacement or an injected script is caught within minutes, not when a customer tweets it.
How alerts work
High-severity findings and confirmed anomalies reach your operators within minutes, with numbers, not adjectives: what changed, since when, how far from normal. Everything else lands in the client area and in the periodic PDF report. Alerts are treated as a scarce resource: a threshold that fires on a shared article trains everyone to ignore the pager, so baselines are reviewed monthly and every proposed change is shown to you first.
Where it stops
Monitor observes and alerts. It does not switch anything on your infrastructure — on your systems SWR7 is propose-only. Hardening your edge against DDoS and rehearsing what to switch when a flood starts is the DDoS protection add-on.
Frequently asked questions
How fast is an alert?
Checks run in cycles of minutes; a confirmed high-severity change is alerted within minutes of the second reading that confirms it. Single readings do not page anyone.
Can we choose who gets alerted and how?
Yes. Operators and channels are set in the Rules of Engagement and can be changed at any time from the client area.
Does Monitor include DDoS protection?
Monitor detects the anomaly and alerts. Edge hardening, the under-attack runbook and the escalation path to your CDN are the DDoS protection add-on.