Changelog

Built in the open.

Every customer-visible change, newest first. No testimonials yet — this page is the honest substitute: what shipped, when.

RSS feed
  1. Improved

    Documentation rebuilt as one page per capability, with search

    • Docs are now 21 pages — monitors, alerting, destinations, maintenance windows, incidents, Intelligence, security grading, environments and the credential vault, status and trust pages, reporting, the REST API, API keys, service accounts, MCP, the probe agent, roles, retention and plan limits — each with the exact fields, limits and routes the platform enforces.
    • Client-side search (⌘K) across every page and heading, with snippets.
    • Where a capability is still in progress — multi-region execution, status-page custom-domain verification, SSO — the docs say so.
  2. New

    Free tools: SSL checker, security headers grader, DNS lookup, is-it-down, SLA calculator, cron builder

    • Six no-signup tools at /tools. The security headers grader uses the same header and cookie scoring as the SSL/TLS Security monitor, so its grade matches what a monitor would report.
    • Live checks are rate-limited per address and refuse private or reserved targets.
  3. Improved

    Comparison and solutions pages on the website

    • Dated, criterion-by-criterion comparisons against UptimeRobot, Better Stack, Pingdom, Checkly, StatusCake, Uptime Kuma and Atlassian Statuspage — each with a section on where the other tool is better.
    • Solutions pages for developers, SRE and platform teams, agencies, e-commerce and SaaS.
  4. Improved

    New sidebar and sign-in design

    • A navy navigation rail with colour-coded sections, an open-incident badge, and a pinned account block with theme switch and sign-out.
    • Settings, Organization and Developer API sub-navigation use coloured pills and icons; sign-in, sign-up and password pages share the same brand panel.
  5. Security

    Billing service hardening

    • Access tokens are checked for token type and audience before a billing action, and the service refuses to start with a placeholder JWT secret.
    • Stripe webhooks are processed in order, re-fetch the subscription before applying a change, and ignore superseded subscriptions; only handled events are recorded.
    • Request timeouts, body-size caps, per-user rate limits and standard security headers on every billing endpoint.
  6. Improved

    Frontends on React 19.2 and Next 16.3

    • The app and admin console run the same React 19.2.8 / Next 16.3 versions; the global monitoring map moved to react-simple-maps 5.
    • Lint clean-up across 43 files and a dependency audit with no open advisories.
  7. Improved

    Security scoring rules v4

    • HTML responses are graded as browser pages (HSTS, CSP, nosniff, clickjacking, Referrer-Policy, Permissions-Policy — 30 points); non-HTML responses on HSTS alone, with browser-page headers reported but unscored.
    • Content-Security-Policy is parsed and scored on six properties, honouring nonce/hash neutralisation of 'unsafe-inline' and 'strict-dynamic'.
    • Cookies are scored in both profiles (Secure, HttpOnly, SameSite; weakest cookie wins) and excluded from the denominator when a response sets none.
    • Certificate key strength and signature algorithm became scored TLS checks.

Try the current build.

Ten monitors, one region and a status page are free forever — no card.