Security updates
Applied on a schedule, not when somebody remembers. What changed is recorded.
Managed hosting and security
Most outages announce themselves for days: a disk filling, memory creeping up, responses getting slower. Nobody is looking, so the first signal anyone gets is a customer saying the site is down. This service is the automation that looks, and that acts on what it sees before you would have noticed anything.
Watched continuously, without anyone asking
Example of the shape, not of your numbers. Two amber rows here are a week of warning, not an incident.
Part of What keeps it all running
Recognise this
Kept secure
Applied on a schedule, not when somebody remembers. What changed is recorded.
Renewed automatically, and checked from outside so a failed renewal is caught.
Libraries checked against known vulnerabilities, and updated when it matters.
Reviewed periodically. People who left keep no way in, and neither do old keys.
What normal looks like is measured, so abnormal is recognisable rather than argued about.
Every change to the server is logged, so a year from now the history still exists.
The point of it
Checking whether a site answers tells you it has already fallen over. The useful signals are the slow ones, the measurements that drift in the wrong direction for days before anything breaks. Those are measured automatically, every hour, whether or not anyone is thinking about your system that week.
What a drifting signal looks like
What that produces
Illustration. The same shape applies to memory, to database connections and to response time.
Automatic recovery
A large share of what goes wrong on a server at three in the morning is recoverable without judgement. Those cases are handled by the machine, immediately, and I read about them afterwards.
One hard rule. Automatic recovery never deletes, edits or moves your data. It restarts things and frees space it created itself. Anything that touches business data waits for a person.
Overnight, no one involved
02:14WARN
02:14INFO
02:14INFO
03:00INFO
03:20INFO
03:41INFO
08:02INFO
From outside
The checks run from separate infrastructure, in a different location. If your server disappears entirely, something that is not your server notices.
Who is asking
Inside the server
Disk, memory, processes
Database and queues
Silent if the server is down
Outside, elsewhere
Does it answer at all
Is the certificate valid
Does DNS still resolve
Speaks when the server cannot
Backups
Backups that run every night and have never been read back are the most common false sense of safety I find. Here the restore is exercised on a schedule, and the result is part of what you get in writing.
Evidence
The hardest thing about a service like this is that when it works, nothing happens. So every month you get a short written record of what was done, whether or not anything went wrong.
What I actually promise
Plenty of providers advertise a response inside the hour. This practice is early in its life, and I will not sign a commitment before I can prove I keep it. So the promise is 24 hours, and the work goes into making 24 hours a comfortable margin instead of a risk.
That is what the automation is for. A problem caught while it is still a trend gives you days to act, not minutes. Since October 2025, no client has needed to open a support ticket. That is across 10+ servers I operate, dedicated and shared VPS.
Availability has two halves. One belongs to the provider whose machine it is, and no monitoring changes that half. The other is the application, the disk, the certificate, the database, and that half is mine. I do not advertise a number for either. You get yours, measured, every month.
If your situation genuinely needs someone reachable within minutes at any hour, say so early. I will tell you that this is not the right service, rather than sell it to you.
Support tickets counted across the systems I run, on 10+ servers, dedicated and shared VPS, from October 2025 to today. Availability is measured per system, from outside the server, and reported to you every month rather than advertised here. Maintenance windows are announced in advance and excluded, as they are in any provider's figure.
How it runs
We measure what normal looks like for your system, so abnormal can be recognised.
Checks from outside, measurements from inside, alerts set where they mean something.
The faults that need no judgement are handled by the machine, and recorded.
Every month, in writing: what happened, what was done, what needs a decision.
The aim is fewer incidents, not faster apologies
How it is sold
Not sure this applies to you yet? See how infrastructure and deployment work
Questions
Monitoring and automatic recovery run at all hours, every day. What is not round the clock is the human response: when something needs a person, the commitment is 24 hours. This practice is early in its life and I would rather earn a faster commitment than advertise one. In exchange, the effort goes into catching problems days before they become outages. Since October 2025 that has meant no client needing to open a support ticket.
Possibly, but not on day one. Watching a system I have never read would mean promising something I cannot stand behind. So it starts with an audit: how it is built, how it is deployed, what state the server is in, what would happen if it fell over tonight. You get that in writing whatever we decide afterwards. If it turns out to be something I can look after honestly, we go ahead. If not, I will say so, and you still keep the audit.
Then the system is down for as long as they are down, and no monitoring changes that. What you get is knowing immediately, knowing it is not your system, and having a backup that has been restored before, in case it becomes worse than an outage.
No. This keeps what exists running, updated and backed up. Changing what it does is separate work, and it goes through the same route as everything else: development first, your approval, then production.
The system keeps running. It is on your server, in your account, with your code. What stops is the watching, the updates and the reporting. I will tell you plainly what you are taking on.
Off the server they protect, encrypted, at a location agreed with you. You can be told exactly where, and you can hold a copy of the keys.
Only what is necessary to keep the system running, and only when there is a reason. Diagnosis starts with logs and measurements. Anything beyond that is discussed with you first.
By how much of the system needs watching, not by how many visitors it has. One application on one environment is one subscription. You get the figure before you commit to anything.
Tell me what you are running today, and I will tell you what would actually be watched.