Platform features

Everything your infrastructure needs — packaged for teams without a dedicated ops function

Six capability areas, each designed to work without privileged access, without vendor lock-in, and without a bill that surprises you at month-end.

Server agent

Deploy in 30 seconds. Root-free.

A single curl command installs the wt15-server-agent as an unprivileged service user with zero Linux capabilities. The only monitoring agent in its class that makes this guarantee.

  • NoNewPrivileges=yes — the process cannot escalate under any condition
  • ProtectSystem=strict — entire filesystem is read-only except the state directory
  • Zero Linux capabilities at install — not even CAP_NET_BIND_SERVICE
  • Credential file isolated to the agent's own state directory
  • Automatic upgrade via --upgrade flag — no manual intervention
  • Self-contained log at /var/log/wt15-server-agent.log
# Install — one command, no root capabilities required
$ curl -fsSL https://watchtower15.com/install.sh \
| sh -s -- <org_token>

==> Installing on prod-01 (amd64) ...
==> Creating unprivileged user: wt15-server-agent
==> Enrolled successfully (agent_id=wt15-a8f3c2e1)
==> ✓ Monitoring active

# Systemd unit — notice what is absent
[Service]
User=wt15-server-agent
NoNewPrivileges=yes
ProtectSystem=strict
AmbientCapabilities= # empty — none granted
Domain monitoring

Know before your users do — across every DNS record type

External probes run every 60 seconds against your domains, SSL certificates and reachability endpoints — from UK/EU infrastructure, so your latency data is relevant to your users.

  • DNS: A, AAAA, MX, CNAME, TXT, NS, SOA record monitoring
  • SSL/TLS certificate health — expiry, chain validity, cipher strength
  • Domain registrar expiry tracking — alert before renewals lapse
  • HTTP/TCP service reachability probes with response-time tracking
  • Configurable scan intervals — from every 60 seconds to daily
  • Historical scan data retained for trend analysis
example.com A Healthy
example.com MX Healthy
example.com SSL Valid · 87 days
example.com Expiry Expires in 14 days
api.example.com HTTP 200 · 142 ms
shop.example.com TCP:443 Reachable
Last scan 32 seconds ago
Security scanning

Security posture without a SIEM

SSL/TLS analysis, DNS anomaly detection and domain expiry monitoring are built directly into the platform — no additional licence, no separate toolchain. No other SMB uptime tool offers this breadth.

  • SSL certificate chain validation — catches intermediate cert issues before browsers do
  • TLS protocol version & cipher analysis — flag deprecated TLS 1.0/1.1 usage
  • DNS anomaly detection — alert on unexpected record changes that may indicate hijacking
  • Domain expiry alerts — configurable thresholds (90, 30, 7 days)
  • On-host security scanning integration — roadmap for Lynis/CIS benchmark checks
What UptimeRobot monitors

SSL certificate expiry date only — nothing else in this list.

TLS protocol TLS 1.3 ✓
Certificate chain Valid (3 certs) ✓
Cipher suite Strong ✓
DNS A record No changes detected
DNS MX record Changed 2h ago
Domain expiry ⚠ 14 days — renew now
Security posture 2 items need attention
Alerting & governance

SSO, audit logs and alarm policies — included at base

Governance features that competing products gate behind enterprise plans come standard with WatchTower15. Your team can enforce access control and maintain a full audit trail from day one.

  • SAML 2.0 / OIDC SSO — integrate with Okta, Azure AD, Google Workspace
  • Role-based access control (RBAC) — admin, editor, viewer roles per organisation
  • Full audit log — every action timestamped and attributed to a user
  • Alarm policies with configurable thresholds and escalation rules
  • Alert channels: email, Slack, PagerDuty, webhook — no extra cost
  • Organisation-level resource isolation — multi-org access for agencies and MSPs
SSO provider Okta (SAML 2.0) ✓
Active users 12 members
Audit log entries 3,847 this month
Active alarm policies 7 policies
Alert channels Slack · PagerDuty · Email
Enterprise plan required No — included at base
Log ingestion

Centralised log search — no separate log platform required

The server agent pushes structured log batches directly to the platform. Logs are stored in VictoriaLogs and S3 simultaneously, giving you fast full-text search alongside durable archival.

  • Agent pushes NDJSON log batches — no syslog forwarding to configure
  • Dual-write: VictoriaLogs for fast search, S3/MinIO for archival
  • Full-text search across all enrolled servers in one interface
  • Log folder patterns configurable per server agent profile — push to all servers simultaneously
  • Log level faceting — filter by ERROR, WARN, INFO across your entire fleet
  • journald log source support alongside file-based sources
Log ingest (last 24h) 2.4M lines
ERROR events 47 events
WARN events 312 events
Storage backend VictoriaLogs + S3
Search latency < 200 ms
Separate log platform Not required
Fleet management

Push config changes to every server in your fleet simultaneously

Server agent profiles let you define telemetry options, log collection rules and scan schedules once — then push them to all enrolled servers at once, without SSH access.

  • Server agent profiles — define config templates in the dashboard
  • Assign profiles to individual servers or groups with tags
  • Config changes are pushed on next agent heartbeat — no SSH required
  • Telemetry options: CPU, memory, swap, disk, disk I/O, network, load, processes
  • Log folder rules with regex patterns and file extension filters
  • Scan schedules: security audit, vulnerability scan, open ports, SSL certificate
Profile: production-servers 8 servers
Telemetry interval 60 seconds
Active metrics CPU · Memory · Disk · Network
Log folders /var/log/nginx · /var/log/app
Config version v12 — all agents current
Last config push 3 minutes ago ✓
Get started

Ready to deploy zero-privilege monitoring?

Talk to us about your infrastructure — we'll show you how WatchTower15 fits into your stack and give you a concrete picture of what your bill will look like.