The number your customer sees is the number your auditor gets.
Four bills become one for the people who sign the budget. Every check becomes evidence an auditor can recompute for the people who sign it off. One product, one record, built in the EU.
Two people have to say yes before Perstat becomes your record of record. The one who signs the budget wants four bills to become one without losing depth. The one who signs it off wants an availability number an auditor can recompute without taking anyone’s word for it. This page is written for both, and the strongest exhibit sits in the middle where both can read it.
For the people who sign the budget, start with the economics. For the people who sign it off, start with the evidence.
The economics
For controlling, and the CTO who defends the spend.
The consolidation math
One monitoring tool, one status-page tool, one on-call tool, and a fourth place where you glue evidence together by hand. That is four subscriptions, four admin consoles, four renewal dates, and four security reviews for one question: are we up, and can we prove it? Perstat answers all four from one contract. The comparison is tool for tool, net against net, as of July 2026, and it is on the pricing page and the comparisons in full: Free 0, Pulse 29, Sentinel 89, Command 249, Enterprise from 690 EUR per month, net, excl. VAT. Sentinel includes 15 seats and Command 30; the price does not multiply the week the team grows.
One incident, against one plan
Bitkom put the cost of IT outages in Germany at 73.3 billion EUR for 2025. Perstat does not promise to keep your share of that at zero. It promises that when an outage happens, you hold a record you can defend in a penalty discussion, a customer call, or an audit. Measured against a single such conversation, Sentinel is 89 EUR per month.
Sovereignty and viability
Sovereignty is a procurement line now, not a preference: customer and regulator questionnaires ask where the data sits. Perstat is a German GmbH with no US parent, the control plane is hosted in the EU, GDPR applies with a DPA you can sign, and there is no US CLOUD Act reach because no US company sits in the chain. Probe nodes on six continents are measurement points; control and data stay in the EU. On viability, note the irony of the category: the incumbent most teams are moving off, Opsgenie, stopped selling in June 2025 and shuts down on April 5, 2027, with customer data deleted. Perstat is built by a founder with 25+ years in internet infrastructure, a certificate-business exit, and a DNS registrar he runs today. More on that.
Compare the stack on the comparison pages, or see pricing.
The artifact
Both tracks point here. This is one quarter of one service, as Perstat records it.
| metric | value |
|---|---|
| availability, gross | 99.925% |
| availability, after curated exclusions | 99.994% |
| period | 91 days = 131,040 minutes |
| check interval | 30 s |
| checks executed | 1,572,480 across 6 regions |
| regions confirming | na-ewr, eu-fra, as-sgp, sa-gru, af-jnb, oce-syd |
| confirmed incidents | 1 |
| excluded maintenance windows | 1, announced, real boundaries |
The incident starts at the quorum confirmation across regions (02:41:12 UTC), not at the first failed check 30 seconds earlier and not at a rounded minute. The maintenance window is excluded only because it was announced, and it is excluded on its real boundaries. The availability number is floored, never rounded up, because an SLA figure should be a lower bound you can defend. 91 days are 131,040 minutes; the math adds up, and anyone can recompute it. See the full sample SLA report.
The evidence
For external and internal audit, and the CISO who carries the register.
Independence is the evidence class
The number is measured from outside the service, from probes on six continents, and an incident is only counted once a quorum of regions agrees. The service under test does not grade its own availability, which is the property that makes the record worth anything to a reviewer. A single flaky route does not create a false incident, and a single region’s good day does not hide a real one.
Math that survives recomputation
Timestamps come from the monitoring system, not from a human recollection written up afterward. The same record feeds your status page and your SLA record, so the public story and the audit story cannot drift apart. Corrections are part of the record, not erasures: a discarded false positive carries a reason and an actor, its uptime effect is previewed before it is applied, and it is reversible. Availability history is retained per plan, 7 days, 30, 90, 1 year, 2 years, and those are the exact windows the record draws from. The credibility of the number survives being recomputed, and it does not depend on any certificate status.
Where Perstat sits, and where it does not
Perstat is the independent availability evidence that feeds an ISAE 3402 or IDW PS 951 assurance report and a DORA incident notification. It is not that report, and it does not make you compliant. You add Perstat to your own DORA Article 28 register of ICT third parties; the GDPR pack that supports that entry, the DPA, the subprocessor list, and the technical and organizational measures, is available on request today. For context, with dates: DORA has applied since January 17, 2025, with a reporting cascade of 4 hours, 72 hours, and one month; NIS2 pulls well over a hundred thousand companies across the EU into scope, an estimated 30,000 to 40,000 in Germany alone, of which about 39% were registered by the March 2026 deadline (BSI).
Read our security controls, or read how this maps to DORA incident reporting and SLA report audits. See a sample SLA report.
Honest limits
- Perstat does not hold ISO 27001 or SOC 2, and does not borrow badges it has not earned. It lists controls you can check and a founder who holds CISSP, CCSP, and ISSAP personally. See the security page.
- The record is recomputable, not tamper-proof. Perstat claims that you can recompute the number, not that the store is immutable; write-once, audit-proof archival is a roadmap note, not a current claim.
- Enterprise SSO (SAML) is not available yet. Sign-in is email-based today.
- Scope is deliberate: uptime and its evidence, not APM and not log management.
It holds up.
Four bills become one, and one number holds up when someone recomputes it. That is the whole promise, and it is small enough to keep.