You sell uptime. Someone will check the number.
You sell availability, so your status page, your SLA clause, and every enterprise security questionnaire rest on a single number. Perstat measures that number from outside your service, confirms it across probes on six continents before it pages anyone, and keeps the record you hand the customer who asks.
The number under your contract
Your product’s uptime is not an internal metric. It is a line in a contract, a figure on a public status page, and a row in every enterprise security questionnaire you answer to close a deal. You sell availability, so sooner or later a customer, a prospect, or an auditor will hold the number you publish against the outage they remember.
That is the moment monitoring that grades itself falls apart. A tool that measures from inside your own infrastructure, or that opens an incident the first time one probe sees one slow response, produces a number you cannot defend the moment it is disputed. What holds up is a number measured from outside your service, on a rule you can explain in one sentence, that reads the same on your status page as it does in your SLA record.
Measured from outside, confirmed before anyone wakes up
Perstat watches your service from a probe fleet on six continents. An incident opens only when more than one region confirms the failure, and within a region 75% of probe nodes have to agree before the region votes at all. A single flaky route, one saturated transit link, or one bad resolver on one continent never reaches your phone, and nothing below that threshold is silently dropped: a single diverging region lands on a watchlist you read on your own schedule instead of at 3 a.m.
Point that fleet at the surface your customers actually touch. There are 12 check types: HTTP with assertions on status code, keyword, or regex for your API and your login; TLS certificate and domain expiry, so a lapsing cert or a forgotten renewal is a warning weeks out and not a Saturday outage; DNS hygiene (SPF, DMARC, CAA); down through SMTP, IMAP, TCP, ping, and traceroute. Every failure is attributed to a layer: your app, your DNS, the network in between, or our own node. When a customer insists the problem is on your side, you can show which layer broke and which region saw it first, instead of trading screenshots.
The record you hand a customer
The same measurements become the record you show when someone asks you to prove it. Your status page and your SLA report draw from one dataset, so the public story and the contract story cannot drift apart.
Downtime is curated with real boundaries: an incident window runs from the quorum confirmation to confirmed recovery, the exact boundary you were paged on. Announced maintenance suppresses alerts for its duration and still stays on the record, visible but not counted against you. A false positive can be discarded with a reason and an actor, its effect on the published number previewed before it is applied, and reversed if you were wrong. Availability is floored, never rounded up, because an SLA figure should be a lower bound you can defend. History is retained from 7 days to 2 years, depending on plan.
For the enterprise deal that hinges on a specific SLA, that curated record with logged exclusions is the evidence behind the number; hand a prospect the sample SLA report and let them recompute it. A downloadable, self-service SLA report export is the announced next step, not a shipped feature today.
A status page on your domain, and metrics in your dashboard
Your customers should see your brand, not ours. From Sentinel up, a status page runs on your own domain (status.yourcompany.com) with automatic TLS, and subscribers confirm by double opt-in and hear about both the incident and the recovery. Draft, public, shared-password, and per-viewer access modes cover a public page and a private one for a single enterprise customer.
For your own dashboards, API keys are live. You mint them per organization, scope them to monitors, incidents, or status pages, and narrow them to selected projects. They authenticate seven read endpoints today, enough to pull monitors, checks, time series, and incidents straight into whatever you already run. Writing through the API is not honored yet, so creating a monitor still happens in the web app or the iOS app; the reference is generated from the contract on every build.
On-call for the incidents that are real
When quorum does confirm, on-call routes it. From Sentinel up, rotations page the person actually holding the shift, escalate at 5 minutes and again at 15 if no one answers, and warn on a coverage gap before it becomes a missed page. Acknowledging an incident is taking ownership: it stops the broadcast and silences every other device at once. Escalation runs over push and email today, with SMS and a voice call the announced next step of the ladder.
Start with one check
Point one monitor at your API and one at your certificate, and watch what Perstat records. That record is the argument for the rest.
Start monitoring free , no card. Or take the tour , no signup, or read how the number holds up for leadership and audit . Every price is on the pricing page .