Skip to content

Monitoring knows where everything lives.

You are handing us a map of your infrastructure: which hosts exist, which ports are open, and sometimes how to sign in. Here is exactly what we do with it.

Agent token
•••••••••••• Shown once

Kept only as a one-way hash, so it is never shown again — not to you, not to anyone else on your account, not in an export. You can replace it; you cannot read it back.

api-01 connected with its token.

Getting in

Two-factor, each person's own choice

An authenticator app or a code by email — whichever each person prefers, not whichever the account decided for everybody. With recovery codes for the day the phone is lost, and a browser you can trust for 30 days so it is not a tax on every sign-in.

It works the same way on the web and in the iPhone and Android apps. If a member loses both phone and codes, the account's owner can reset it for them, and every change to two-factor is confirmed by email.

The address is confirmed before the account works

A new account cannot sign in until its email address has been confirmed. Alerts are only useful if they arrive, and an address nobody has ever proved they own is not an address.

Password reset that proves something

A reset link goes to the address on file and nowhere else, and the request answers the same way whether or not that address has an account — so the form cannot be used to find out who is a customer.

Owners decide who may change what

Everyone on the account sees the monitoring, gets the alerts, acknowledges problems, runs a check on demand and goes on or off call. The owner decides, person by person, who may also add and change hosts, checks, maintenance windows and status pages; new members start watch-only. Only owners manage the people and the monitoring switch.

A lock on the app

Turn it on and the app asks for Face ID, Touch ID, a fingerprint or the phone's own passcode before it shows anything. Alerts still arrive while it is locked.

A lost phone is one click

From My profile on the web, sign every one of your phones and tablets out of Gryphon at once. Their sign-in stops working and their alerts stop arriving.

Your secrets

Encrypted at rest, and write-only

Database passwords are encrypted in the database, and agent tokens are kept only as a one-way hash. Neither is shown again once saved — not to you, not to anyone else on your account, not in an export. You can replace one; you cannot read one back.

A token per agent, and no open port

The agent connects out to Gryphon and listens for nothing, so the machine it runs on opens no port to anyone. Each agent proves which host it is with a token issued for that host alone: replacing one host's token is one host's job, disconnects the agent that held the old one, and a token taken from one machine is not a way into the others.

In a Kubernetes cluster the agent runs as a pod with an account that may only read workloads, nodes and pods: not Secrets, not ConfigMaps, not logs, and it cannot open a shell in a pod or change anything. The manifest that grants it is short and public.

The best credential is no credential

Postgres and MariaDB/MySQL can be checked with no user and no password at all: the handshake alone distinguishes a server that is accepting connections from one that is still recovering. Redis needs none unless the server itself demands one. Where you do not need to hand us a password, do not.

Checks that stay on the machine

A database bound to localhost is checked by the agent on that host, so its port never has to be exposed to reach it. If the check signs in, the password is stored encrypted and reaches the agent only over HTTPS, with each check; or the check can use no credential at all.

Our side of it

Hosted in Canada

The application and its database run in Canada. The remote vantage points that run checks from other parts of the world hold nothing: they are given what one check needs — an address, and a database password if that check signs in — report what happened, and keep no record of it or of your account.

Encrypted in transit, everywhere

Between you and Gryphon, between the app and the API, and between our server and every vantage point — where it is required rather than merely offered, and each one carries its own key.

Vantage points cannot be aimed inwards

A remote location refuses private, loopback, link-local and carrier-grade NAT addresses on every check, with no setting to allow them. A check run from another part of the world can only reach the public internet.

Ninety days, then gone

Events and alerts are kept for three months and then removed. Readings are kept one by one for a week, and as an hourly summary for the three months. You can delete your account outright from the app, which takes your hosts, checks, history and keys with it.

Fourteen days free. Then from $4.99 a month.

The agent, the dashboard, the apps and every check but the five for Kubernetes are in every plan. The plans differ in how much you watch, how often, from where, and how many people and status pages they include. Compare the plans. Cancel any time.

Already have an account? Sign in