# HarpyWatch: know before your customers do

> HarpyWatch checks your websites around the clock — whether they are up, whether the certificate and domain are about to lapse, whether links and pages still work — and tells you the moment something breaks.

Start free: https://app.harpywatch.com/signup (add `?target=https://your-site.com` to carry the site you want watched).

## The first minute

1. **Name the site.** Type an address into the box. There is no account yet; the address rides along to sign-up, so you never type it twice.
2. **Confirm your inbox.** Sign-up is an email address and a password. Confirming the address is what starts the watching: there is no wizard after it and nothing to configure first.
3. **Read the first results.** Four checks have run by the time the grid opens: uptime, DNS, the certificate, and a grade of the security headers. That last one fails on many perfectly healthy sites, which is the first thing it finds for you.

## What it checks (31 kinds)

### Uptime and availability

Is it answering, and answering every time?

- [Website uptime monitoring](https://harpywatch.com/checks/http-uptime): Requests the target and records the response class and how long it took.
- [Intermittent downtime detection](https://harpywatch.com/checks/availability-sample): Requests the same endpoint several times in one run and reports how many of those samples actually succeeded.
- [TCP port monitoring](https://harpywatch.com/checks/tcp-port): Opens a TCP connection to the port and reports whether it is accepting them.
- [Real browser page load monitoring](https://harpywatch.com/checks/browser-render): Renders the page in a real browser and times each phase of the load.
- [Redirect chain checker](https://harpywatch.com/checks/redirect-chain): Follows the redirects from the URL and reports the route a visitor is taken along, hop by hop.
- [WebSocket monitoring](https://harpywatch.com/checks/websocket-handshake): Performs the WebSocket opening handshake and reports whether the endpoint still upgrades the connection to a real socket.

### Certificates, DNS and domains

Is it still the site people think they are reaching?

- [SSL certificate expiry monitoring](https://harpywatch.com/checks/ssl-cert-expiry): Watches certificate validity and warns before it lapses.
- [SSL certificate chain checker](https://harpywatch.com/checks/cert-chain-trust): Completes a TLS handshake and reports whether a browser would trust the certificate it was served.
- [TLS version and cipher check](https://harpywatch.com/checks/tls-handshake): Completes a TLS handshake and reports the protocol version, cipher suite and key exchange the endpoint agrees to with a modern client.
- [DNS monitoring](https://harpywatch.com/checks/dns-resolution): Resolves the hostname and checks the records against what is expected.
- [Domain expiration monitoring](https://harpywatch.com/checks/domain-expiry): Asks the registry when the domain's registration lapses, and counts down to it.

### Content, links and SEO

Is the page, the API and what crawlers read still right?

- [Broken link checker](https://harpywatch.com/checks/broken-links): Requests every link on the page and reports the ones a visitor would find broken.
- [Page content monitoring](https://harpywatch.com/checks/dom-content): Loads the page and asserts that expected content is present.
- [JSON API monitoring](https://harpywatch.com/checks/json-api): Fetches the endpoint and checks the document it returns is still the one callers depend on.
- [JSON Schema validation](https://harpywatch.com/checks/json-schema): Validates the whole document an endpoint serves against the JSON Schema its callers were promised.
- [HTTP header monitoring](https://harpywatch.com/checks/http-headers): Fetches the page and checks the response headers are the ones that should be there.
- [XML sitemap monitoring](https://harpywatch.com/checks/sitemap-health): Fetches the sitemap and reports whether it is still a document a crawler can use — that it parses, declares URLs, and points at this site.
- [Robots.txt monitoring](https://harpywatch.com/checks/robots-policy): Fetches /robots.txt, parses it the way a crawler does, and reports whether the URLs this monitor requires are still crawlable.
- [RSS and Atom feed monitoring](https://harpywatch.com/checks/feed-freshness): Fetches the RSS or Atom feed and reports whether it still parses and whether anything has been published into it lately.

### Speed and performance

How long does a visitor wait, and for how much?

- [Core Web Vitals monitoring](https://harpywatch.com/checks/core-web-vitals): Loads the page in a real browser and reports what a visitor experiences while it paints: when the main content appeared, how much the page moved under them, and how long it could not answer a tap.
- [Time to first byte monitoring](https://harpywatch.com/checks/ttfb-budget): Times the wait before the first response byte and splits it into DNS, connect, TLS and the origin’s own think time.
- [Page weight monitoring](https://harpywatch.com/checks/page-weight): Loads the page in a real browser and adds up every byte it fetched, split by what kind of resource spent them.
- [Gzip and Brotli compression check](https://harpywatch.com/checks/compression): Asks for the page the way a browser does and measures whether the body really arrived compressed, and by how much.
- [HTTP cache header check](https://harpywatch.com/checks/cache-policy): Reads the caching rules a response declares, then sends the origin its own validator back to check that revalidation really produces a 304.

### Security and privacy

What does the site hand to a browser, and to whom?

- [Security headers checker](https://harpywatch.com/checks/security-headers): Grades the response against the browser protections a visitor relies on, and reports which are actually in force.
- [Content Security Policy checker](https://harpywatch.com/checks/csp-policy): Reads the Content-Security-Policy off the response and judges what it actually restricts, rather than whether one was sent.
- [Mixed content checker](https://harpywatch.com/checks/mixed-content): Reads every subresource an https page references and reports which of them a browser is told to fetch over plaintext http.
- [Cookie security flags check](https://harpywatch.com/checks/cookie-flags): Grades every cookie the page sets on Secure, HttpOnly and SameSite, and reports which ones a browser would hand to an attacker.
- [CORS policy checker](https://harpywatch.com/checks/cors-policy): Sends a cross-origin read and a real preflight from an origin nobody can own, and reports who this endpoint is willing to hand its data to.
- [Open redirect check](https://harpywatch.com/checks/open-redirect): Hands the endpoint a destination on a host that cannot exist and reports whether it would send a visitor there.
- [Third-party tracker monitoring](https://harpywatch.com/checks/third-party-data-flow): Loads the page in a browser and reports which third parties received identifying data about the visitor, against the processors you have approved.

## What happens at 3am

- **A rule is waiting before you write one.** First run creates it: if the site stops answering, you hear about it. You can add rules for anything else afterwards.
- **A grade never wakes you.** A missing security header is worth a look in the morning, not a call at three. Posture checks report; outages page.
- **Repeats collapse, and recoveries close.** Alerts are throttled so a flapping site sends one message, not forty. PagerDuty incidents close themselves when the site recovers.
- **Nothing reads as fine until it was checked.** A check that has not run says Pending, never zero. A result older than twice its interval is marked stale. Missing data is drawn hollow, not green.

Alerts go to: Email, Slack, Microsoft Teams, Discord, Telegram, PagerDuty, Webhooks.

## Pricing

| | Free | Sentinel | Starter | Studio |
|---|---|---|---|---|
| Price | No charge | $20 a year | $19 a month | $59 a month |
| Monitors | 30 | 150 | 150 | 600 |
| Checks per month | 250,000 | 250,000 | 2.5 million | 12 million |
| Fastest check interval | Every 3 minutes | Every 5 minutes | Every 1 minute | Every 30 seconds |
| Result retention | 30 days | 30 days | 90 days | 1 year |

Payment is handled by Stripe.

## What is not built yet

Published status pages are not built yet. The screen exists in the product and says so where you would look for it. Everything else on this page runs on a server, against real sites, today.

## Who it is for

- **Agencies.** Every client site as one row in one grid. Filters live in the address bar, so the view you are looking at is a link you can send.
- **Online shops.** Know when checkout stops answering, a certificate is days from lapsing, or the domain is about to expire, before a customer tells you.
- **SaaS and API teams.** Watch JSON endpoints against the schema callers were promised, WebSocket upgrades, TLS settings and CORS, from outside your own stack.
- **Freelancers and small sites.** The Free plan watches 30 monitors at no charge. Sign-up is two fields.
- **SEO and marketing teams.** Broken links, redirect chains, robots.txt, the sitemap and Core Web Vitals, checked on a schedule rather than in a yearly audit.
- **Teams shipping with AI agents.** A green pipeline says a process started. A check from outside says the site works. Point HarpyWatch at every deploy.

## Questions

### What does HarpyWatch check?

31 kinds of check, in five families: uptime and availability; certificates, DNS and domains; content, links and SEO; speed and performance; security and privacy. Each one reports what that check actually knows, such as days left on a certificate or the links that broke.

### How quickly will I know my site is down?

At the next check. How often that is depends on the plan (Free: every 3 minutes; Sentinel: every 5 minutes; Starter: every 1 minute; Studio: every 30 seconds). If minutes matter, take a plan that checks more often.

### Is there a free plan?

Yes. Free costs nothing and watches up to 30 monitors, every 3 minutes. Sign-up is an email address and a password.

### Where do alerts go?

Email, Slack, Microsoft Teams, Discord, Telegram, PagerDuty and webhooks. Repeats are throttled, and a posture grade never pages anyone.

### Do I have to install anything?

No. Every check runs from outside your infrastructure, the way a visitor reaches you, so it keeps working when your own servers do not.

### Is there an API?

Yes. Create a token under Settings, API in the product. It reaches monitors and their results, alert rules and channels, the team, and the plan.

### How do I pay?

By card, through Stripe. Card details are entered on Stripe’s pages and never reach ours. You can change or cancel a plan from the product.

### Can I publish a status page?

Not yet. Published status pages are not built, and the product says so on the screen where you would look for them.

## How we measure

- **Check:** One kind of observation, such as uptime or certificate expiry.
- **Monitor:** One check running against one site on a schedule. A site with four checks is four monitors.
- **Interval:** The wait between two runs of a monitor. A failure is noticed at the next run.
- **Pending:** Configured, never run. Not a zero and not a pass.
- **Stale:** No result for more than twice the interval. Dimmed and marked; nothing is derived from it.
- **Hollow:** A time bucket with no observation in it: the difference between "we did not look" and "it was fine".
- **Retention:** How long results are kept and charted. Set by your plan.

Contact: hello@harpywatch.com. Docs: https://harpywatch.com/docs. Blog: https://harpywatch.com/blog.
