The 2 AM pages
Credential expiry
A Key Vault secret or certificate reaches its expiry date and every API call that depends on it fails — simultaneously.
Idle VMs on autopilot
Every cloud makes it easy to spin things up. None of them remind you to spin them down. Forgotten instances bill $300–$800/mo each, across every account you own.
Silent endpoint failures
Your status page says green. Customers start reporting errors. Somewhere, an HTTPS endpoint went down two hours ago.
What it watches
Everything that quietly breaks across your cloud stack
Secret & certificate expiry
Tracks expiry across Azure Key Vault, AWS Secrets Manager and ACM, and GCP Secret Manager. Alerts at 30-day and 7-day thresholds, classified by severity.
Secrets · Certs · Keys
Compute cost analysis
Identifies idle and underutilised Azure VMs, AWS EC2 and GCP Compute Engine instances from CPU and memory telemetry over 7-day windows. Reports estimated monthly waste in dollars, not percentages.
VMs · EC2 · Compute Engine
Endpoint monitoring
HTTP/HTTPS uptime checks with response-time tracking and SSL certificate expiry alerts. Downtime is logged by the minute, so there is a forensic record afterwards.
HTTP · HTTPS · SSL
Storage hygiene
Flags unattached managed disks, aging snapshots, and publicly readable Azure Blob containers, S3 buckets and GCS buckets — with estimated monthly cost and a link straight to the resource.
Blobs · S3 · GCS · Disks
Platform coverage
CloudMonitor has no single vantage point to watch from, because there isn't one. It walks all five platforms in turn, checking each resource on the way past and coming back around on a schedule — the 2 AM round, made so you can sleep through it. The table below is the route.
Coverage is uneven, and it would be misleading to present it otherwise. Azure and AWS are where the depth is; the rest are real but narrower and still growing.
| Platform | Depth | What's covered |
|---|---|---|
| Azure | Deepest | Key Vault, Storage, Compute, SQL, App Service, Container Apps, ACR, Cosmos DB, Defender, identity, NSGs, public IPs, VM security, end-of-life tracking, cost. |
| AWS | Broad | EC2, S3, RDS, IAM, ACM, Secrets Manager, Lambda, ECS, ELB, EBS, VPC/security groups, CloudTrail, CloudFront, GuardDuty, Security Hub, Route 53, DynamoDB, API Gateway, SQS/SNS, SSM, WAF. |
| GCP | Narrower | Compute Engine, Cloud SQL, Cloud Storage, IAM. Secret Manager is on the roadmap, not built. |
| Kubernetes | Narrower | AKS, EKS and GKE cluster checks. |
| MuleSoft | Narrower | Runtime health and alert configuration. |
How it connects
No agents to install and no policy changes. CloudMonitor connects with least-privilege read-only access — an Azure service principal, an AWS cross-account IAM role, or a GCP service account — and never needs write permission on anything it watches. Each customer's data sits in its own isolated tenant.
- 1
Grant read-only access
Per-platform onboarding guides walk through the exact role and scope, so you can review it before you grant anything.
- 2
Scanners walk the accounts, pass after pass
Every pass re-enumerates what is actually there, so findings describe the account as it stands rather than as it looked on the day you connected it. They are ranked by severity and estimated cost impact, not dumped as an undifferentiated list.
- 3
Alerts fire as new issues appear
Expiry thresholds, new public buckets, endpoints that stopped answering — surfaced when they happen rather than at the next audit.
Planned pricing
Sliding scale, priced per monitored resource, with every feature included on every plan and unlimited users. Nothing is billable yet — this is published so there are no surprises later, and it may still change before launch.
“The best monitoring tool is the one that catches the problem before your users do. CloudMonitor was built by someone who has been paged at 2 AM over an expired certificate.”
Cloud architect · 15+ years in the cloud
Your infrastructure deserves a second pair of eyes.
CloudMonitor is in early access and not yet open for signup. Leave your email and I'll get in touch when there's something worth your time — no drip sequence, no newsletter.