netwatch ~ ~/fleet.tsxmetro · 244 hosts● live
live fleet topology

Your network is
a living thing.
Watch it breathe.

Hundreds of hosts, thousands of flows, every dependency drawn in real time. Hover any node to trace what it talks to — and see congestion the moment it forms.

↪ hover a node to trace its dependencies
coredatacenteredgecongested
The problem

Observability got heavy. Your hosts paid for it.

01 — agent sprawl

One daemon becomes nine

A collector, a forwarder, a sidecar, a config-reloader. Each one a process, a port, a CVE surface, a thing that wakes you at 3am. We ship one static binary.

02 — per-host pricing

Your bill scales with your fleet

The tools that charge per host punish you for growing. Monitoring 400 hosts shouldn't cost more than the hosts. The free tier covers real fleets.

03 — data egress

Your packets, their cloud, your invoice

Most platforms ship every metric off-box by default and bill the egress back to you. Our OSS agents are read-only and phone home to nothing.

Live demo

Watch a real fleet, live.

Inside the dashboard — interfaces, packets, topology, and an anomaly caught in plain English. No narration, no edits.

app.netwatchlabs.com/fleet● live demo · no audio
How it works

Agent, ingest, dashboard. That’s the whole diagram.

01

Drop the agent

One curl on each host. A 5 MB static Rust binary reads /proc and the socket table. No root, no config file.

02

It streams to ingest

Metrics flow over a single outbound TLS connection — bandwidth, RTT, loss, DNS, per-connection topology. Nothing inbound to firewall.

03

You watch it live

The dashboard renders the fleet at one-second resolution. Self-host the ingest, or use NetWatch Cloud. Your data exports as JSON, always.

edge-fra-01agent v1.4 · 5 MBapi-iad-07agent v1.4 · 5 MBdb-replica-03agent v1.4 · 5 MB…241 more hostsingestTLS · outbound onlyself-host or clouddashboard1s resolutionexports JSONTLS · read-onlypush
Principles

Stated as guarantees, not aspirations.

Read-only by default

The agent observes. It never writes to your host, opens a listener, or executes anything. Mutation isn't a setting we ship.

Single static binary

5 MB, no runtime, no dependencies, no daemon tree. Drop it in, delete it clean. Works the same on a Pi and a 128-core box.

No telemetry in OSS

The open-source agent phones home to nothing. We find out you exist when you star the repo, and not before.

MIT agents, exportable data

Agents are MIT — fork them. Everything the dashboard holds exports as JSON. No format lock-in, no hostage data.

Enterprise

Controls your security team will ask for.

NetWatch sees the connections your hosts open and the processes that opened them. That is real visibility into real people’s activity, so the controls around it are on by default — not gated behind a sales call.

Two-factor authentication

TOTP with single-use time steps, ten hashed recovery codes, and enforced session eviction when it is switched on.

Role-based access control

Owner, admin, member, viewer. Viewers are strictly read-only. Role changes take effect on the next request, not at token expiry.

Append-only audit log

Sign-ins, key issuance, host deletion, role changes, consent, export. The table rejects UPDATE and DELETE at the database level — nobody edits it, including us.

Recorded risk consent

Every user acknowledges the monitoring disclosure before their account exists. Each record stores the version and a SHA-256 of the exact text shown.

Revocable sessions

Refresh tokens are hashed, rotated on every use, and listable with IP and user agent. Replaying a rotated token revokes the whole chain.

Attested packet capture

Off by default per host. Turning it on needs a named admin to attest authority over that specific machine. Metadata-only, always redacted, fully audited.

Export and deletion

Owners export the whole workspace as JSON and can schedule deletion with a grace period. Consent and audit records survive as evidence.

No per-seat pricing

Invite your whole team. Enterprise controls are not a tier you upgrade into — they are on for every account, including free ones.

No SOC 2 and no SAML yet, and we say so on the security page rather than waiting for the questionnaire.

Where it fits

The honest comparison.

No straw men. These are good tools — they’re just built for a different trade-off.

 
NetWatch
Datadog
Uptime Kuma
PRTG
time to first host
2 min
30+ min
15 min
1+ hr
agent footprint
5 MB static
~250 MB
external
~300 MB
per-host pricing
none
$15+/host/mo
none
license tiers
data egress
zero by default
metered off-box
n/a
n/a
self-host
yes, unlimited
enterprise only
yes
yes
open source
MIT agents
no
yes
no
mfa + rbac + audit log
free tier
paid tiers
no
paid tiers
Pricing

Free while we grow.

Free while we grow.

Every feature, unlimited hosts, no card. We’re building NetWatch in the open and it’s free while we do. When that changes you’ll hear it from us first — not from an invoice.

No per-host pricing. No “Contact sales” wall. No usage-based surprise invoice. MFA, RBAC, the audit log and data export are included — security is not an upsell.