Founder deal Lifetime access for $149. First 50 builders only. Claim your seat →
Monitoring for people who ship fast

Know the second
something breaks.

Failed logins, error spikes, bots, downtime. AlertRelay watches for the things that matter and tells you. Your agent sets it up.

Start free See how it works →
Free plan, no credit card. Setup is one paste into your agent.
AlertRelayCritical
Failed-login spike
my-saas · 2 minutes ago
Matched47 events in 10 min
ip203.0.113.9
targetadmin@my-saas.com
ResolveView details
What this usually means. Someone is running a password list against you. Rate-limit the login route and back off after repeated failures.
Set up by the tools you already build with
Claude Claude Code Cursor Cursor Windsurf Windsurf Replit Replit Lovable Lovable v0 v0 + any MCP client

Setup is a conversation.
Not a settings tour.

Connect AlertRelay to your agent once. Then just say what you want watched, and it wires the whole thing into your code.

claude — via MCP
> set up security monitoring for my app
 
⏺ alertrelay · create_project ✓ my-saas
⏺ alertrelay · enable_security_pack ✓ 9 alerts on
⏺ editing src/auth/login.ts ✓ failed_login wired
⏺ alertrelay · test_alert ✓ sent to your inbox
 
Done. You'll get an email the moment anything trips.

Everything it watches.
Nothing you configure.

One call turns all of this on. You do not have to know what to pick, or what any of it means.

Break-in attempts

Failed logins, credential stuffing, password-reset abuse, new-device sign-ins, and someone quietly being made an admin.

Your app falling over

Errors and critical events spiking, checkout throwing, background jobs failing silently in the middle of the night.

Bots and probing

Signup floods, scanners walking your routes, a pile of blocked requests that means somebody is looking for a way in.

Total silence

The failure most tools miss. If your app stops checking in we alert you, because a dead app cannot report that it died.

Every alert says what to do

A plain-language note on what the pattern usually means and what to change. A 3am email is actually useful at 3am.

On-call, if you want it

Put one person on overnight and another on weekends. An uncovered hour alerts everyone, so a rota never causes silence.

How it actually works

Three steps, and your agent does two of them.

01

Connect it to your agent

One MCP link, pasted into Claude Code or Cursor. That is the only thing you personally have to do, and it takes about ten seconds.

$ claude mcp add alertrelay
02

Say what you want watched

"Set up security monitoring for my app." Your agent creates the project, turns on the alert pack, adds the fire-and-forget calls to your code, and sends a test so you see one land in your inbox.

03

Get on with your day

Nothing to check, nothing to babysit. Alerts arrive by email or webhook only when something actually needs you, throttled so a bad night can never flood your inbox.

Free covers most people.

If you are one person watching one app, free is the whole product. Pro is for watching a lot, or for a team that leans on you.

Free
$0
forever
  • 1 project
  • 10,000 events a month
  • The full security pack
  • 2 custom alerts
  • Email and webhook alerts
  • Dead-man switch
  • Full MCP and API access
Start free
Pro
$15 / mo
or $108 a year
  • 25 projects
  • 250,000 events a month
  • Payments, Email and API packs
  • Unlimited custom alerts
  • On-call scheduling
  • Alert teammates, not just you
  • 90 days of history
See Pro

MCP and the API are never paywalled, and we never limit the alerts that actually fire.

FAQ

The stuff people actually ask.

I am not a security person. Is this for me?
That is exactly who it is for. You pick nothing and configure nothing. One call turns on a set of alerts that catch the common ways small apps get hurt, and every alert explains what it means and what to change.
What do I actually do to set it up?
Paste your MCP link into Claude Code or Cursor and say "set up security monitoring for my app." Your agent does the rest and sends a test so you watch one arrive. Prefer to do it by hand? It is a single fire-and-forget POST, and the snippet is on your project page.
Will this slow my app down or break it?
No, by design. The call is fire-and-forget, so it never sits in your request path, and our ingest endpoint never returns an error into your app. Worst case an event gets dropped. Your app never breaks because of us.
What if my app goes down completely?
That is the dead-man switch. Your app pings a URL on a schedule, and if the pings stop we alert you. It is the one failure an event tool cannot otherwise catch, because a dead app cannot send an event saying it died.
Will a bad night flood my inbox?
No. Every alert is throttled. The first sends immediately, repeats inside the window get rolled up into the next message as "+42 more." An attack cannot mail-bomb you.
I just have a static site or a contact form.
Then there is nothing here to monitor and you should not pay us. You want FormRelay, our sibling tool, which catches form submissions and emails them to you.

Ship it. We will watch it.

Free plan, no credit card, and your agent can do the setup while you get on with something else.

Get started free