FAQ
Questions and answers
How Site Monitor checks your websites, where alerts go, and how plans and billing work. Setting up for the first time? Follow the step-by-step guide.
Getting started
What is Site Monitor, and who is it for?
Site Monitor checks your websites around the clock and alerts you when one goes down, starts returning errors, comes back up or has an SSL certificate close to expiry. It is built for web agencies and freelancers who look after client websites, with branded emails and public status pages on the plans that include them.
How do I get started?
Create an account; you don't need a card. You land in a short setup guide that shows where alerts will go and lets you send yourself a test alert, and then you add your first website on the Dashboard. Our step-by-step guide covers the rest in ten steps.
How does the free trial work?
Every new account gets 14 days of the Agency plan free, with no card needed, and we email the account owner about 3 days before it ends and again on the day it ends. If you choose a plan during the trial, nothing is charged until the trial ends. If you don't, monitoring keeps running for 3 more days and then pauses. Your websites, history and settings are kept, and choosing a plan starts monitoring again.
Monitoring
How often are websites checked?
Every website is checked about every 2 minutes by default, the fastest setting on every plan, and Edit lets you slow a website down to every 5, 15, 30 or 60 minutes. When a website that was up, or has not been checked before, fails a check, we check it again up to 2 more times about 8 seconds apart before anyone is alerted, when there is time. If a re-check succeeds, no alert goes out.
What counts as up, error and down?
A check follows redirects like a browser and judges the final answer. UP means a status code below 400, and ERROR a 4xx code such as 404, where the server answers but the page is broken. DOWN means a 5xx code, no answer within the website's timeout (10 seconds unless you change it with Edit), a connection or certificate failure, or a chain still redirecting after 10 requests. A Cloudflare or Sucuri bot challenge counts as up, with a note that the site is bot-protected.
Do you warn me before an SSL certificate expires?
Yes. For https websites we read the certificate at most every 6 hours, show the days left on the Dashboard, and send an alert to the same people and channels as an outage alert when the days left reach 14, 7 and 1, once at each mark. A certificate that has expired or is not valid also makes the regular check fail, so the website shows as down.
What do your checks look like to my server?
Each check is a normal GET request with a desktop Chrome user agent and ordinary browser headers, and it keeps cookies across redirects the way a browser does, so most firewalls treat it like a visitor. It does not name Site Monitor anywhere, so a firewall can't pick it out by its user agent. We record the status code, response time and any error, not the page's content.
Why was my web address refused?
Our servers make the requests, so we refuse addresses that lead to private or internal networks, such as localhost, private IP addresses, cloud providers' internal addresses and names ending in .local or .internal, and anything that is not http:// or https://. The same rule covers every redirect a check follows, Slack and webhook addresses and your own SMTP server. The message you see for a private address is “Checks to private or internal network addresses are not allowed”.
How many websites can I monitor?
Practice monitors up to 3 websites, Agency monitors up to 25 websites and Agency Plus monitors up to 100 websites. The limit counts every website on the account, paused ones included, so adding one more is refused until you remove one or upgrade. After a move to a plan with fewer websites, the ones you added first keep running and the rest show Paused · plan limit until you upgrade, or pause or remove some. For more than 100 websites, email support@concepcion.work.
Alerts
Where can alerts go?
Down, error, recovery and SSL alerts go by email on every plan, and can also go to Slack, a ClickUp Chat channel and your own signed webhook, which you set up under Settings → Alert channels. On Agency and Agency Plus, emails carry your logo or account name instead of our brand, and you can send them through your own SMTP server under Settings → Email delivery so they come from your domain.
How do signed webhooks work?
For every alert we POST a JSON body with event, site, health, error, since, durationMs, at and account. Each request has an X-SiteMonitor-Event header and an X-SiteMonitor-Signature header, a hex HMAC-SHA256 of the raw body made with the signing secret shown under Settings → Alert channels once you save the address. It must be a public https:// address, and anything other than a 2xx answer within 5 seconds counts as a failed delivery.
How do I test my alerts?
Send test alert on the Dashboard, or in the setup guide, emails a test to your own address through the same path a real alert takes. Send test to all channels under Settings → Alert channels also posts to Slack, ClickUp and your webhook, and shows the result for each channel. If the email doesn't arrive, check your spam folder.
What happens if an alert can't be delivered?
If no channel delivers an alert, we keep it and try again at the website's next check at least 5 minutes later, up to 12 attempts in all. If at least one channel delivers it, the failed channels are not retried, and the Dashboard marks the website alert failed with the reason. Changing who is notified for the website gives a stuck alert a fresh set of attempts, and if your own SMTP server fails we send that email through our built-in sender instead.
Who gets notified for each website?
Each website's Notify row on the Dashboard decides who gets its emails: Everyone (the default for a new website) means the whole team, or untick it and pick people by name. You can add other addresses there too, such as a client's. Slack, ClickUp and webhook alerts go to the account's channels for every website, and Bulk edit all changes recipients for all websites at once.
Team and security
How do I add teammates?
The account owner adds each person under Settings → Team with a name, email address, username and password, then presses Add user. We don't send an invitation, so give them their username and password yourself and ask them to change the password on their Profile page. Practice includes 3 team members, including you; Agency and Agency Plus have no limit.
What can team members do?
There are two roles. The owner, who created the account, manages the team, the account name, alert channels, email delivery, branding, the status page's address, the report schedule, data retention, billing and account deletion. Members can sign in, add, edit, pause and remove websites, choose who is notified and which websites appear on the status page, send test alerts and reports, and manage their own profile and two-factor authentication.
Do you support two-factor authentication?
Yes, for every user. On your Profile page press Set up two-factor, scan the QR code with an authenticator app and enter the 6-digit code; you then get 8 one-time backup codes to keep somewhere safe. From then on, signing in asks for a code from the app after your password. Each person turns it on for their own login.
What if I forget my password?
Choose Forgot password? on the sign-in page and enter your email address; we send a reset link that works once and expires after 30 minutes. Setting a new password signs you out on every device, and if two-factor is on you still need your code. The account owner can also set a new password for a team member with Edit under Settings → Team.
What if I lose the phone with my authenticator app?
Sign in with your username and password, then enter one of your backup codes instead of the app's code; each works once. On your Profile page, use Turn off and then set two-factor up again on your new phone, or press Regenerate backup codes for a fresh set. Without the app or a backup code, email support@concepcion.work from the address on your account and we will confirm it's you before we help. A locked-out teammate can also ask the account owner to remove and re-add their login.
Reports and status pages
Can I email uptime reports to my clients?
Yes. Under Settings → Reports & data → Scheduled email reports, choose Daily, Weekly (Mondays) or Monthly (1st), list the recipients (the whole team gets it if you list none) and press Save schedule; each report covers the day, week or month just finished, with uptime, incidents and average response time for every website on the account. Your logo, saved under Branding & status page, appears on emailed reports, and on Agency and Agency Plus the whole email carries your brand instead of ours. The Reports page shows the same history as charts or a Calendar, and Email this report sends the dates and websites you pick to the same recipients.
Do you offer a public status page?
Yes, on Agency and Agency Plus, with one status page for each account. Under Settings → Branding & status page, choose the page's address and an optional title, press Save, then tick Show on status page for each website it should list. The page shows each listed website's current status and daily uptime bars, refreshes itself every 60 seconds, and shows nothing about your recipients or alert settings. The same data is available as JSON for embedding.
How long is check history kept?
Practice keeps 30 days, Agency keeps 90 days and Agency Plus keeps 90 days of check history. Under Settings → Data retention you can keep less, and older data is deleted automatically as checks run. After a move to a plan that keeps less, the older history is hidden and deleted 7 days later unless you upgrade again.
Plans and billing
What do the plans cost?
Practice is $19 a month or $190 a year, Agency is $49 a month or $490 a year and Agency Plus is $99 a month or $990 a year, so a year costs the same as 10 months. Prices are in US dollars and exclude tax: Stripe calculates any tax due from the billing address you enter at checkout, where you can also add a tax ID. The pricing page shows what each plan includes.
How do I start paying?
The account owner opens Settings → Plan & billing, picks Monthly or Yearly, presses Choose and the plan's name, checks the summary of what will keep running and presses Continue to Stripe. You pay on Stripe's checkout page and come back to Settings when it's done. If you choose during the free trial, nothing is charged until the trial ends.
How do I change plan or cancel?
In Settings → Plan & billing, use Switch to for another plan or billing period: an upgrade charges the prorated difference straight away, and a downgrade turns the unused time into credit on your next invoice. Cancel keeps your plan until the end of the period you've paid for, and Keep my plan opens Stripe's billing portal, where you can renew before then. Manage billing opens Stripe's billing portal for your card and invoices, and refunds are covered by our Refund Policy.
What happens if a payment fails?
Settings → Plan & billing shows Past due and Stripe keeps retrying the charge for 7 days while monitoring carries on; press Update card or Pay invoice to settle it. If it stays unpaid, monitoring pauses. Your websites, history and settings are kept, and choosing a plan again starts monitoring again.
Data and privacy
What data do you keep about my websites?
For each website we keep its address and settings, its latest check results (up, error or down, the status code, response time and any error message) and daily summaries for reports and status pages, which are kept for your history period. We don't store the content of your pages. The Privacy Policy, Security page, DPA and list of subprocessors cover everything else, including account and billing data.
How do I delete my account?
The account owner opens Settings → Cancel account, presses Cancel and delete my account…, confirms with their password and presses Delete everything. That cancels any subscription at once, with no refund for the unused time, and deletes the account's users, websites and history; it can't be undone. To remove one teammate instead, press Remove next to their name under Settings → Team.
Reliability
What availability do you commit to?
Our Service Level Agreement commits to 99.5% monthly availability for the app and for starting scheduled checks, measured at a public health check. If we miss it, accounts on a paid plan can claim a service credit within 30 days after the month ends. The SLA page sets out how availability is measured, the credit for each level and what is excluded.
Troubleshooting
Why am I not getting alerts?
Press Send test alert on the Dashboard and check your spam folder. Then check the website's Notify row: Everyone or your name must be ticked, or your address added. An alert failed note or an Alert emails are not being delivered box on the Dashboard gives the reason, and a banner there tells you if monitoring is paused because a trial ended or a payment is overdue.
Why did I get an alert when my site looks fine?
The alert and the Dashboard show what the check saw, such as an HTTP status code or a timeout. Common causes are a slow page (give it a longer timeout with Edit), a firewall or rate limit that answered our check differently from a visitor, or a network problem between our servers and the site: all checks run from a single cloud region, so we can see a problem that visitors elsewhere don't. We re-check a failing website before alerting, so one dropped request rarely causes an alert.
What if my site's firewall blocks your checks?
A Cloudflare or Sucuri bot challenge is recognised and counted as up, but other blocks make the website show ERROR or DOWN. Our checks use an ordinary browser user agent and we don't publish a list of IP addresses, so ask whoever runs the firewall to let requests for the monitored page through, or monitor a page the firewall leaves open.
Why can't I add a team member?
Only the account owner can add people, under Settings → Team. Practice includes 3 team members, including you; upgrade for unlimited members. Each email address and username can belong to only one login across the whole service, and the password must be at least 12 characters and not a common or breached password.
How do I get help?
Email support@concepcion.work. Customers on Agency Plus get priority support, and our reply-time targets are on the SLA page. For setup, the step-by-step guide walks through everything from your first website to two-factor sign-in.
Still stuck?
Email support@concepcion.work, or work through the step-by-step guide from the start.