lbreeze

Quiet until it matters. Ready the moment it does.

Observability, on-call, security operations and host management in one platform — watching every machine you run, so the night something breaks you are reading a page instead of building one.

See plans

One agent, on everything you run

Debian, Ubuntu, RHEL and SUSE

The full surface: metrics, logs, package inventory, backup state and security events.

Alpine

A musl build under OpenRC, treated as a first-class target rather than an afterthought.

Windows

Metrics, logs and backups reporting from Windows endpoints alongside the Linux fleet.

Honest about gaps

Where a platform genuinely cannot do something it says so, rather than showing a green tick over a hole. A blank panel means the host is dark, not quiet.

When something breaks

From signal to a person who can fix it.

Alerting is the easy half. The hard half is making sure it reaches someone awake, with enough context to act, and stops when it is handled.

01 · It is noticed

Threshold alerts, service checks and heartbeats — the inverse probe that fires when something stops reporting, which is how silent failures surface.

02 · It is routed

Escalation chains by severity and label, with on-call schedules, overrides and silences so a known maintenance does not wake anyone.

03 · Someone is paged

A step can target several people at once with a paging strategy, so “whoever answers first” is a real option rather than a single point of failure.

04 · It becomes a record

An incident with its timeline, the runbook that applied, and the evidence of what was done — which is what you need afterwards, not during.

Security operations

CVEs matched to what is actually installed

Each host reports its real package inventory, correlated against advisories for Debian, Ubuntu, RHEL, SUSE and Windows. A stale inventory is refused rather than matched.

Known-exploited first

KEV-flagged findings drive a detect-to-fix loop with the package upgrade that closes them, so triage starts with what is being exploited rather than with the longest list.

A threat feed with triage built in

Failed-auth floods, SQL injection and webshell detections in one queue you can acknowledge, assign, resolve or mark false-positive, in bulk.

One-click response

Block an address, quarantine a file, run a scan or open an incident — as signed commands to the agent. Rules can do it automatically above a severity you choose.

Managed web application firewall

Rules deployed and kept applied across the whole estate from one place, with per-host exclusions where a platform needs them, and coverage pushed rather than merely reported.

Fleet-wide address intelligence

Hover any IP anywhere in the product and see whether the rest of your estate has seen it too.

Proof, not assumptions

Backups that have been restored

Snapshots are verified and restore drills actually replay them. A backup that has never been proven is reported as never proven, with the reason, instead of counting as a green tick beside one that has.

Compliance evidence from operation

Evidence is drawn from what the system is doing, not from what it is configured to do. Monitoring counts when it reports; a privileged session counts because the recording exists.

A public status page

Components, incidents and maintenance windows on their own site, with a double-opt-in subscribe list, RSS, and a WCAG 2.1 AA pass — so it is readable by everyone on the worst day.

High availability and recovery

A Postgres streaming replica you can mint on demand, a dedicated backup host, and an operations handbook covering architecture, ports and egress.

Service management

Incidents carry through to the rest of the job.

Ticket queues, a request catalogue, problem records linking repeat incidents to a root cause, and SLA policies with breach flags — structured along ISO 20000 rather than invented.

Frequently asked questions

Do I need Zephyr to use Standby?

No. Standby runs on its own. If you run both, Standby holds the physical facts about your estate and Zephyr the commercial ones, and they exchange them rather than each keeping a half-right copy.

Does it work on Windows?

Yes — metrics, logs and backups all report from Windows endpoints, alongside Debian, Ubuntu, RHEL, SUSE and Alpine. Where Windows cannot report something the way Linux does, the product says so rather than showing a false green.

Is this a monitoring tool or an incident tool?

Both, deliberately. A monitoring tool that cannot page anyone and an incident tool with no telemetry are each half a product, and the seam between two vendors is where the 3am confusion happens.

Where does the vulnerability data come from?

From a dedicated ingestion platform that normalises advisories across distributions, matched against the package inventory each host actually reports.

How is it priced?

Per device. The count comes from the devices actually reporting, so it follows your estate rather than a number you have to remember to update.

Start with the hosts you would miss.

Put the agent on a handful of machines that matter and let it run for a week. The useful conversation is about what it found, not about what it could find.

Book a walkthrough