Self-Hosted · Open Platform · Enterprise Ready

Everything
your IT team
actually needs.

Uptime monitoring, security scanning, AI-powered infrastructure health, CVE tracking, breach detection, Cloudflare Fight Mode — unified in one platform. Deploy in minutes, own your data forever.

Coming Soon
Explore Features
Docker Compose deploy
No per-seat pricing
Your data, your servers
r9ops.com — Dashboard
api.production.com 99.98% UP
dashboard.myapp.io 100% UP
auth.internal.net 97.2% SLOW
payments-gateway.io 99.99% UP
cdn.staging.myapp.io 94.1% DOWN
24
Monitors
99.4%
Overall Uptime
3
Active CVEs
Security Watchlist — Recent CVEs
HIGH Nginx 1.18.x — CVE-2024-7347 2d ago
MED PostgreSQL 14.x — CVE-2024-4317 5d ago
LOW Node.js 18.x — CVE-2024-22019 1w ago
0
Monitoring modules
0
Integrations & tools
5
Deploy time with Docker
0
Per-seat cost, forever

One platform.
Every tool your team needs.

R9ops replaces 12+ separate tools with a single, self-hosted platform. From uptime checks to Cloudflare Fight Mode — it's all here, fully integrated.

Uptime Monitoring
Real-time monitoring for HTTP, TCP, DNS, keyword match, and API endpoints. Uptime and latency are measured on the visitor-facing path only — origin and secondary-URL checks stay as diagnostics so they can never distort your numbers.
HTTP/HTTPS TCP DNS Keyword Match API Checks SSL Expiry Smooth Monitoring
Public Status Pages
Public status pages with affected monitors, degraded performance indicators, past incidents timeline, and maintenance category badges (Planned, Emergency, Routine).
Affected Monitors Degraded Past Incidents Maintenance Badges RSS Feed Status Badge
Web Security Scanning
OWASP ZAP powered full, quick, and passive security scans. Every finding tagged with CVE and CWE references.
HIGH SQL Injection (CWE-89)
HIGH Missing HSTS Header
MED Clickjacking Possible
MED Weak CSP Policy
LOW Cookie Without Secure Flag
INFO Server Version Exposed
OWASP ZAP CVE/CWE Tags HTML Reports
Breach Detection
Monitor emails, domains, and passwords against HIBP, DeHashed, and NVD. Watchlist with recurring checks and instant alerts.
HIBP DeHashed NVD Watchlist
CVE Stack Watchlist
Watch specific technologies (e.g. "Apache Log4j", "Nginx") and get notified instantly when new CVEs are published in NVD.
NVD Feed Version Matching Email/Webhook
Multi-Channel Alerting
Instant notifications when your services go down, recover, or enter maintenance — via every channel your team already uses.
Microsoft Teams
Slack
Discord
Email (SMTP)
Webhooks
Power Automate
Adaptive Cards
Dependency Security
Scan Bitbucket repositories for vulnerable dependencies. Supports npm, Go, Python, Maven, NuGet, Ruby, Cargo via Trivy + OSV.
Trivy OSV Bitbucket 8 Ecosystems
Permission Management
Category-based Read/Write permission matrix for Monitoring, Security, Analytics, and Operations. LDAP/Active Directory SSO, per-user timezone, last-seen tracking, time-spent analytics, and a full audit log of every action.
Read/Write Matrix LDAP/AD Audit Logs 3 Roles
Dependency Tracker
Track every package change across your repositories. Get webhook alerts when dependencies are added, removed, or updated.
Package Changes Webhook Alerts npm/Go/Maven
Cloudflare Fight Mode
Block malicious IPs via Cloudflare Access Rules with a role-based approval workflow. Any team member can raise an IP block request — admins and operators approve with one click. Full IP intelligence shows country, ISP, ASN, and proxy/datacenter detection before you approve.
Pending Approval
185.220.101.47 🇩🇪 DE · Tor Exit
45.155.205.233 🇷🇺 RU · Datacenter
Recently Blocked
91.108.4.200 🇳🇱 NL · VPN
194.165.16.11 🇨🇳 CN · ISP
Cloudflare API Approval Workflow IP Intelligence Country / ISP / ASN Proxy Detection CSV Export Email Notifications
Multi-Location Check & Alerting
Run uptime checks from multiple geographic probe locations. Detect regional outages vs. real downtime with corroborated alerting — no more false positives from single-vantage blind spots.
Istanbul
67ms
Ankara
110ms
Multi-Region Active-Active Latency Compare Corroborated Alerts
InfraSight — AI Infrastructure Health
SSH into the nodes of any open-source cluster — Elasticsearch, RabbitMQ, Couchbase, Redis, Kafka and more — to collect logs, then analyze them with GPT-4 or Claude. The log timestamp format is detected from the log itself, so adding a new product needs no code change. Real-time health score, critical issue list, and cost-tracked AI run history — all in one place.
Node Status
es-node-01 · Healthy
rmq-node-02 · Warning
cb-node-03 · Healthy
Last AI Analysis
⚠ 2 warnings detected
High memory pressure on rmq-node-02. Consider increasing heap size.
AI cost: $0.0024 · 3 nodes analysed
SSH Log Collection Elasticsearch RabbitMQ Couchbase GPT-4 · Claude Cost Tracking
Multi-Location Speed Test
Run Lighthouse performance scans from multiple probe locations. Compare Core Web Vitals side-by-side across geographies to catch CDN and routing issues.
ISTANBUL
308ms
LCP
ANKARA
576ms
LCP
Lighthouse Core Web Vitals Regional Compare HAR Analysis
AI Visibility Analyzer
Score your websites for visibility in AI-powered search engines. Checks robots.txt AI bot permissions, JSON-LD schema stacking, Core Web Vitals, heading hierarchy, and meta quality — producing a GEO score across Technical, Content, AI Visibility, and Performance pillars.
Technical SEO90
AI Visibility (GEO)72
Performance95
GEO Analysis Core Web Vitals Schema Stacking AI Bot Access ChatGPT · Claude · Perplexity
Performance Auditing
Lighthouse 12.8.2 powered audits — real audit results, not scores estimated from timings. Core Web Vitals, LCP, FCP, CLS and TTFB tracking with performance budgets.
Performance94
SEO Score98
Accessibility88
Team KPI Deep Dive
Cross-platform team performance metrics from Jira, Bitbucket, SonarQube, and Argo CD. Pattern-based team grouping for focused analysis.
Jira Bitbucket SonarQube Argo CD
Compliance Reports
Generate SOC2 and ISO27001 compliance reports for any time period. One-click export and scheduled delivery.
SOC2 ISO27001 PDF Export

Full security stack.
Zero blind spots.

R9ops combines web security scanning, dependency analysis, breach monitoring, and CVE tracking into a single security intelligence layer.

🛡️

OWASP ZAP Web Scanning

Full, quick, and passive scans. Every finding tagged with CVE and CWE references, scored by severity.

📦

Dependency Vulnerability Scanning

Trivy + OSV CLI scans across npm, Go, Python, Maven, NuGet, Ruby, and Cargo ecosystems in Bitbucket repos.

🔍

Breach Watchlist

Recurring checks against HIBP and DeHashed for emails and domains. Alert instantly when credentials appear in a breach.

⚠️

CVE Technology Watchlist

Watch specific tech stacks for new NVD CVEs. Semantic version matching — get alerted only when your version is affected.

🔥

Cloudflare Fight Mode

Block malicious IPs via Cloudflare Access Rules with a role-based approval workflow. IP intelligence shows country, ISP, ASN, and proxy/datacenter status before you approve. Full audit trail, CSV export, and email notifications on approval.

Security Overview — Last 30 Days ● 3 Critical
CRITICAL
CVE-2024-7347 · Nginx 1.18.x
CVSS 9.1 · Buffer overflow in ngx_resolve_name_done
HIGH
CVE-2024-4317 · PostgreSQL 14
CVSS 7.5 · Privilege escalation via row security
MEDIUM
lodash 4.17.19 · package-lock.json
Prototype pollution · Fix: upgrade to 4.17.21
MEDIUM
ZAP Scan · admin.myapp.io
Missing HSTS · X-Frame-Options header absent
Breach Watchlist — Last Check
2
Breached emails
24
Clean emails
1
Domain flagged
Team KPI Dashboard — Q1 2025 ● Live
Deploy Frequency
4.2/day
↑ Elite performer
MTTR
48min
↑ High performer
Lead Time
2.1hrs
↑ Elite performer
Change Fail Rate
3.2%
↑ High performer
SonarQube — Code Quality
A
Reliability
A
Security
B
Maintain.
84%
Coverage

Understand your
team's performance.

SonarQube quality scores, Argo CD deployments, Bitbucket commit activity and Jira flow metrics — unified into one team KPI view.

📊

Team KPI Deep Dive — Jira + Bitbucket

Cross-platform team performance built from real ticket and commit data, with pattern-based team grouping for focused analysis.

🚀

Argo CD Deployment Insights

Read deployment activity directly from Argo CD sync events. Detect rollbacks, OOM kills, and deployment anomalies automatically.

🔬

SonarQube Integration

Pull code quality metrics — bugs, vulnerabilities, code smells, coverage — and track trends over time per team.

Know before
your users do.

Smooth monitoring prevents false alarms. Multi-channel alerting ensures the right person is notified, every time.

⏱️

Smooth Monitoring

Configurable delay thresholds plus automatic retry with backoff. Probe-side network blips — DNS, timeouts, connection resets — are classified separately from real HTTP failures, so they never count against uptime or wake anyone up.

🔔

Incident Management

Structured incident lifecycle from investigating to resolved. Link alerts to incidents, track updates, and manage severity.

🗓️

Maintenance Windows

Schedule planned maintenance to suppress alerts automatically. Teams get advance notifications and calendar events.

🌐

Public Status Pages

Transparent status pages with live uptime, active incidents, maintenance schedules, RSS feeds, and embeddable badges.

Alert History — Last 24 Hours 24 events
cdn.staging.myapp.io — DOWN
Teams + Email notified · 14:32
cdn.staging.myapp.io — RECOVERED
Downtime: 8 min · 14:40
Maintenance — auth.internal.net
Scheduled 20:00 – 22:00 · Alerts suppressed
SSL Expiry Warning — api.prod.com
Certificate expires in 14 days · Slack sent
Notification channels active
💬 Teams 🟢 Slack 🎮 Discord 📧 Email 🔗 Webhook

Works with your
entire stack.

R9ops integrates with the tools your teams already use — from project management to CI/CD to communication platforms.

Jira
Bitbucket
Argo CD
SonarQube
Microsoft Teams
Slack
Discord
OWASP ZAP
Trivy
HIBP
NVD / NIST
Wappalyzer
Lighthouse
LDAP / AD
Power Automate
Cloudflare

Your monitors,
on every screen.

Native desktop and mobile apps that talk to your own R9ops instance. You type in your server address — there is no R9ops cloud in the middle, and no account to create anywhere else.

macOS Menu Bar
Live status in your menu bar, and a popover with every monitor, incident notices and one-glance detail. Native notifications the moment something changes state. Your API token lives in the macOS Keychain, never in a plain file.
Signed .pkg installer Keychain-backed
Windows Tray
A tray icon that turns red before the phone call does. Click through to per-monitor detail, get a desktop notification on every state change, and install from a single signed executable.
Installer + portable .exe Desktop notifications
iOS
Dashboard, group and service detail, search and incident notices in your pocket. Native SwiftUI, signed in to your own server, showing exactly what the web dashboard shows.
Native SwiftUI Push-ready
Android
Coming Soon
The same app for Android, in development. The iOS feature set is the target: dashboard, service detail, search, incident notices and push on state change.
In development Same server, same login

Your data.
Your servers. Your rules.

R9ops is built to run inside your infrastructure. No data leaves your network. No vendor lock-in. No per-seat pricing surprises.

01
Data Sovereignty
All monitoring data, security scan results, CVE findings, and user information stays within your own infrastructure. Perfect for regulated industries and compliance requirements.
02
No Per-Seat Pricing
Deploy R9ops for your entire organization — 5 users or 500 — for the same cost. Add monitors, users, and integrations without watching a billing meter spin.
03
Enterprise Authentication
LDAP and Active Directory integration out of the box. Use your existing corporate identity provider — no separate user management needed.
04
Air-Gap Capable
Run R9ops in fully isolated environments. Configure optional external API connections (NVD, HIBP) only if your security policy allows — everything else works offline.
05
Compliance Ready
Built-in SOC2 and ISO27001 report generation. Full audit log of every action with IP addresses and user agents. Granular role-based permissions per module.
06
Docker Native
Deployed via Docker Compose with a single command. All services — backend, workers, database, frontend — fully containerized and production-ready out of the box.

IT tools your team
can replace with R9ops.

  1. 01
    Uptime Monitoring

    Replace standalone uptime tools like Better Uptime or UptimeRobot — HTTP, TCP, DNS, keyword, and API checks in one place.

  2. 02
    Web Security Scanning

    Replace dedicated DAST tools — OWASP ZAP full/quick/passive scans with CVE and CWE tagging, scored by severity.

  3. 03
    CVE Stack Watchlist

    Replace manual NVD monitoring — watch specific tech stacks with semantic version matching and instant alerts for new vulnerabilities.

  4. 04
    Breach Detection

    Replace manual HIBP checks — recurring watchlist monitoring against HIBP and DeHashed for emails, domains, and passwords.

  5. 05
    Dependency Security Scanning

    Replace standalone SCA tools — Trivy + OSV scans across npm, Go, Python, Maven, NuGet, Ruby, and Cargo in Bitbucket repos.

  6. 06
    Compliance Reporting

    Replace manual compliance workflows — automated SOC2 and ISO27001 report generation with one-click PDF export.

  7. 07
    AI Visibility Analyzer

    Replace manual GEO audits — automated website scoring for AI search engine visibility across ChatGPT, Claude, and Perplexity.

  8. 08
    Cloudflare Fight Mode

    Replace manual Cloudflare IP management — role-based approval workflow for IP blocking with full IP intelligence, audit trail, CSV export, and email notifications.

  9. 09
    Team KPI Deep Dive

    Cross-platform team performance metrics from Jira, Bitbucket, SonarQube, and Argo CD with pattern-based team grouping for focused analysis.

  10. 10
    Dependency Tracker

    Track every package change across repositories. Get instant webhook alerts when dependencies are added, removed, or updated.

  11. 11
    Permission Management

    Category-based Read/Write permission matrix. Control access per team role across Monitoring, Security, Analytics, and Operations.

  12. 12
    InfraSight — AI Infrastructure Health

    Replace manual log triage — SSH log collection from any open-source cluster, analyzed by GPT-4 or Claude into a health score and a ranked critical-issue list.

  13. 13
    Multi-Location Speed Test

    Replace separate synthetic testing tools — Lighthouse scans from multiple probe locations, with Core Web Vitals compared side-by-side across geographies.

  14. 14
    Desktop & Mobile Apps

    Replace a second status dashboard on every laptop — macOS menu bar, Windows tray and iOS apps that all point at your own server, with Android on the way.

Up and running
in under 5 minutes.

Deploy R9ops with a single Docker Compose command. Everything is included — database, backend, workers, and frontend. No infrastructure expertise required.

1

Clone the repository

Get the source from GitHub and copy the example environment file.

2

Configure environment

Set your SMTP, API keys, and database credentials in .env.

3

Launch with Docker Compose

All 11 services start automatically. Access the dashboard at port 3000.

bash
# Clone R9
$git clone https://github.com/your-org/r9ops
$cd r9ops
 
# Configure environment
$cp .env.example .env
$nano .env
 
# Launch all services
$docker compose up -d
 
Creating r9-postgres ... done
Creating r9-backend ... done
Creating r9-seo-runner ... done
Creating r9-security-runner ... done
Creating r9-breach-runner ... done
Creating r9-repo-runner ... done
Creating r9-frontend ... done
 
✓ R9 is running at http://localhost:3000
→ Default admin: admin / changeme

The platform your
IT team has been waiting for.

Stop juggling 12+ different tools. R9ops gives your team everything they need to monitor, secure, and optimize your infrastructure — in one self-hosted platform.

Coming Soon
Self-hosted · No credit card · No per-seat pricing