The safety net for your
agency's infrastructure.
Uptime, TLS/SSL, DNS, and AI-visibility monitoring built for agencies. Merlonix watches the things that take a client site down even when it looks “up” — expiring SSL certificates, DNS records that quietly change, and outages at vendors like Stripe or Cloudflare. Every client in one dashboard, so you hear about it before they do.
Trial unlocks the full workspace for 14 days; Free is yours forever — 3 assets, 5-minute checks, email alerts. No credit card either way. See how it works · Run a free instant check.
- Fastest check interval
- 1 min
- Encrypted DNS lookups
- DoH
- Upstream vendors watched
- 11
- Always-on monitoring
- 24/7
Agencies monitoring clients on
- WordPress
- Shopify
- HubSpot
- Webflow
- Squarespace
- Vercel
Public status page
Every agent we run, alive or degraded — out in the open.
Vendor monitoring, transparent
The 11 vendor status pages we watch — and what we saw last.
Free plan or 14-day trial. No card required.
Start free on 3 services, or trial the full workspace for 14 days.
We run Merlonix on our own sites
We run Merlonix on our own live sites — the exact same checks you'd get: expiring certificates, DNS changes, and uptime.
The gaps between other monitors
The failure modes standard uptime monitors miss.
Standard uptime monitors check whether a URL returns a 200 OK. Merlonix watches the infrastructure underneath: SSL certificate validity, DNS record drift, and upstream vendor status. These are the silent killers that standard monitors miss.
Expired silently
SSL certificates
Let's Encrypt renewals fail. Manually-installed wildcards lapse. Chains break after an upstream CA rotation. You find out when a client's checkout stops working.
Drifted quietly
DNS records
Someone ran a migration. Someone deleted an A record. Someone flipped a CNAME. Now a subdomain resolves to nothing and nobody at the agency knew until the client called.
Degraded upstream
Vendor status
Stripe is having a partial outage. Cloudflare's DNS in one region is flapping. Shopify's admin is intermittent. Your team learns on Twitter.
How it works
Alert-first workflow. Zero daily checking.
Merlonix is designed to be invisible until you are needed. We handle the plumbing so you can focus on your clients, not your monitors.
01
Prove you can watch each domain (once)
You confirm you're authorized to monitor a domain — a quick text record, DNS entry, or file upload. We sign and store that proof, so monitoring always stays on the right side of the line between watching and snooping.
02
We check as often as every minute
We read each site's live security certificate and compare every DNS record against what you expect — resolving each record over an encrypted DNS-over-HTTPS lookup. Before we page you on a uptime failure we re-probe to confirm it's real, not a transient blip. We also watch 11 major vendors' status pages, so you're covered there too.
03
AI triages before we alert
AI sorts every signal first — real issue, false alarm, or just informational — so you're not woken for noise. Anything it's unsure about skips the AI and goes straight to your team. Nothing fails silently.
04
Deliver to where you already are
Get alerts where you already work — email, Slack, or piped into your own tools. Acknowledge, snooze, or resolve right from the alert. No "log in to the dashboard to find out what broke."
See it in action
Every client's infrastructure, one workspace.
Real screens from the Merlonix workspace — the dashboard you open each morning, the alerts we surface, and the branded status page your clients see.

The dashboard — an at-a-glance read on every asset you watch.

Alerts — with a recommended action, not just a red dot.

A branded status page your clients can check themselves.
Walk the workspace with sample data — no signup, no login.
Vendor-aware alerting
Your provider's outage shouldn't wake your on-call.
Most monitors page you the moment your site looks down — even when the real cause is AWS, Cloudflare, or Stripe having a bad day. Merlonix watches the status pages of 11 major providers and, when one of the ones your site depends on is in a live incident, holds the page: the alert still shows in your dashboard, attributed to the provider — but nobody gets woken up for an outage they can't fix. Planned maintenance you didn't expect still reaches you, and nothing is ever hidden.
AI answer presence
Know how AI answers describe you.
Buyers increasingly ask an AI assistant “who does X?” before they ever reach a search results page. Merlonix tracks the questions that matter to you and your clients, asks public AI answer engines on a weekly cadence, and checks whether they cite the brand and get its facts right— alerting you when that drifts.
Perplexity and ChatGPT are both live, and each engine runs independently. We report what the engines currently say — we don't promise to change it. Included on Agency and Compliance.
Beyond uptime
What we watch that a 200 OK never tells you.
A standard uptime monitor confirms a URL loads. Merlonix watches the infrastructure and reputation layers underneath — the certificates, DNS chain, registrar controls, silent jobs, security headers, and even how AI describes you. Each of these is a live check you can turn on.
Security headers
Continuous checks on HSTS, CSP, and cookie flags — you get alerted when a security header regresses in production, not just a one-time scan score.
DNSSEC & DANE
Watches the DNSSEC chain and DANE/TLSA records so you're paged the moment a zone is downgraded or a signature is dropped — a takeover precursor uptime monitors never see.
Domain-hijack & registrar lock
Surfaces registrar-lock (EPP) status and alerts on the nameserver and registrar changes that precede a domain hijack. No uptime or security scanner watches this.
Cron & heartbeat
A dead-man's switch for cron jobs, backups, and pipelines: your job pings a URL when it runs, and we alert when the ping goes silent.
Vendor-aware alerting
Holds the on-call page when the real cause is a provider — AWS, Cloudflare, or Stripe — in a live incident, so nobody is woken for an outage they can't fix.
Alerting & on-call
Route alerts to email, Slack, Teams, Discord, Telegram, Google Chat, a webhook, SMS, PagerDuty, or Opsgenie — then run on-call rotations and escalation policies so the right person is always paged.
AI answer presence
Tracks whether public AI answer engines cite your brand and get its facts right on a weekly cadence — and alerts you when that drifts.
AI agent-readiness
Grades whether AI agents and answer engines can read — and now call — your site: crawler access, structured data, llms.txt, and MCP endpoints. Free to scan; monitored for drift on a paid plan.
Certificate Transparency
Watches public CT logs for certificates issued for your domain and alerts on an issuance you did not expect — a rogue or shadow cert an uptime monitor never sees.
Blocklist / DNSBL
Continuously checks your mail and web IPs against DNS blocklists so you find out you're listed before your email starts bouncing — not from a customer complaint.
AI content safety
Scans your rendered pages for hidden prompt-injection text aimed at AI crawlers and assistants, and alerts when a page turns injection-likely — detection, not a blocker.
Core Web Vitals
Tracks lab Core Web Vitals over time and alerts on a real regression — a score drop or a good→needs-work bucket change — instead of a one-off Lighthouse run.
MCP server health
The first uptime monitor that speaks the Model Context Protocol: it runs a real initialize handshake and tools/list, then alerts on downtime, a failed handshake, latency, and silent tool-schema drift that breaks every agent. Free to check; monitored on a paid plan.
OpenAPI → MCP converter
Turn a REST API into a server AI agents can call: paste an OpenAPI or Swagger spec and get MCP tools, a .well-known/mcp.json manifest, and a runnable server — then a readiness grade that scans for tool-poisoning before you hand it to an agent. Free, no signup.
Broken links & mixed content
Check any page for dead links (404s, timeouts, unreachable targets) and insecure mixed-content resources instantly — free, no signup. On a paid plan, Merlonix crawls the whole site weekly and alerts the moment a new link breaks.
Certificate expiry
Check any domain's TLS certificate expiry date and days remaining instantly — free, no signup. On a paid plan, Merlonix tracks expiry across every domain you run and alerts well before the 47-day renewal cliff bites.
Zapier, Make & n8n
Send Merlonix events — SSL expiry, DNS changes, incidents, and alerts — into Zapier, Make, n8n, or any tool in real time via signed webhooks, or pull them from the REST API. Wire monitoring into the workflows you already run.
MCP server for AI agents
Connect Claude Code, Claude Desktop, or any MCP client to the Merlonix MCP server and let your AI agent query live SSL, DNS, domain health, AI agent-readiness, and vendor status directly. Read-only, no API key required.
Pricing
One flat fee per month. Every client included.
No per-seat upsells. No per-check metering. Pick the tier that fits your asset count and move on.
Starter
For solo operators watching a handful of clients.
$19/ month
- 15 monitored assets
- 3 seats
- 5 min check cadence
- Webhook, Slack, Teams & Discord alerts
- REST API + bulk import included
Team
For small agencies that need faster checks and more seats.
$79/ month
- 60 monitored assets
- 10 seats
- 1 min check cadence
- All alert channels — incl. SMS & on-call (PagerDuty, Opsgenie)
- REST API + bulk import
Agency
For the agencies that can't afford an outage they didn't see.
$199/ month
- 250 monitored assets
- Unlimited seats
- 1 min check cadence
- All alert channels — incl. SMS & on-call (PagerDuty, Opsgenie)
- REST API + bulk import
- Priority support
Compliance
For agencies serving HIPAA / SOC 2 / PCI verticals with audit obligations.
$699/ month
- Everything in Agency
- 13-month evidence retention
- Per-control compliance dashboards
- Evidence-pack export
- Read-only auditor seats
- Quarterly audit-prep email
Need SSO/SAML, white-label, or a custom annual contract? Talk to us about Enterprise →
Common questions
What agencies ask before signing up
Do I need DNS access to add a client domain?
No. Merlonix supports DNS TXT record verification (if you manage DNS) and HTTP file verification (if you only have hosting access). The HTTP method requires dropping a single text file into .well-known/ — no DNS credentials needed.
How is this different from uptime monitoring (Pingdom, UptimeRobot, etc.)?
Uptime monitors check whether a URL returns a 200 OK. Merlonix watches what they miss: SSL certificate validity and expiry dates, DNS record drift, and upstream vendor status. These are the failure modes that generate client calls after a normal uptime monitor shows green.
Which upstream vendors do you watch?
Stripe, Cloudflare, Shopify, Vercel, GitHub, Slack, AWS, Azure, Google Cloud, Anthropic, and OpenAI — 11 vendors in total. Need to monitor a specific vendor? We accept requests for new status page integrations via the dashboard.
What happens when the 14-day trial ends?
You choose a plan and enter billing. There is no automatic charge at trial end — if you do nothing, your account becomes read-only until you add a payment method. Cancel any time.
Can I monitor domains my clients own, not me?
Yes — that is the primary use case. Merlonix’s attestation system (DNS TXT or HTTP file verification) proves you have a legitimate relationship with each domain without requiring ownership. One verification per domain, then you monitor indefinitely.
How quickly do I get alerted?
Check cadence depends on your plan — 5 minutes on Starter, and as fast as every 1 minute on Team, Agency, and Compliance. SSL expiry alerts fire at 30 days and 7 days before expiry so you have time to act. Vendor status alerts fire within one check cycle of a status page update.
Start watching for free.
Add your first client domain and get your first SSL, DNS, or vendor alert in under 10 minutes — or know that everything is green. Start free on 3 services, or trial the full workspace for 14 days. No card either way.
No credit card for the trial or the Free plan. Terms.