Two versions of the
same 3am page.
Same alert. Same service. Vorhut reads the signals you already collect, ranks what breaks by blast radius, and acts only through governance you control. One of these nights wakes you up.
Tonight, without
71 minutes awake- 03:04Page. checkout p99 over threshold.
- 03:09Laptop open. Which dashboard was it?
- 03:21Found it — Kafka consumer lag upstream.
- 03:38Scaled the consumer group. Watching.
- 04:15Back to bed.
Tonight, with Vorhut
no page- 02:51Trend flagged. cpu_usage crosses 90 in 8m.
- 02:51Blast path walked — 2 services downstream.
- 02:52Policy gate: production needs an operator.
- 02:52Approve. One tap, on your phone.
- 02:54Executed, verified, closed on recovery.
The right-hand column is the sequence Vorhut runs, not a measured average. Detection lead time depends on your signals; we publish per-incident traces rather than headline numbers.
Your stack, ranked by what breaks next.
Vorhut sits on top of the tools you already pay for — Datadog, Prometheus, OpenSearch, your cluster — and reads their signals. No new agent to deploy. Incidents are ordered by blast radius rather than by how loudly they alerted.
- checkout · error_rate 3.6σ above baselineblast high
- ledger-api · p99 crosses 400ms in 6mblast med
- kafka.platform-shared · memory 99.4% of limitblast med
- observability.tempo · recovered, auto-closed2m ago
Blast-radius ranking works over the service dependencies you declare; a freshly connected cluster starts flat until you do.
It asks permission.
The question every team asks about a tool with production credentials is what it does at 3am without them. Vorhut predicts the incident, drafts the fix, and then stops — because your policy said so.
Policies are written in RPL and evaluated before any executor runs. They gate on confidence, blast radius, service scope and environment. AI recommends and authors; it never mutates state.
WHEN remediation.execute
AND environment = "production"
AND blast_radius > low
THEN require approvalEvery action leaves a trace you can read.
Signal to remediation, with the policy that allowed it and the operator who approved it. Hash-chained, replayable as a dry run, and scoped to your tenant at the database.
Connect a cluster and watch a night go quiet.
Free during the public beta. Reads your existing observability stack; nothing new to deploy alongside it.