Turn Messy Alerts Into Reliable Escalation
NiteWtch ingests alerts from vendor email and server sensors, parses them with deterministic rules you control, and escalates through voice, SMS, Slack, email, and signed outbound webhooks — until a human acknowledges.
Alert intake
Bring Alerts In From Email and Sensors
Every alert path binds to an alert source with its own routing, parser profile, and on-call assignment. Intake today is vendor email routes and server sensors — not customer-facing inbound webhooks or R-U-ON RSS feeds.
Vendor email routes
Forward Fortinet, VIPRE, Datto, backup tools, or any vendor alert email to a dedicated inbound address. Sender domain whitelist and per-tenant routing keep intake secure and organized.
Lightweight server sensors
One agent per server for CPU, RAM, disk, services, HTTP/TCP checks, DNS, ping, and heartbeats. Threshold breaches create alerts in the same escalation engine as vendor email.
Alert sources, routes, and deduplication
Bind intake to alert sources with primary and failover on-call groups. Debounce windows and maintenance suppression reduce call fatigue while preserving full alert history.
AI Analyzer Studio
AI Builds the Parser. Deterministic Rules Run Production.
Upload real vendor email samples, validate against history, publish a versioned profile — live mail never depends on a black-box AI decision.
Train from samples
AI Studio clusters email shapes, proposes classifiers and field extractors, and maps vendor severity to your routing rules — no regex literacy required.
Validate before publish
Replay draft parsers against real historical emails with the same engine used in production. See matched type, extracted fields, and what would have escalated.
Versioned snapshots + import/export
Publish immutable profile snapshots with instant rollback. Export alert types as portable JSON for dev-to-prod moves or library sharing.
Learn how AI Analyzer Studio works → · Notification channel setup guides →
Escalation
Persistent Voice and SMS Until Someone Acknowledges
On-call groups, escalation policies, availability windows, vacation mode, and holiday calendars route alerts to the right people — then keep calling.
Voice calls with DTMF acknowledgement
Primary voice provider with fallback. Random-digit DTMF confirmation, retry on no-answer, escalate to backup contacts, and re-initiate the pattern until acknowledged.
SMS via Twilio
Outbound alert SMS with per-user profile opt-in and tenant-level enable. Test delivery from your profile before going live.
On-call groups and escalation policies
Primary and failover groups per alert source or sensor. Parallel or sequential calling modes, timezone-aware availability, and maintenance windows that log without paging.
Integrations
Slack, Email Notifications, and Outbound Webhooks
Fan out alert events to the channels your team already watches — alongside voice and SMS escalation.
| Channel | What you get |
|---|---|
| Slack | Outbound Slack webhook — POST alert events to your channel (hooks.slack.com URL) |
| Email notifications | Outbound alert email alongside escalation channels |
| Outbound webhooks | HMAC-signed POST to your customer webhook URL |
| Voice + SMS | Persistent escalation with acknowledgement (see above) |
Operational reporting
Daily and Weekly Email Digests
Operational summaries for managers and on-call leads — without logging into the dashboard every morning.
Daily digest — last 24 hours
Alert counts, per-incident summary chips, p95 acknowledgement timeliness, and top noisy sources from the past day.
Weekly digest — 7-day trends
Week-over-week patterns, recurring incidents, per-incident chips, and an AI-generated summary of what changed.
Monitoring & metrics
Sensors, Metrics Cell, and Host Log Events
Enough context to investigate before the phone rings — without shipping every log line to the cloud.
Retained time-series metrics
Per-sensor charts for CPU, RAM, disk, and other collected metrics. See trends in the hours before an alert fired. Included storage scales by plan.
Host log events
Error and critical log lines from monitored servers in a fleet view — filterable by site, tag, or severity. Windows Event Log and Linux syslog.
Multi-tenant architecture
Built for tenant isolation from day one — tags, sites, per-route on-call assignment, domain whitelists, and billing/trial signup ready for MSP workflows.
See It With Your Real Alert Emails
45-day production-capable trial. No credit card. Bring your ugliest vendor samples and sensor checks — we will help you route them.