openstatus
openstatus provides open source, self-hostable status pages and uptime monitoring for teams that need audit-ready incide
The Problem
Companies going through SOC 2 or other security audits get asked how they notify customers during incidents, and auditors typically want documented, timestamped proof rather than screenshots or verbal explanations. Growing teams often lack a branded, on-domain way to communicate outages and maintenance, forcing them to improvise during incidents or scramble to produce evidence when a security questionnaire arrives. Without automated monitoring tied to a status page, updates during incidents require manual work, and customers may discover problems before the company does.
The Solution
openstatus offers a branded status page on the customer's own domain, paired with uptime monitoring from 28 regions across multiple clouds, so status updates happen automatically when something breaks. Every status report, maintenance window, and subscriber notification is timestamped and logged, creating an audit trail that maps to SOC 2's CC2.3 incident communication criteria. The product supports themes, custom domains, public or password-protected pages, and alerting to Slack, Discord, PagerDuty, or email. It's also built for programmatic and AI-driven management: a CLI, typed API with OpenAPI spec, Terraform provider for managing monitors as code, and a remote MCP server that lets Claude, ChatGPT, or Cursor create and resolve status reports, with every action recorded in an audit log. The full stack is open source and self-hostable via an 8.5MB Docker image, including options to monitor internal services behind a firewall.
Why Now?
SOC 2 audits require proof of incident communication, and a status page is described as the fastest way to satisfy that requirement, with setup possible in under 10 minutes.
