Infrastructure monitoring
Every server.
Every switch. Watched.
Arqos watches your servers and network gear and speaks up only when something needs you. Healthy machines stay quiet. Problems rise to the top.
outbound-only / no open ports / no remote execution — by design
Monitoring was supposed to help.
It became two problems.
The wall of data nobody reads
Traditional tools answer every question except the one that matters: is anything wrong right now? Forty charts per server, and the warning that counts is buried on page six. When a tool demands reading, people stop reading — and problems hide in plain sight.
The watcher became the way in
Most monitoring tools can also control the machines they watch — remote commands, remote updates, remote everything. That made them the single most valuable target in the building. In 2021, attackers compromised one such tool (Kaseya) and used its own update channel to lock up roughly 1,500 businesses in a single afternoon. Insurers and lawyers noticed. So did we.
Arqos is the opposite, on purpose
The Arqos agent has no ability to run anything on your machines — not a disabled feature, the capability simply does not exist in the software. And the dashboard is built so you don't have to study it: quiet means healthy, and anything that needs attention is already at the top.
[•]the product watches so you don't read.
01
Nothing to open
Every report leaves your network the same way your browser does — encrypted, outbound, port 443. No VPN, no firewall changes, no new doors for an attacker to find.
02
Switches too
Network gear can't run software. One small probe on any machine checks your switches, routers, and storage over the local network and relays their health out.
03
It can only watch
The agent reads health numbers — CPU, memory, disk, uptime — and sends them. There is no command channel. Even if our cloud were breached, an attacker gets graphs, not your network.
Installed before your coffee brews
One command, one token. The agent enrolls itself, gets its keys, and starts reporting in under a minute.
$ arqos-agent enroll --token et_4f29…
[•] enrolled as device dc-01
$ arqos-agent run
[•] report sent (cpu 11.2%, mem 31.0%, 2 disks)
What every device gets
One price. The whole box, watched its own way.
A server, a hypervisor and a printer don’t speak the same language — so Arqos doesn’t force them into one table. Each device is watched in its own terms, and it’s all the same per-device price. No add-ons, no “that’s the Enterprise tier.”
Servers & VMs
60-second agent
- [•]CPU, memory and per-volume disk, once a minute
- [•]“Disk full — with what?” names the largest directory in the alert
- [•]The runaway process, named, while CPU is pinned
- [•]Uptime + boot cause: Windows Update vs. power loss, told apart
- [•]Any service, port or process you name — up / listening / running
Hypervisors
ESXi / VMware
- [•]Every datastore's capacity — with cluster-shared SANs de-duplicated
- [•]The full VM roster: running, heartbeat-lost, or powered off
- [•]Committed memory and true host uptime (survives an snmpd restart)
- [•]Pages on a filling datastore, a failed sensor, or clock drift
Switches · routers · firewalls
read-only SNMPv2c
- [•]Per-port status, link speed and ↓/↑ traffic
- [•]Interface error rates, physical uplinks split from virtual
- [•]A port that drops when it should be up opens one incident
- [•]No agent on the gear — one on-site probe watches them all
Printers
read-only SNMP
- [•]Toner and supply levels per cartridge, in plain language
- [•]Monthly page ledger — the lease-billing number, kept for you
- [•]Jam, open-door and low-paper states surfaced
- [•]Onboard a printer at 8% toner and it pages on first sight
Hardware & environment
self-reported inventory
- [•]Model, serial and firmware — a live inventory, not a spreadsheet
- [•]Temperature, fan and voltage sensors where the gear exposes them
- [•]Clock drift measured against server time
- [•]Read-only config visibility — nothing is ever scanned or probed
Service exposure
config visibility
- [•]Every network service a device advertises about itself
- [•]Cleartext and legacy protocols flagged with a quiet advisory
- [•]Telnet, FTP, SNMPv1, SMBv1 — “prefer X / disable if unused”
- [•]Self-reported from the device, never a port scan
And for the whole fleet
A dashboard that stays quiet
Healthy machines collapse into summaries; the worst thing is already at the top. Drill fleet → site → device, worst-first, every hop.
Down in ~2 minutes, resolved automatically
Absence-based detection catches power loss and cut uplinks. The alert auto-resolves and confirms recovery, so a 2 a.m. page can't haunt your morning.
Alerts that route and escalate
Email and iOS push today, with per-channel routing, escalation, and daily / weekly digests. Snooze a device or set a maintenance window without going blind.
Evidence your insurer will accept
Uptime reports and incident dossiers, exportable — the paper trail lenders and cyber-insurance underwriters ask for, generated instead of assembled by hand.
Scoped, site by site
Every location its own view, every viewer scoped to only what they should see, and alert thresholds you can tune. Bring a new site online without touching a firewall.
iOS and desktop, in your pocket
The whole fleet on an iPhone and a menu-bar monitor on the desktop — the same worst-first story, wherever you are.
What it costs
One published price.
The same for everyone.
$3–5 per device per month — printed on one page, the same number for a 10-device office and a 1,000-device fleet. The first three devices are free.
[•]See the whole priceNo quote wall
The price is on the page — no discovery call, no “contact sales,” no wondering what the last customer paid.
Month-to-month
Cancel anytime. No 1-, 3-, or 5-year contracts, and no auto-renew traps. If we stop earning it, you stop paying it.
Your rate is locked
The per-device price you join at never goes up while you stay subscribed. We deleted the renewal-hike letter.
Ghost devices are free
A device silent for 30 days auto-archives and drops off the bill — by itself. We only charge for what we're actually watching.
Why Arqos exists
I run ThinkOpen, a security and IT firm in Los Angeles. The insurers and lawyers our clients answer to kept asking the same question: what can your management tools doto the network if they're compromised? For every tool we evaluated, the honest answer was “everything.” Meanwhile my engineers were drowning in dashboards built to impress in demos, not to be read at 7 a.m. I wanted monitoring that a lawyer could love and an engineer could ignore until it mattered. Nobody sold it. So we built it, ran it on our own fleet first, and called it Arqos.
— Luis Ramos, founder · ThinkOpen Inc., Los Angeles
Fair questions.
The objections we hear from owners, managers, and the IT teams who advise them — answered plainly.
[•] something we missed? ask us directly
What data leaves my network?
Health numbers, and only health numbers: CPU, memory, and disk usage, network throughput, uptime, the device's name and operating system version, and response times for your network gear. No file contents, no documents, no keystrokes, no screenshots — the agent has no code to collect them.
Will it fight my antivirus or EDR?
No. The agent reads the same health counters your Task Manager does and doesn't hook into other software, so there's nothing for your security tools to object to. Every release is signed and ships with a published checksum, so your security team can verify exactly what's running and allowlist it once.
What happens if Arqos itself gets breached?
The honest worst case: an attacker sees your machines' health numbers. That's it. There is no command channel to hijack and no path from our cloud into your network — the agent only ever talks outward. Compare that with the worst case of a traditional remote-management tool, which is control of every machine it touches.
How long does rollout take?
About 60 seconds per server — one command, no reboot, no firewall tickets, no maintenance window. A typical small fleet is fully reporting the same afternoon. Switches and routers need nothing installed at all; one probe machine watches them.
What does it run on?
Windows and Windows Server, Linux, and macOS — one small program, about 9 MB. Switches, routers, firewalls, and storage devices are monitored over your local network by the probe, so they don't need to run anything.
See your whole fleet by this afternoon.
Early access is open to a small number of IT teams.