Outages and security alerts
Know which cloud provider is down — and which vulnerability is being exploited
right now. Status for 33 providers, advisories from CISA, NVD and vendors.
Infrastructure status. Security intelligence.
GrafStatus answers two questions: what is broken right now, and what is dangerous right now.
STATUS
It watches the official status sources of 33 cloud and SaaS providers — AWS, Azure, Google Cloud, Cloudflare, GitHub, Slack, Zoom and more — and tells you when one of them is in trouble. No dashboards to build, no integrations to wire up, no account to create.
• One screen for right now. Everything currently broken, worst first.
• Every vendor at a glance, with its state and when it was last checked.
• Push alerts when a vendor goes down, at the severity you choose.
SECURITY INTELLIGENCE
The Security tab aggregates published security advisories from official sources — CISA's Known Exploited Vulnerabilities catalogue, NIST's NVD, GitHub Security Advisories, and the security bulletins of Microsoft, GitLab, AWS and Google Cloud.
• Vulnerabilities under active exploitation, marked clearly and never inferred.
• CVSS, affected products, the vendor's own recommended action, and a timeline.
• Every event carries its sources, and every source opens the original advisory.
• Filters for cloud, Kubernetes, containers, network, identity and CI/CD.
One vulnerability is one entry. The same flaw is announced by CISA, described by NVD, patched by its vendor and catalogued by GitHub — GrafStatus resolves those into a single event carrying all four sources, instead of four cards you have to work out are the same thing.
BUILT ON ONE RULE: NEVER INVENT
Most status aggregators guess. When a feed fails or returns something unrecognised, they quietly show green — and a green dot that is a guess is worse than an honest blank.
GrafStatus does not do that. When a source cannot be read, it says Unknown and says so. When a vendor is not monitored, it says that too. When nobody has scored a vulnerability, it shows no score rather than a zero.
The same rule governs what reaches the Security tab at all. Thousands of advisories are published every week and almost none of them are about the infrastructure you run; GrafStatus surfaces what is exploited, critical, or high severity and relevant to cloud, DevOps and enterprise IT. It is not a CVE reader.
WHAT IT IS NOT
GrafStatus does not scan your systems. It has never seen your infrastructure and cannot tell you whether you are affected — it aggregates and prioritises public intelligence so you know what to go and check. It is not a vulnerability scanner and does not claim to be one.
QUIET BY DESIGN
Set a severity floor for outages and another for security, and nothing below them reaches your phone. An ongoing outage notifies once, not every minute until it clears. Scheduled maintenance never wakes you. Unclassified reports never wake you. Vulnerabilities confirmed to be under active attack can always reach you, whatever else you have turned off.
NO ACCOUNT, NO TRACKING
There is nothing to sign up for. If you allow notifications, the app sends the push token Apple issues for that installation and the alerting preferences you chose. That is everything. No analytics, no advertising identifier, no location, no profile.
Status and security data come from each provider's and authority's own published sources. GrafStatus is not affiliated with, endorsed by, or connected to any of the vendors it monitors.
Chrome-Stats does not own this Apple app. Please use these information below to contact the Apple app developer.