Design partners: we replay 110k events/s at 1 vCPU on your smallest node, masking on, your tools untouched.

Book a run →
Skip to content
CosmoTrace
Menu

Edge-first observability

Observability on your nodes. Data where it must stay.

CosmoTrace is an agent, a stream and a lake. CosmoEdge finds and parses logs on the node with no configuration and tells you what it could not reach. CosmoStream routes every event by a policy you sign. CosmoLake lands it on storage you own. One hierarchy — datacenter, region, cluster, node, service — from the first byte to the bill.

One hierarchy: datacenter, region, cluster, node, service A datacenter contains two regions. Each region contains clusters. Each cluster contains nodes. One node is expanded to show the services running on it. The same five levels are used everywhere in CosmoTrace. DATACENTER ams-1 REGION eu-west CLUSTER payments node-17 node node node node node node node node node node CLUSTER edge-retail REGION eu-central CLUSTER core NODE node-17 · 2 vCPU · 4 GiB SERVICES payment-worker systemd checkout-api container postgres systemd sshd systemd cosmotrace-agent systemd Same five levels in the console, the query language and the bill.
One hierarchy, drawn once. The same five levels appear in the console, the query language and the bill.
  • No per-gigabyte ingest tax

    Priced per node. Noise stops paying the same fare as evidence.

  • Your bucket, your region

    Open columnar files on storage you own. Leaving is a copy.

  • Measured, not projected

    Every figure on this site is one we ran. We replay it on your node.

  • Nothing behind a form

    Every technical fact is readable without giving us an email.

The problem

Observability bills grow. Evidence does not.

Noise is priced like evidence
Retries and debug chatter pay the same ingest tax as a privileged command.
Signals live in five tools
Login, process, error, latency and request cannot be joined without swivel-chair work.
The edge is ignored
Most platforms start after data leaves the node — the cheapest place to classify and redact.
Operations cannot scale with volume
L1 and L2 headcount follows alert floods, not incidents resolved.

What we claim

Four claims. Each one has evidence next to it.

  1. 01

    CosmoEdge discovers sources itself and parses logs with no configuration.

    It walks the node for files, journald, container output and the process tree, recognises common formats, and keeps anything else as an opaque line with time, source and hierarchy attached. Nothing is dropped for being unfamiliar.

    The formats it recognises and the fallback
  2. 02

    It reports what it cannot access instead of failing quietly.

    Every agent ships a coverage report with its data: what it refused for lack of permission, what it sampled under budget, what it lost when a buffer filled or a link dropped. Blind spots are listed, not discovered later.

    How coverage works
  3. 03

    One hierarchy end to end: datacenter, region, cluster, node, service.

    The same five levels name every event at collection, every route in CosmoStream, every file in CosmoLake, every query in CosmoConsole and every line on the bill. There is no second model to reconcile.

    The hierarchy diagram
  4. 04

    Managed or on your own hardware, from the same artifacts, in modules.

    The binaries and images we run for you are the ones you download. Start with CosmoEdge and CosmoStream, add CosmoLake when you want to own storage, and run any of it in your region or your racks.

    The module list and the pricing model

For the engineer evaluating it

What runs on the node

One statically linked binary, or a DaemonSet. CosmoEdge needs outbound 443 to the stream and read access to whatever you want covered. It does not need root; what it cannot read is listed in the coverage report as refused. You set the CPU and memory cap; the agent stays under it.

110kevents/s
Sustained on 1 vCPU

Under 100 MB resident memory.

25kevents/s
On 0.5 vCPU with sort and mask

50 MB resident memory.

0OOM kills
Under a 150 MB cap

Half-core run, full duration.

400GB/day
CosmoStream ingest per vCPU

CosmoLake writes at 15 MB/s per vCPU.

Measured by us on a fixed event shape. Your events are not that shape, so a design-partner run replays the same test on your node with your data before anyone quotes a number.

Deployment

Same artifacts, wherever they run

Managed
We run CosmoStream and CosmoLake in a region you choose. CosmoEdge is on your nodes either way. Priced per node with usage overage.
On your hardware
You run the same images in your datacenter or cloud account. Data never leaves your network. Licensed by capacity band.
Modules
CosmoEdge, CosmoStream and CosmoLake ship now. CosmoConsole with Ops Agent, the Hub and Seal follow when there is something true to show. Buy the ones you need; they share one hierarchy and one coordinate.

Why we built it

We had watched the bill grow faster than the evidence, and every agent we ran failed quietly.

Observability platforms charge for bytes, so the cheapest events and the most important ones cost the same. Collectors are cheap but tell you nothing when they cannot read a file. Nobody started on the node, where classifying and masking is nearly free.

So we built the thing we wanted: an agent that finds its own sources and admits what it missed, a stream that routes by what an event is worth, and a lake on storage you already own. Then we measured it, wrote the numbers down, and put them on this site with the limits beside them.

We are early-stage and remote-first. The people who read the demo form are the people who write the agent.

See it on your smallest node.

A design-partner run puts CosmoEdge on one node you choose, replays our benchmark on your event shape with masking on, and leaves your existing tools exactly where they are.

Request a demo