Edge-first observability
Observability on your nodes. Data where it must stay.
CosmoTrace is an agent, a stream and a lake. CosmoEdge finds and parses logs on the node with no configuration and tells you what it could not reach. CosmoStream routes every event by a policy you sign. CosmoLake lands it on storage you own. One hierarchy — datacenter, region, cluster, node, service — from the first byte to the bill.
No per-gigabyte ingest tax
Priced per node. Noise stops paying the same fare as evidence.
Your bucket, your region
Open columnar files on storage you own. Leaving is a copy.
Measured, not projected
Every figure on this site is one we ran. We replay it on your node.
Nothing behind a form
Every technical fact is readable without giving us an email.
The components
Seven parts. One hierarchy. One coordinate.
Buy the ones you need. They share the same five-level name for every event and the same coordinate, so adding one later never means re-collecting or re-indexing anything.
- CollectShips now
CosmoEdge
Discovers sources, parses what it knows, masks before anything leaves, reports what it could not reach.
Read more110k
events/s on 1 vCPU, under 100 MB
- ClassifyShips now
CosmoStream
One signed policy per class. Evidence is never sampled. Economy skips the hot tier.
Read more400 GB
per day ingest, per vCPU
- OwnShips now
CosmoLake
Open files in your bucket. One query over hot and cold. Leaving is a copy.
Read more15 MB/s
ingest per vCPU; at most 20 vCPU-h per TB
- InvestigatePhase two
CosmoConsole
Timeline, evidence graph and a finding where every sentence points at a raw event.
Read more4 → 1
four signals, one finding, seconds
- OperatePhase two
Ops Agent
Runs the same investigation unattended and proposes an action. A person approves.
Read more0
actions taken without approval
- GovernPhase two
Hub
One registry of every node, agent version and active signed policy. See who refused.
Read more1
source of truth for the fleet
- ProtectPhase two
Seal
Fields masked on the node. Data held inside a region boundary you draw.
Read more0
original values leave the node
The problem
Observability bills grow. Evidence does not.
- Noise is priced like evidence
- Retries and debug chatter pay the same ingest tax as a privileged command.
- Signals live in five tools
- Login, process, error, latency and request cannot be joined without swivel-chair work.
- The edge is ignored
- Most platforms start after data leaves the node — the cheapest place to classify and redact.
- Operations cannot scale with volume
- L1 and L2 headcount follows alert floods, not incidents resolved.
What we claim
Four claims. Each one has evidence next to it.
- 01
CosmoEdge discovers sources itself and parses logs with no configuration.
It walks the node for files, journald, container output and the process tree, recognises common formats, and keeps anything else as an opaque line with time, source and hierarchy attached. Nothing is dropped for being unfamiliar.
The formats it recognises and the fallback → - 02
It reports what it cannot access instead of failing quietly.
Every agent ships a coverage report with its data: what it refused for lack of permission, what it sampled under budget, what it lost when a buffer filled or a link dropped. Blind spots are listed, not discovered later.
How coverage works → - 03
One hierarchy end to end: datacenter, region, cluster, node, service.
The same five levels name every event at collection, every route in CosmoStream, every file in CosmoLake, every query in CosmoConsole and every line on the bill. There is no second model to reconcile.
The hierarchy diagram → - 04
Managed or on your own hardware, from the same artifacts, in modules.
The binaries and images we run for you are the ones you download. Start with CosmoEdge and CosmoStream, add CosmoLake when you want to own storage, and run any of it in your region or your racks.
The module list and the pricing model →
Start where you are
Three people read this page. Which one are you?
- What runs on the node
Platform or SRE lead
“What does the agent need from me, and will it really run with no configuration?”
A binary or a DaemonSet, outbound 443, and read access to what you want covered. What it cannot read appears in the coverage report as refused. Start at the agent page; it is written for you.
- The deployment and pricing model
Infrastructure director
“Can this run on my hardware, in my region, and can I buy it in pieces?”
Yes, yes and yes. The images we run for managed customers are the ones you download. Modules share one hierarchy, so you can start with two and add a third later without re-collecting.
- The architecture
Evaluating engineer
“Skip the marketing. What actually runs, and where are the limits?”
One static binary, under 100 MB, 110k events per second on one vCPU with parse, mask and classify on. The limits are on every page, in mono, next to the claim they qualify.
For the engineer evaluating it
What runs on the node
One statically linked binary, or a DaemonSet. CosmoEdge needs outbound 443 to the stream and read access to whatever you want covered. It does not need root; what it cannot read is listed in the coverage report as refused. You set the CPU and memory cap; the agent stays under it.
- 110kevents/s
- Sustained on 1 vCPU
- 25kevents/s
- On 0.5 vCPU with sort and mask
- 0OOM kills
- Under a 150 MB cap
- 400GB/day
- CosmoStream ingest per vCPU
Under 100 MB resident memory.
50 MB resident memory.
Half-core run, full duration.
CosmoLake writes at 15 MB/s per vCPU.
Measured by us on a fixed event shape. Your events are not that shape, so a design-partner run replays the same test on your node with your data before anyone quotes a number.
Deployment
Same artifacts, wherever they run
- Managed
- We run CosmoStream and CosmoLake in a region you choose. CosmoEdge is on your nodes either way. Priced per node with usage overage.
- On your hardware
- You run the same images in your datacenter or cloud account. Data never leaves your network. Licensed by capacity band.
- Modules
- CosmoEdge, CosmoStream and CosmoLake ship now. CosmoConsole with Ops Agent, the Hub and Seal follow when there is something true to show. Buy the ones you need; they share one hierarchy and one coordinate.
Why we built it
We had watched the bill grow faster than the evidence, and every agent we ran failed quietly.
Observability platforms charge for bytes, so the cheapest events and the most important ones cost the same. Collectors are cheap but tell you nothing when they cannot read a file. Nobody started on the node, where classifying and masking is nearly free.
So we built the thing we wanted: an agent that finds its own sources and admits what it missed, a stream that routes by what an event is worth, and a lake on storage you already own. Then we measured it, wrote the numbers down, and put them on this site with the limits beside them.
We are early-stage and remote-first. The people who read the demo form are the people who write the agent.
See it on your smallest node.
A design-partner run puts CosmoEdge on one node you choose, replays our benchmark on your event shape with masking on, and leaves your existing tools exactly where they are.