CerebrixOS
Watchtower by CerebrixOS

Always-on SRE, security and FinOps for your cloud — delivered as pull requests.

CerebrixOS — The AI Deployment Company. Sign up is installing our GitHub App. No forms, no passwords, no agents in your environment.

1 · Install the GitHub App

Pick your incident repo and the repos that declare your infrastructure. That installation is your account.

Install Watchtower

2 · Grant read-only cloud access

Your setup page gives you a one-command grant for Azure (or a Lighthouse button), AWS and GCP — all read-only, all revocable.

3 · Point alerts at us

One Alertmanager block. Investigations arrive as GitHub issues; fixes as PRs you approve.

What you get

ContinuouslyWhere you see it
Alert investigations with evidence, root cause, blast radius and a dry-run fixan issue per alert
Security exposure, drift and unauthorized live changes — with who changed whatsweep issues, SARIF for your security tab, OCSF for your SIEM
Cloud waste and right-sizing, priced, with realised savings trackedFinOps issues + console
Blast radius on every infrastructure PRa comment and a check on the PR
Everything as MCP tools and CloudEvents for your own agentsclaude mcp add watchtower …

Watchtower by CerebrixOS never changes your infrastructure directly — only through pull requests you approve. Access is read-only and revocable at any time.