Rootly logo
Observability Monitoring · Devops Mlops

Rootly

Rootly is an AI-native incident management platform for engineering teams. It combines on-call paging, Slack and Teams incident response, automated root cause analysis, retrospectives and status pages in one place.

Active GDPR compliant Free trial Subscription API available 16+ Verified by Guidaio
Overview

What is Rootly?

Rootly is an incident management platform built by Rootly Inc., a San Francisco company founded in 2021 by JJ Tang and Quentin Rousseau, two former Instacart employees who lived through the manual side of on-call at scale. The product covers the whole incident lifecycle rather than a single step of it, and its own positioning is AI-native: the automation is built into every stage instead of being sold as a separate module.

Five surfaces make up the platform. On-Call handles multi-person rotations, layered primary and secondary coverage, time-zone aware planning, overrides, shadow rotations, coverage requests, holiday and PTO calendars, schedule gap detection, a pay calculator and Slack user group syncing. Paging reaches responders through voice, SMS, push, Slack and email with automatic fallbacks and Do Not Disturb override, and heartbeats catch systems that go quiet. Incident Response lets an engineer declare an incident from chat; Rootly then opens the channel, sets severity, assigns roles and pulls in the right people, while workflows automate the repetitive parts and communications keep stakeholders informed. AI SRE starts investigating the moment an alert fires, runs parallel hypothesis checks across telemetry, deploys, commits and feature-flag changes, and returns ranked root causes with confidence scores and a visible reasoning chain; it drafts fixes and pull requests but never remediates without human sign-off. Retrospectives rebuild the timeline from alerts, messages and deploys, draft the document and sync action items into Jira or Linear. Status Pages keep customers informed automatically.

A conversational agent, @Rootly, answers questions and acts inside the requesting user's own permissions, and a Meeting Scribe joins incident bridges to transcribe in more than twenty languages. Extensibility runs through a JSON:API REST API, a Terraform provider, webhooks, an MCP server for IDEs and an Edge Connector for on-premise systems. The platform runs entirely on AWS with a claimed 99.99% availability, and iOS and Android apps carry the same experience to the phone.

What it does

  • Declare and run a full incident without leaving Slack, Microsoft Teams or Google Chat
  • Page the right responder through schedules, escalation policies and live call routing
  • Investigate an alert automatically and surface probable root causes with confidence scores
  • Draft remediation steps, suggested fixes and pull requests for human sign-off
  • Generate a retrospective from the incident timeline and track action items to completion
  • Publish and keep public or internal status pages up to date as the incident evolves
  • Configure incident tooling as code through the API, the Terraform provider and the MCP server
Audience

When to use Rootly / When not to

A quick filter to help you decide if Rootly is the right fit.

When to use Rootly

  • Site reliability, platform and DevOps engineers who carry the pager and want schedules, escalation and root cause analysis in one system
  • Engineering organisations migrating off PagerDuty or Opsgenie, since Rootly audits the existing setup, runs the migration and buys out the remaining contract
  • Security teams running sensitive investigations, thanks to granular RBAC, private incidents, isolated tenants and a complete audit trail
  • Regulated companies in finance, healthcare and public services that need SOC 2 Type II, a HIPAA BAA, GDPR and CCPA coverage and a named EU representative
  • Fast-growing startups, which can claim up to 50% off under 100 employees and a pay-what-you-can rate under 25 employees

When not to use Rootly

  • Teams that do not work in Slack, Microsoft Teams or Google Chat, because the entire response experience is anchored in chat
  • Organisations bound by data residency rules outside the United States: the service runs in the US and Rootly states it does not currently offer region routing
  • Buyers who require bring-your-own-key encryption for the AI agent today, since BYOK is described as being on the roadmap rather than available
  • Companies that need a per-tenant retention window on Rootly AI, where a fixed 90-day default applies to everyone
  • Individuals or very small teams with no budget, as there is no permanent free plan below the 20 USD per user per month entry point
Get started

How to use Rootly

A typical end-to-end flow, from setup to results.

  1. Start a free trial from the sign-up page, or book a demo to be walked through the platform
  2. Install the Rootly application in Slack, Microsoft Teams or Google Chat with your workspace administrator
  3. Enable Rootly AI for the workspace from Configuration then Rootly AI, and review the AI configuration settings
  4. Connect your alert sources, such as Datadog, Sentry, Prometheus, CloudWatch or a generic webhook
  5. Define your services, teams, incident roles and catalogue entries so alerts route to the right owners
  6. Build on-call schedules and escalation policies, then layer in overrides, PTO calendars and coverage rules
  7. Declare a first incident from chat and let Rootly open the channel, set severity and assign roles
  8. Mention @Rootly during the incident to get a catch-up summary, draft communications or take an action
  9. Close the loop with a generated retrospective and track the action items synced into Jira or Linear
  10. Install the mobile app and, if you want configuration as code, wire up the API, the Terraform provider or the MCP server
Quick read

Pros & Cons

Pros

  • One platform covers alerting, on-call, response, communication, retrospectives and status pages, instead of stitching several tools together
  • The entry price is public and readable at 20 USD per user per month, positioned at roughly half the cost of PagerDuty
  • The AI is transparent by design: confidence scores, a visible reasoning chain and mandatory human sign-off before any destructive action
  • The data stance is unusually explicit, with zero third-party model training, automatic PII redaction and a documented opt-out
  • Compliance is serious for a company of this size: SOC 2 Type II, HIPAA and BAA, GDPR and CCPA, a published subprocessor list and a DPA on request
  • Extensibility is real, through a JSON:API REST API, a Terraform provider, webhooks, an MCP server and hundreds of named integrations
  • Migration off PagerDuty or Opsgenie is handled by Rootly, including an audit, a plan and a buyout of the remaining contract

Cons

  • There is no permanent free plan: once the two-week trial ends, every tier is paid
  • AI SRE and Enterprise pricing is not published, so budgeting requires a sales conversation
  • Data is hosted and processed in the United States, and Rootly states that region routing is not currently offered
  • Bring-your-own-key for the AI agent is described as being on the roadmap rather than available today
  • Rootly AI retention is fixed at ninety days and cannot be configured per tenant, while Slack messages and Meeting Scribe transcripts have no automatic expiry
  • Full LLM traces are logged for quality monitoring and there is no per-customer opt-out of debug logging
  • The site publishes neither an About page nor a Contact page, and the Trust Center returns an HTTP 403 to ordinary clients
Pricing

Pricing & Plans

There is no permanent free plan. Access begins with a free trial of approximately two weeks, which Rootly says it can extend on request. The lowest paid entry point is the Essentials tier at 20 USD per user per month, available separately for Incident Response and for On-Call. Enterprise tiers and the AI SRE product are quoted on request only. Discounts are offered when the three products are purchased together, and Rootly can also be bought through the AWS Marketplace.

Incident Response Essentials - 20 USD per user per month
  • response in Slack
  • @Rootly AI chat
  • AI similar incidents
  • AI Meeting Scribe
  • retrospectives
  • status page
  • mobile app
  • advanced metrics and insights
On-Call Essentials - 20 USD per user per month
  • alert grouping and noise reduction
  • alert routes
  • live call routing with one number
  • twenty schedules and escalation policies
  • shadow rotations
  • holiday and PTO calendars
  • overrides and coverage requests
  • pay calculator
On-Call Enterprise - quoted on request
  • everything in Essentials plus support for China
  • dynamic escalation paths
  • custom alert fields and labels
  • unlimited schedules and escalation policies
  • five live call routing numbers
AI SRE - quoted on request
  • probable root cause with supporting evidence
  • alert-to-change correlation
  • impact analysis
  • drafted remediation steps and pull requests
  • alert noise suppression
  • stack integrations
  • feedback for personalisation
  • standalone or integrated use
Special offers — Startup discount of up to 50% for companies with fewer than 100 employees, less than 50 million USD raised and less than five years in business · Pay-what-you-can pricing for companies with fewer than 25 employees · Bundle discount when Incident Response, On-Call and AI SRE are purchased together · PagerDuty contract buyout: billing only starts the day the existing PagerDuty contract ends · White glove migration from PagerDuty and Opsgenie, scoped and planned by Rootly before commitment · Purchase through the AWS Marketplace, with pre-approved legal and security terms that count towards an EDP commitment · Free trial of approximately two weeks, extendable on request
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Rootly handles your data.

GDPR overview

GDPR compliance is claimed explicitly and backed by concrete mechanisms. The privacy policy carries a dedicated European Data Subject Rights section listing access, rectification, erasure, withdrawal of consent, portability, objection, restriction and the right to complain to a supervisory authority, with a link to the EDPB list. Lawful bases are named field by field: contractual necessity, legitimate interest, consent and legal obligation. An Article 27 representative is designated for the European Union and a separate one for the United Kingdom. Transfers to the United States rely on the European Commission's standard contractual clauses. A data processing agreement is available on request from the account team or security@rootly.com, and the subprocessor list is published in full. All requests go to privacy@rootly.com. No Data Protection Officer is named anywhere on the site.

Who owns the data?

Customer content stays with the customer. Rootly acts as data controller for the personal data it collects to run its own service, and as a processor when it handles a client's end users or employees, in which case the client remains the controller and the first point of contact. Incident data is described as staying within the walls of the customer organisation and is never pooled with other customers. Access mirrors the client's own SSO and role-based permissions and is auditable. Deletion, access, rectification and portability requests go to privacy@rootly.com, subject to the usual legal exceptions.

Reuse rights

Customers keep the right to use and export their own incident records, timelines and retrospectives, including through the API, webhooks and data export. On Rootly's side, use is limited: data sent to OpenAI is used solely to deliver Rootly AI and is neither stored nor used for training by OpenAI, and Rootly states that customer data is processed in context for each request and never used to fine-tune base models. Personally identifiable information is stripped automatically before prompts leave the platform, and private incident content is excluded from the classic AI features. Customers can opt out of AI processing at any time from the AI configuration page, or plug in their own OpenAI account. Rootly may still create aggregated or anonymised data for its own business purposes, provided it cannot identify anyone.

Data retention & training

Retention summary
Personal data is kept for as long as your account stays open, until you ask for deletion, or as long as needed to deliver the service. It may be kept longer to meet legal obligations, resolve disputes or collect fees, and may be retained indefinitely once anonymised or aggregated. Deletion requests go to privacy@rootly.com. Rootly AI keeps a short conversation record that is hard-deleted 90 days after the last activity, and that window cannot be configured per tenant. Slack messages captured through the integration and Meeting Scribe transcripts currently have no automatic expiry. Enterprise plans add custom data retention and session timeout settings, and the terms say Rootly will try to accommodate reasonable custom retention requirements.
Trains on customer data
No
Training opt-out available
Yes
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Rootly states that its services are hosted and operated in the United States, through Rootly itself and its service providers, and that customer data is therefore transferred to and stored on US servers. The platform runs entirely on Amazon Web Services for compute, application databases, object storage, queuing and event routing, with customer data encrypted at rest. Cloudflare provides content delivery, edge networking and the web application firewall, ClickHouse Cloud handles analytics, and QuotaGuard supplies static outbound IPs. All LLM inference for the Rootly AI agent also runs on US-based infrastructure, and the documentation states plainly that region routing for teams is not currently available, pointing customers with that requirement to their customer success manager. International transfers rely on standard contractual clauses approved by the European Commission. Security teams that need full separation can request isolated tenants so their operations run independently from the rest of the organisation.

Hosting countries
🇺🇸 United States
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Rootly.

  • Subscriptions renew automatically by default, and cancellation must go through support@rootly.com before the term ends, with no pro-rata refund on fees already paid
  • The free trial opens a paid service: stop using it before the period ends or the plan starts billing
  • All data, including LLM inference, leaves for the United States, and no regional residency option is offered, which can conflict with internal or contractual data rules
  • Slack messages captured through the integration and Meeting Scribe transcripts are retained with no automatic expiry today, so sensitive conversations can accumulate indefinitely
  • Full prompts and completions are logged to Rootly's evaluation platform for quality monitoring, and customers cannot opt out of that debug logging
  • The terms impose individual arbitration under Californian law and waive class actions, with an opt-out that must be posted by mail within a limited window
  • An AI assistant that drafts summaries and root causes can quietly erode the habit of reading the timeline yourself: the confidence score is an aid to judgement, not a substitute for it
Setup

Setup & Integrations

Technical difficulty

Moderate, and mostly configuration rather than engineering. A workspace administrator installs the Rootly app in Slack, Teams or Google Chat, a Rootly administrator enables the AI, and you then connect alert sources and define services, teams, roles and schedules. Smart defaults and best-practice templates ship out of the box and can be adjusted without code. Rootly claims adoption in under a week for organisations above a thousand users, and no separate onboarding for AI SRE. Advanced setup through the API, the Terraform provider, the MCP server or the Edge Connector is optional. Migrations from PagerDuty and Opsgenie are run by Rootly.

Deployment

Web appMobile appAPISlack appIOS appAndroid app

Apps stores

Integrations

Slack Microsoft Teams Google Chat Mattermost Zoom Google Meet Webex GoToMeeting Jira Cloud Confluence Cloud Linear Asana ClickUp ServiceNow Freshservice Pylon GitHub GitLab Terraform Pulumi Kubernetes Heroku AWS Elastic Beanstalk Datadog Sentry Grafana New Relic Dynatrace Splunk Honeycomb Prometheus Alertmanager AWS CloudWatch AWS EventBridge AWS SNS Google Cloud Rollbar Nobl9 Monte Carlo PagerDuty Opsgenie PagerTree VictorOps Statuspage.io Notion Google Docs SharePoint Outlook Coda Quip Dropbox Paper Airtable Backstage Cortex OpsLevel Glean Fivetran Looker Zapier Superplane Anthropic OpenAI Azure OpenAI Google Gemini Mistral AI BambooHR HiBob Personio Rippling CharlieHR Workday HashiCorp Vault Expel Google Calendar Google Directory Sync SendGrid SMTP X

Supported languages

EnglishArabicBengaliFrenchGermanHindiPortugueseRussianSimplified ChineseSpanishTraditional Chinese
Company

Behind Rootly

Company name
Rootly Inc.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇺🇸 United States
Headquarters
1390 Market Street. #2126 San Francisco, CA 94102 USA
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

Seed round of 3.2 million USD announced on 8 July 2021, led by Ross Fubini at XYZ Venture Capital with participation from 8VC and Y Combinator
Angel investors in the seed round included Jason Warner (CTO GitHub), Bharat Mediratta (CTO Dropbox), Max Mullen and Brandon Leonardo (co-founders of Instacart), John Lilly (formerly Greylock), Akshay Kothari (COO Notion), Andrew Fong (CTO Vise), Ed Shrager (formerly Softbank), Jett Fein (Headline) and Romain Huet (Stripe)
Round of 12 million USD announced on 10 August 2023, led by Renegade Partners with participation from Google Gradient Ventures and XYZ Ventures
Total funding announced as of August 2023: 15.2 million USD (20 million CAD), alongside existing investors Y Combinator and 8VC
No funding announcement later than August 2023 is published on the site

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Rootly.

P PagerDutyO OpsgenieJ Jira Service ManagementI incident.ioF FireHydrantR Resolve AI
FAQ

Frequently asked questions

Which chat tools does Rootly work in?
The full incident lifecycle runs natively in Slack, Microsoft Teams and Google Chat, from declaration and coordination through communications, AI assistance and retrospectives, without switching to a separate interface.
Does Rootly train AI models on my incident data?
No. Rootly states that it enforces zero third-party model training, that customer data is processed in context for each request and is never used to fine-tune base models, and that data sent to OpenAI is neither stored nor used for training by OpenAI.
Can I turn the AI off or keep my data out of it?
Yes. The documentation states that you may opt out at any time from the AI configuration page, and that organisations can plug in their own OpenAI account to apply their own retention policies. Administrators can also enable or disable Rootly AI for the whole workspace.
Which models power Rootly AI?
Rootly AI uses Claude Sonnet 4.6 from Anthropic as the default model with OpenAI's GPT-5 as a fallback, both accessed through a Rootly-managed gateway. Personally identifiable information is scrubbed from outgoing prompts automatically.
How much does Rootly cost and is there a free plan?
Essentials costs 20 USD per user per month, charged separately for Incident Response and for On-Call. Enterprise tiers and AI SRE are quoted on request. There is no permanent free plan, only a free trial of about two weeks that can be extended.
Where is my data hosted?
The services are hosted and operated in the United States, and Rootly runs entirely on AWS. All LLM inference for Rootly AI also runs on US-based infrastructure, and Rootly states that region routing for teams is not currently offered.
What certifications and compliance documents does Rootly hold?
Rootly presents itself as SOC 2 Type II certified and HIPAA compliant with a BAA available, and as GDPR and CCPA ready. The SOC 2 Type II report, penetration test results and security policies are made available through the Rootly Trust Center.
Are subprocessors published and is a DPA available?
Yes. A detailed subprocessor list is published in the documentation, grouped by function and naming the data each one processes. Rootly maintains a data processing agreement covering those processors, available on request from your account team or security@rootly.com.
Is there a mobile app and a public API?
Yes. Rootly ships iOS and Android apps with critical alerts that bypass Do Not Disturb, and exposes a JSON:API REST API with bearer tokens, a Terraform provider, webhooks and an MCP server that plugs into editors such as Cursor, Windsurf and Claude.
How does migration from PagerDuty or Opsgenie work?
Rootly scans and audits the existing environment, provides the full plan up front and runs the migration with the customer. Billing only starts the day the existing PagerDuty contract ends, so the two contracts never overlap.
Conclusion

Should you pick Rootly?

Rootly is one of the more complete answers to a problem most engineering organisations solve badly: the messy hour between an alert firing and a system coming back up. Rather than selling paging alone, it stitches on-call, chat-native response, automated investigation, retrospectives and customer communication into a single product, and the AI is genuinely woven through it instead of bolted on. The transparency choices matter here. Root causes arrive with confidence scores and a visible reasoning chain, destructive actions require human sign-off, and the data posture is spelled out in unusual detail: no third-party model training, automatic PII redaction, a published subprocessor list naming every vendor, and a documented way to opt out of AI processing altogether. For a company this size, the compliance surface is serious, with SOC 2 Type II, a HIPAA BAA, GDPR and CCPA coverage and a named Article 27 representative in Ireland.

The reservations are real but specific. Everything runs in the United States and Rootly says region routing is not offered today, which rules it out where data residency is contractual. Bring-your-own-key is on the roadmap rather than shipped, Rootly AI retention is fixed at ninety days for every tenant, and full model traces are logged with no customer opt-out. Pricing is only half public: Essentials is clearly posted at 20 USD per user per month, but AI SRE and Enterprise require a sales conversation, and there is no permanent free tier.

The natural buyer is a team already living in Slack or Microsoft Teams that has outgrown PagerDuty or is being pushed off Opsgenie, especially in a regulated sector. For that reader, the migration support and contract buyout remove most of the switching friction, and the two-week trial costs nothing but time.