Nothing you own expires by surprise.
ExpirySentry finds every certificate, domain, email-security record and Microsoft credential your company has — including the ones nobody automated — and tells the right person before it breaks.
Manual renewals are about to happen 8× as often.
Spreadsheets and calendar reminders worked when certs lasted a year. They won't at 47 days.
Maximum public TLS certificate lifetime under CA/Browser Forum Ballot SC-081.
One inventory for everything that expires.
Built from public data you can't hide from, so you see what an attacker — or an outage — sees first.
Every TLS certificate
We pull every cert ever issued for your domains from public Certificate Transparency logs, then handshake each live endpoint — including VPNs, mail servers and odd ports nobody remembers.
Domain registrations
Registry expiry, registrar, transfer lock and nameserver changes for every domain you own. A surprise nameserver change gets a high-priority alert.
Email authentication
SPF (including the 10-lookup limit), DKIM, DMARC, MTA-STS and TLS-RPT — checked continuously, with plain-English fixes.
New subdomains + takeovers
New hostnames show up in CT logs the moment someone issues a cert. We flag them, and catch CNAMEs pointing at deleted cloud resources before someone else claims them.
Exposed services
Weekly checks for RDP, SMB, databases and other ports that should never face the internet — on domains you've verified you own.
Microsoft Entra secrets + SAML
Read-only Graph access lists every app-registration secret, certificate and SAML signing cert, so SSO and integrations don't die on a Tuesday.
Live in five minutes. No agents, no tickets.
Enter your domain
We map certificates, hostnames, DNS and email posture from public data in under a minute. Nothing to install.
Verify with one DNS record
Prove ownership and we switch on live checks for every host, exposure checks and takeover detection.
Route alerts to owners
Assign an owner per asset. Alerts go to them plus Slack, Teams, email or your ticketing webhook — at 60, 30, 14, 7, 3 and 1 days.
It's never the cert you're watching.
The VPN cert someone renewed by hand
It was a 398-day cert. Nobody automated it, the person who did it left, and remote work stopped at 8:02 AM.
The SAML signing cert
Entra rolls a three-year cert. Three years later, nobody remembers, and every user is locked out of the app at once.
The client secret behind an integration
A two-year app secret expires and payroll, CRM sync or backups quietly stop. You find out from an angry email.
The domain on an expired card
Auto-renew was on, but the card wasn't. Website and email go dark, and the name is up for grabs.
Priced like a tool, not a PKI project.
Enterprise certificate-lifecycle suites run tens of thousands a year. Start in minutes, cancel any time.
Starter
For a single IT team with a handful of domains.
or $1,990/year
- 5 root domains, 250 hostnames
- Certificate Transparency discovery
- TLS, domain, DNS and email-auth checks every 12 hours
- Email, Slack and Teams alerts
- Owners per asset + weekly digest
- 3 team seats
Pro
For orgs where an expired cert is an incident.
or $4,990/year
- 25 root domains, 2,000 hostnames
- Checks every 2 hours
- Microsoft Entra secrets + SAML certs (3 tenants)
- Exposed-service and takeover detection
- Custom ports + SMTP STARTTLS
- Signed webhooks
- Monthly executive report
- 10 team seats
Business
For multi-brand orgs, MSPs and regulated teams.
or $9,990/year
- 100 root domains, 10,000 hostnames
- Hourly checks
- 10 Entra tenants
- REST API + CSV/JSON export
- Unlimited seats
- Priority support with a 4-hour response target
- Onboarding call included
More than 100 domains, MSP pricing, or need a security review? Talk to us.
Questions IT teams ask us
Do you need access to our servers or network?
No. Everything is outside-in: public Certificate Transparency logs, DNS, the registry, and the same TLS handshake a browser makes. The optional Microsoft add-on is read-only (Application.Read.All) and you can revoke it any time.
Why verify the domain?
So we only actively test infrastructure you own. Until you verify, we limit ourselves to passive data plus your main website. Verification is a single TXT record — or a file on your web server.
We already use ACME / Let's Encrypt. Do we need this?
ACME handles the easy certs. The outages come from the ones it doesn't: appliances, VPNs, load balancers, vendor-hosted subdomains, SAML certs, app secrets, and the domain itself. We also catch ACME jobs that silently stopped renewing.
How is this different from an EASM platform?
We focus on the expiry and misconfiguration problems that cause real outages, at a fraction of enterprise pricing, with setup in minutes rather than a sales cycle.
What happens after the trial?
14 days, full Pro features, no card required. If you don't pick a plan, monitoring pauses and nothing is charged. Your inventory stays saved for 30 days.
Can we pay annually or by invoice?
Yes. Annual plans include two months free. Business customers can pay by invoice — contact us.
What expires next on your domain?
Run a free scan. You'll see your certificates, registration date, email-security grade and anything already in the danger zone.