Know before an Entra secret or SAML cert takes down sign-in.
Read-only Graph access inventories every app-registration secret, certificate and SAML signing cert across your tenants — with owners and alerts — alongside your public certificates and domains.
Everything that expires, in one place.
Microsoft Entra secrets + SAML
Read-only Graph access lists every app-registration secret, certificate and SAML signing cert, so SSO and integrations don't die on a Tuesday.
Every TLS certificate
We pull every cert ever issued for your domains from public Certificate Transparency logs, then handshake each live endpoint — including VPNs, mail servers and odd ports nobody remembers.
Domain registrations
Registry expiry, registrar, transfer lock and nameserver changes for every domain you own. A surprise nameserver change gets a high-priority alert.
Email authentication
SPF (including the 10-lookup limit), DKIM, DMARC, MTA-STS and TLS-RPT — checked continuously, with plain-English fixes.
New subdomains + takeovers
New hostnames show up in CT logs the moment someone issues a cert. We flag them, and catch CNAMEs pointing at deleted cloud resources before someone else claims them.
Exposed services
Weekly checks for RDP, SMB, databases and other ports that should never face the internet — on domains you've verified you own.
Certificate lifetimes are collapsing.
Maximum public TLS certificate lifetime under CA/Browser Forum Ballot SC-081.
Live in five minutes.
Enter your domain
We map certificates, hostnames, DNS and email posture from public data in under a minute. Nothing to install.
Verify with one DNS record
Prove ownership and we switch on live checks for every host, exposure checks and takeover detection.
Route alerts to owners
Assign an owner per asset. Alerts go to them plus Slack, Teams, email or your ticketing webhook — at 60, 30, 14, 7, 3 and 1 days.
Simple pricing. 14-day free trial.
No card to start. Annual plans include two months free.
Starter
For a single IT team with a handful of domains.
or $1,990/year
- 5 root domains, 250 hostnames
- Certificate Transparency discovery
- TLS, domain, DNS and email-auth checks every 12 hours
- Email, Slack and Teams alerts
- Owners per asset + weekly digest
- 3 team seats
Pro
For orgs where an expired cert is an incident.
or $4,990/year
- 25 root domains, 2,000 hostnames
- Checks every 2 hours
- Microsoft Entra secrets + SAML certs (3 tenants)
- Exposed-service and takeover detection
- Custom ports + SMTP STARTTLS
- Signed webhooks
- Monthly executive report
- 10 team seats
Business
For multi-brand orgs, MSPs and regulated teams.
or $9,990/year
- 100 root domains, 10,000 hostnames
- Hourly checks
- 10 Entra tenants
- REST API + CSV/JSON export
- Unlimited seats
- Priority support with a 4-hour response target
- Onboarding call included
FAQ
What permissions do you need?
Application.Read.All and Organization.Read.All (to confirm the tenant owns your verified domain), application-only, granted by a Global or Cloud Application Administrator. We never read users, mail or files.
Do you need access to our servers or network?
No. Everything is outside-in: public Certificate Transparency logs, DNS, the registry, and the same TLS handshake a browser makes. The optional Microsoft add-on is read-only (Application.Read.All) and you can revoke it any time.
Why verify the domain?
So we only actively test infrastructure you own. Until you verify, we limit ourselves to passive data plus your main website. Verification is a single TXT record — or a file on your web server.
We already use ACME / Let's Encrypt. Do we need this?
ACME handles the easy certs. The outages come from the ones it doesn't: appliances, VPNs, load balancers, vendor-hosted subdomains, SAML certs, app secrets, and the domain itself. We also catch ACME jobs that silently stopped renewing.
How is this different from an EASM platform?
We focus on the expiry and misconfiguration problems that cause real outages, at a fraction of enterprise pricing, with setup in minutes rather than a sales cycle.
What expires next on your domain?
Run a free scan. You'll see your certificates, registration date, email-security grade and anything already in the danger zone.