Security at ExpirySentry
We're a monitoring product, so we hold ourselves to the standard we check you against. Here's exactly what we collect, how we scan, and how we protect it.
What we access
- Public Certificate Transparency logs, public DNS and domain-registry (RDAP/WHOIS) data.
- TLS handshakes to your public endpoints — the same connection a browser makes. We never send credentials or exploit payloads.
- TCP connect tests on a short list of high-risk ports (RDP, SMB, databases), only on domains you've verified, about once a week.
- Optional: Microsoft Graph with
Application.Read.AllandOrganization.Read.All(read-only, app-only) to read credential expiry dates and confirm the tenant owns your verified domain. We never read users, mail, files or groups.
What we store
Hostnames, certificate metadata (issuer, dates, fingerprints), DNS records, registry data, and your account details. We don't store private keys, secrets or certificate private material — we never see them.
How we protect it
- Hosted on AWS in the United States. Encrypted in transit (TLS 1.2+) and webhook URLs encrypted at rest with AES-256-GCM.
- Passwords hashed with scrypt. Sessions are HTTP-only, Secure, SameSite cookies with CSRF protection on every form.
- Customer data is isolated per organization and every query is scoped to your org.
- Nightly encrypted backups to separate AWS storage with 30-day retention.
- Payments are processed by Stripe; we never see card numbers.
Our scanner
Scanner traffic identifies itself as ExpirySentry-Monitor/1.0 (+https://expirysentry.com/security). To ask us to stop scanning a host you own, email solutions@expirysentry.com and we'll respond within one business day.
Report a vulnerability
Email solutions@expirysentry.com with details. We'll acknowledge within two business days and won't pursue good-faith research.