INTERACTIVE DEMO · SAMPLE DATA

Expiry is only one of the ways a certificate breaks.

This is the CertWatch window with a sample watch list loaded — the same layout and the same stylesheet as the installed app. The list is sorted by risk, so the thing that will hurt you first is at the top. Press “Scan now” to watch it work through the list. Nothing to install, and nothing here is saved anywhere.

Demo Sample data for a fictional network — no real host is being contacted.

The Risk column is a 0–100 score, not a label — it exists to put the list in the right order. Read it top down and stop when you stop caring.

What the rows are telling you

One certificate has already expired. One is valid for months but was installed without its intermediate, so it works in a browser that cached the chain and fails everywhere else. One covers example.com while the service moved to a subdomain. One is still signed with SHA-1. None of those are visible from a calendar reminder.

It reaches what a hosted checker cannot

CertWatch runs from your own computer, so the appliance on the management VLAN, the internal API and the staging box behind the VPN are all reachable. An online SSL checker can only see what the public internet can.

Nothing installed on the servers

It opens a TLS connection the way any client would, reads the certificate the server actually presents, and disconnects. No agent, no credentials — a certificate is public by design.

Free covers three hosts

Enough for a personal domain and a side project. Pro adds unlimited hosts, scheduled background rechecks, subnet scanning, DNS change monitoring, webhook alerts, and the CSV and PDF an auditor asks for.

Run it against your own hosts

Every install starts with a 30-day trial of Pro — no card, no account, no email address.