What the rows are telling you
One certificate has already expired. One is valid for months but was installed without
its intermediate, so it works in a browser that cached the chain and fails everywhere else.
One covers example.com while the service moved to a subdomain. One is still
signed with SHA-1. None of those are visible from a calendar reminder.
It reaches what a hosted checker cannot
CertWatch runs from your own computer, so the appliance on the management VLAN, the
internal API and the staging box behind the VPN are all reachable. An online SSL checker
can only see what the public internet can.
Nothing installed on the servers
It opens a TLS connection the way any client would, reads the certificate the server
actually presents, and disconnects. No agent, no credentials — a certificate is
public by design.
Free covers three hosts
Enough for a personal domain and a side project. Pro adds unlimited hosts, scheduled
background rechecks, subnet scanning, DNS change monitoring, webhook alerts, and the
CSV and PDF an auditor asks for.