Public-signal checks
CertPilot checks public SSL, DNS, RDAP/domain-expiry, email-authentication, and official vendor-status signals without private-system credentials.
IT Governance Evidence Platform
Daily public-signal checks on domains, SSL, DNS, and email authentication. Customer-maintained registers for renewals, vendors, people, assets, and access reviews. Turn both into management-ready evidence reports for lean IT teams, MSPs, agencies, and founders/operators.
Sample evidence · illustrative
Governance Evidence Pack
External footprint — SSL, DNS, RDAP
Email authentication coverage
Renewal risk register
Access review completion
Checks + Registers → Evidence
Public signals show what can be observed from outside. Maintained registers capture the operational context only your team knows. Neither half proves governance alone.
CertPilot checks public SSL, DNS, RDAP/domain-expiry, email-authentication, and official vendor-status signals without private-system credentials.
Your team enters or imports the owners, renewal dates, people, assets, systems, and review decisions that no public scan can know.
Checks and maintained records resolve into dated, plain-English reports with source, scope, ownership, and limits stated.
Domain and certificate health
From public checks
Renewal risk
From maintained register
Access review completion
From dated sign-off
The platform
Each module has one job: observe a public signal, maintain an operational record, or turn both into evidence. The architecture can grow without changing the model.
Daily public checks plus customer-entered domain governance and sending-source context.
Maintain vendor, contract, licence, domain, certificate, owner, and renewal records.
Customer-maintained people and account records for ownership and offboarding evidence.
Record hardware, software, ownership, maintenance, and licence evidence without device monitoring.
Use the Systems Catalog, access matrix, review states, and completion log to create dated evidence.
Track cached official public vendor incidents and maintenance signals for operational context.
See the workflow
The product overview shows public checks, maintained registers, access reviews, and report output using a synthetic workspace.
Free IT admin tools
Run a focused utility before you sign up. Each selected tool uses public input and returns an operational result on screen.
Track upcoming retirements, end-of-support dates, and admin-impact changes across Microsoft 365, Google Workspace, Atlassian, and Apple.
Operational record
Check SSL expiry dates for up to 25 client domains and generate a shareable calendar feed.
Open WatchtowerCheck DMARC, SPF, MX, MTA-STS, TLS-RPT, and BIMI records across client domains.
Open Inbox PulseChange intelligence
Published records are source-backed against official vendor announcements and pass the same verification predicate used by the full calendar, detail pages, CSV, and ICS exports.
Effective
1 September 2026
From September 1, 2026 Entra ID auto-enables passkeys for SMS/voice MFA users; Microsoft-provided SMS and voice retire on February 1, 2027.
Effective
8 September 2026
Atlassian Analytics stops new dashboard subscriptions on September 8, 2026 and removes emailed dashboard reports on November 2, 2026.
Effective
30 September 2026
Microsoft retires Project Online on September 30, 2026. Project Web App sites and data become unavailable, so migrate projects before then.
Published records only · needs-review records never render
See all changesEvidence reports
Reports are the product output: dated, readable artifacts generated on demand from public checks and customer-maintained registers.
SSL, DNS, domain-expiry, and email-authentication evidence.
Upcoming renewals, notice windows, owners, and open decisions.
A dated monthly summary including DNS change evidence.
An on-demand governance summary; not an automated weekly delivery.
A dated register and completion record for access-review work.
A cross-module management packet from checks and maintained registers.
Governance Evidence Pack
External footprint — SSL, DNS, RDAP
Email authentication coverage
Renewal risk register
Access review completion
Resources
Practical articles on checks, customer-maintained registers, and management-ready evidence reports.
Use public-signal checks and customer-maintained registers to create dated IT evidence reports with scope, owners, and limits.
Updated 21 Aug 2026
Read the resourceAccess Reviews
Record access review sign-off with reviewer, date, period, cadence, scope counts, open actions, next due date, and evidence notes.
Read articleRenewal Ledger
Track auto-renewing subscriptions with renewal dates, notice deadlines, owners, decisions, cancellation paths, and review evidence.
Read articleClear product boundary
CertPilot gathers operational evidence. It does not surveil people, read private content, or judge compliance on your behalf.
CertPilot does
CertPilot does not
Pricing
Users are not the meter. Workspace capacity is based on tracked items: domains, renewals, vendors, people, accounts, assets, systems, and access-review entries.
Starter
For one lean team moving the first evidence workflow out of spreadsheets.
Included capacity
Up to 100 tracked items
Professional
For MSPs, agencies, and growing IT teams with several clients, departments, or business units.
Included capacity
Up to 250 tracked items
Portfolio
For heavier evidence volume across larger domain portfolios and multiple operating registers.
Included capacity
Up to 500 tracked items
Start with a 14-day free trial. No credit card required. Upgrade when the workspace reaches its tracked-item capacity.
Tracked items means the combined total across monitored domains, renewals/vendors, people/accounts, hardware/software assets, systems, and access-review entries. Higher-capacity workspaces should be quoted separately instead of silently stretching a low-price plan.
FAQ
Exact answers about current scope, imports, reports, connectors, and plan capacity.
CertPilot helps a lean IT team keep the recurring governance records in one place: public domain checks, renewal ownership, vendor and software records, people and account records, assets, access-review states, and dated PDF evidence reports. It is for the work that usually lives across spreadsheets, inboxes, calendar reminders, and one person's memory.
The live workspace covers domains, SSL/DNS/email-authentication checks, renewals and vendors, people and accounts, hardware and software assets, systems, and access-review entries. Pricing is based on tracked-item capacity, so a domain, vendor, person/account, asset, system, or access-review entry all count toward the plan limit.
Six on-demand report types: Domain Health, Renewal Risk, Monthly Proof, Weekly Governance, Access Review Register, and Governance Evidence Pack. They are built for management, client, insurance, and audit-preparation conversations where a dated, readable artifact is more useful than another dashboard screenshot.
Yes. CertPilot is manual-first and CSV-friendly. Start from your existing domain list, renewal spreadsheet, people/accounts export, asset list, or access-review sheet, then clean the records into structured registers. You can also export the data back to CSV, so the workspace is not a data trap.
No. CertPilot has no Google Workspace, Microsoft 365, HRIS, finance, MDM, RMM, inbox, contract-parsing, or device-discovery connector today. Teams enter or import register records themselves. That keeps the access surface smaller, but it also means CertPilot is not a replacement for an IAM, IGA, MDM, ITAM, or SaaS-discovery platform.
A spreadsheet is better for blank-canvas analysis. CertPilot is better when the same records must be reviewed repeatedly, assigned to owners, checked against public signals, turned into reminders, and converted into PDF evidence. The point is not to replace every spreadsheet; it is to stop important governance records from depending on manual formatting and memory.
Those tools are usually alerting systems. CertPilot includes daily public checks for SSL, RDAP/domain expiry, DNS, and email authentication, but the broader job is governance evidence: who owns the domain, what changed, what renews soon, what was reviewed, and what report can be shared. CertPilot deliberately does not monitor uptime or response time.
Choose by tracked-item capacity, not by vague company size. Starter fits a small controlled workspace. Professional fits several clients, departments, or business units that need branded reports. Portfolio adds more room for heavier evidence volume. If the workspace will exceed the plan limit, the honest answer is to upgrade or discuss custom capacity before importing everything.
Start with the evidence
Turn on public-signal checks, maintain the operational records your team already owns, and generate evidence a client, a boss, or an auditor can read.
Questions? Email hello@certpilot.app.