Certificate expiry monitoring

Never learn about an expired certificate from a customer.

An expired certificate takes a service down as effectively as any attack — and the usual cause isn't neglect, it's renewal automation that failed without telling anyone. Bastion watches the certificate actually served on every host it knows about and escalates before the deadline, not after.

No card required to start. Plans from $25/month; first scan in about a minute.

Why certificates still take sites down

Automation fails silently

An ACME client loses a permission, a DNS challenge breaks, a renewal cron dies — and nothing complains until the browser does. The served certificate is the only honest signal.

Coverage is wider than the spreadsheet

The main domain is tracked; the API host, the old marketing site and the subdomain a vendor set up are not. The cert that expires is always the one nobody wrote down.

Issuance you didn't order

A certificate issued for your domain by a CA you don't use is worth investigating the day it appears in CT logs — it's how you spot both misconfiguration and impersonation.

The domain itself can lapse

A domain registration that expires is worse than any certificate problem. The registry record deserves the same watch.

How Bastion watches them

Warnings that escalate

Renewal reminders at 30, 14, 7 and 3 days on every certificate — with a note when the served cert hasn't changed in months, the signature of stalled automation.

Every host, including the found ones

Subdomains discovered from certificate transparency logs get certificate checks too, so coverage tracks your real estate instead of a list from last year.

CA and chain checks, not just dates

Chain validity and trust, negotiated protocol, whether TLS 1.0/1.1 still answer, key strength and hostname coverage — expiry is one field of a full TLS check.

Alerts that reach the right person

Email, Slack or a webhook into ticketing, the moment a certificate crosses a threshold. The full guide to monitoring expiry →

Common questions

How is this better than a calendar reminder or a cron script?

A reminder tracks the date you wrote down; Bastion checks the certificate actually being served, on every host it has discovered, and alerts on drift — including certs renewed but not deployed, and hosts you forgot existed. The check is the ground truth, not the plan.

Does it catch certificates on subdomains I haven't listed?

Yes — subdomain discovery from certificate transparency logs runs continuously, and discovered hosts get the same TLS checks. New subdomains typically surface within days of getting their first certificate.

What about wildcard certificates?

Bastion checks what each host actually serves, so a wildcard deployed on some hosts but not others shows up as exactly that — per-host results rather than an assumption that the wildcard covers everything.

Put every certificate on watch.

Verify your domain and get the full TLS picture in about a minute.

Start your 7-day trial

No card required to start. Cancel any time.