Certificate intelligence, connected

See the infrastructure behind every certificate.

Search certificate history, uncover related domains and endpoints, and monitor the changes that matter—all with evidence you can verify.

Passive CT evidence Source-level timestamps API-first
investigation / example.com INDEXED
domain.name: example.com
Certificates4
Names7
Issuers3
api.example.comGoogle Trust Services · WE1
example.comDigiCert Inc · ECC SHA384
status.example.comLet's Encrypt · R12
Built for investigations where provenance mattersEvery relationship keeps its sourcePassive evidence stays separate from live scansCoverage and freshness are always visible
One investigation surface

From first clue to connected context.

Purpose-built around certificates instead of hiding them as one more filter in a general internet scanner.

01

Search the evidence

Move from a domain or fingerprint to normalized certificate records with exact match reasons and source timestamps.

Domains · SANs · Issuers · SHA-256
02

Pivot through infrastructure

Follow shared certificates, public keys, names, and live endpoints without losing the evidence behind each connection.

Certificates · Names · Keys · Endpoints
03

Know what changed

Turn any investigation into a saved hunt and receive a clear alert when new matching issuance is observed.

Email · Webhooks · Slack
Evidence, not theater

Know what was observed, where it came from, and when.

CertificateScan keeps historical transparency data separate from active endpoint observations. Missing scan data is never treated as proof of absence.

Read the methodology
Evidence provenance2 sources
Google Argon 2026CT log · entry 1,842,291,142
Cloudflare Nimbus 2026CT log · entry 923,188,420
Duplicate observations preserved; issuance deduplicated.
Start with public evidence

What is your certificate trail revealing?

Open the investigation console