About
Operational IT governance evidence, without the heavyweight suite
Checks · Registers · Evidence reports
01 · Purpose
What CertPilot is
CertPilot is an IT governance evidence platform for small teams that need a reliable record of what was checked, reviewed, owned, and reported. It brings externally visible technical signals and customer-maintained registers into one workspace, then packages that information into management-ready PDFs.
The aim is practical: make recurring governance work easier to see and explain without asking a lean team to adopt a heavyweight GRC system.
02 · Model
Checks + registers → evidence
Checks
Public SSL, DNS, domain-registration, email-authentication DNS, and official vendor-status signals.
Registers
Customer-maintained records for renewals, people/accounts, assets, systems, access reviews, and governance context.
Evidence
Dated reports that assemble those facts into a readable operational record.
The methodology explains what each source proves, what it cannot prove, and how reports are generated.
03 · Audience
Built for teams carrying governance work alongside everything else
- Lean internal IT teams that need repeatable evidence without enterprise overhead.
- MSPs that need a clear operating record across client estates.
- Agencies responsible for domains, renewals, access reviews, and client proof.
- Founders and operators who need ownership and review context to stay visible.
04 · Trust boundary
Evidence, not an audit or automatic control system
CertPilot does not certify compliance, provide legal advice, perform vulnerability scanning, monitor employees, read private content, or make changes inside customer systems. Registers depend on customer maintenance. Public checks describe externally visible facts, not complete tenant-specific state.
Read the full methodology and limitations, browse the resource library, or contact CertPilot with a specific question.