← All glossary terms

Checks

Public-signal check

A public-signal check reads externally visible facts such as DNS, SSL, domain registration, or vendor-published status.

Updated 24 July 2026

What it means

A public-signal check is a check against information visible from outside the customer's private systems. It can include DNS records, SSL certificate metadata, RDAP/domain registration data, email authentication DNS records, or an official vendor status feed. Public-signal checks are useful because they do not require customer credentials and can be repeated consistently over time.

Why it matters

Public signals often explain trust and governance problems before a customer or client notices them. A domain may be close to expiry, a certificate may be near renewal, a DNS record may change, or a vendor may be publishing an incident. Those facts do not prove everything about the private environment, but they are useful evidence for external footprint monitoring and management reporting.

How CertPilot uses the term

CertPilot uses public-signal checks for external footprint monitoring and vendor status watch. It does not use those checks to log into private systems, read mailboxes, inspect documents, or scan internal networks. When CertPilot reports a public signal, the source and boundary matter: it is reporting externally visible evidence, not full internal state.

What to record

  • The source checked and when it was checked.
  • The observed value, status, or change.
  • Whether the signal needs review, not automatic remediation.
  • Any management note that explains context or ownership.

What not to assume

  • A public signal does not prove private tenant health.
  • A check result does not mean CertPilot changed the underlying system.
  • Vendor-published status is not the same as endpoint uptime monitoring.