What CertPilot observes
Public SSL, DNS, RDAP/domain-expiry, email-authentication, and official vendor-status signals. No tenant credentials or private content.
The platform
CertPilot runs automated public-signal checks, keeps the operational registers only your team can maintain, and turns both into dated evidence reports. One system for what is automated, what you maintain, and what you hand over.
Governance Evidence Pack
External footprint — SSL, DNS, RDAP
Email authentication coverage
Renewal risk register
The model
Automated public signals and customer-maintained records are different things. CertPilot keeps them distinct, then brings both into dated evidence.
Public SSL, DNS, RDAP/domain-expiry, email-authentication, and official vendor-status signals. No tenant credentials or private content.
Owners, renewal decisions, people, assets, systems, access reviews, and the operational context no public check can know.
Checks and maintained records resolve into dated, readable reports with source, scope, ownership, and limits stated.
Domain and certificate health
FROM PUBLIC CHECKS
Renewal risk
FROM MAINTAINED REGISTER
Access review completion
FROM DATED SIGN-OFF
Review the public sources and limits behind the automated checks in the CertPilot methodology.
The module map
Read each module by its role. The architecture can grow without changing the model or blurring what is automated.
Daily public checks plus customer-entered domain governance, SSL-readiness, and sending-source context.
Maintain vendor, contract, licence, domain, certificate, owner, and renewal records.
Use the Systems Catalog, access matrix, review states, and immutable completion log to create dated evidence.
Keep customer-maintained people and account records for ownership, review, and offboarding evidence.
Record hardware, software, ownership, maintenance, and licence evidence without device monitoring.
Track cached official public vendor incidents and maintenance signals for operational context.
Generate six on-demand report formats from public checks and customer-maintained registers.
How a workflow moves
A real workflow does not touch every module. It moves through three explicit states while people remain responsible for decisions and action.
A public check flags an SSL certificate nearing expiry, or a maintained register shows a renewal inside its notice window.
SIGNAL → item · source · date
An owner records the decision, exceptions, and scope. CertPilot holds the record; your team remains responsible for acting.
OWNER → decision · exception · scope
The reviewed item becomes a readable report line with its source, owner, date, and limits stated.
OUTPUT → dated · scoped · reviewable
Who it is for
Internal IT
Keep evidence out of spreadsheets, inboxes, and one person's memory when a small team owns the whole operational estate.
Managed services
Keep client-facing checks and registers organised, then bring dated evidence into client review conversations.
Client operations
Support care plans with domain checks, renewal visibility, and client-ready evidence without loose tooling.
Small companies
Show that recurring IT governance work is under control without standing up an enterprise GRC programme.
Clear boundary
CertPilot gathers evidence from public signals and records your team maintains. It does not read your tenant, surveil people, or judge compliance on your behalf.
The platform does
The platform does not
Public inputs and customer-maintained records only. CertPilot documents the evidence; your team judges and acts on it.
The output
The platform's job is to create evidence someone else can read. Inspect all six fictional report examples before you sign up.
Start with the evidence
Run daily public-signal checks, keep operational records in one place, and generate evidence your clients and leadership can review.
Platform FAQ
CertPilot is an IT governance evidence platform. It combines public technical checks, customer-maintained registers, and PDF evidence reports for lean IT teams, MSPs, agencies, and founders/operators.
Checks cover public signals like SSL, DNS, RDAP, and email authentication. Registers cover records your team maintains, such as renewals, vendors, people, assets, and access reviews. Evidence reports turn both into dated PDFs.
External Footprint Monitoring, Renewals & Vendor Register, Access Reviews, People & Accounts, Assets Register, Vendor Status Watch, Evidence Reports, and the Sample Reports Gallery are live today. Email Authentication Monitoring is part of External Footprint Monitoring, and Systems Catalog is managed inside Access Reviews.
No. External footprint checks use public data. Register records are entered or imported by your team. CertPilot does not read email, documents, chats, AI prompts, device telemetry, or private employee activity.
No. Lean IT teams and founders/operators can use CertPilot for leadership and audit-preparation conversations, MSPs can use it for client governance evidence, and agencies can use it for client proof.
No. CertPilot produces operational evidence that can support governance reviews and audit conversations. It does not certify compliance, provide legal advice, or guarantee any audit outcome.