C
CertPilot

The platform

Checks and registers in one workspace — evidence out.

CertPilot runs automated public-signal checks, keeps the operational registers only your team can maintain, and turns both into dated evidence reports. One system for what is automated, what you maintain, and what you hand over.

No credit cardTry free tools first — no login
Model / checks + registers → evidence
C

Governance Evidence Pack

Demo / illustrative
Inputs
Checks + registers
Scope
Demo workspace

External footprint — SSL, DNS, RDAP

Observed

Email authentication coverage

Example gap

Renewal risk register

Review
Fictional workspace · no customer data

The model

Two kinds of input. One evidence output.

Automated public signals and customer-maintained records are different things. CertPilot keeps them distinct, then brings both into dated evidence.

Automated public signalsPublic / official sources

What CertPilot observes

Public SSL, DNS, RDAP/domain-expiry, email-authentication, and official vendor-status signals. No tenant credentials or private content.

SSL expiryDNS recordsDMARC / SPFRDAP / domainVendor status
Customer-maintained registersYour context

What your team maintains

Owners, renewal decisions, people, assets, systems, access reviews, and the operational context no public check can know.

Renewals & vendorsPeople & accountsAssetsAccess reviewsSystems Catalog
Evidence outputManagement-ready

The evidence report

Checks and maintained records resolve into dated, readable reports with source, scope, ownership, and limits stated.

Domain and certificate health

FROM PUBLIC CHECKS

Observed

Renewal risk

FROM MAINTAINED REGISTER

Review

Access review completion

FROM DATED SIGN-OFF

Current

Review the public sources and limits behind the automated checks in the CertPilot methodology.

How a workflow moves

From a signal or record to dated evidence.

A real workflow does not touch every module. It moves through three explicit states while people remain responsible for decisions and action.

1 · Surface

A check or record surfaces it

A public check flags an SSL certificate nearing expiry, or a maintained register shows a renewal inside its notice window.

SIGNAL → item · source · date

2 · Review

A person reviews and decides

An owner records the decision, exceptions, and scope. CertPilot holds the record; your team remains responsible for acting.

OWNER → decision · exception · scope

3 · Evidence

It lands in a dated report

The reviewed item becomes a readable report line with its source, owner, date, and limits stated.

OUTPUT → dated · scoped · reviewable

Who it is for

Built for lean teams that still have to prove control.

Internal IT

Lean IT teams

Keep evidence out of spreadsheets, inboxes, and one person's memory when a small team owns the whole operational estate.

Managed services

MSPs

Keep client-facing checks and registers organised, then bring dated evidence into client review conversations.

Client operations

Agencies

Support care plans with domain checks, renewal visibility, and client-ready evidence without loose tooling.

Small companies

Founders / operators

Show that recurring IT governance work is under control without standing up an enterprise GRC programme.

Clear boundary

What the platform is — and deliberately is not.

CertPilot gathers evidence from public signals and records your team maintains. It does not read your tenant, surveil people, or judge compliance on your behalf.

Scope, stated plainly

Scope / defined

The platform does

  • Run public-signal checks on domains, SSL, DNS, RDAP, email authentication, and official vendor status.
  • Store the operational registers your team enters or imports.
  • Turn checks and maintained records into dated, reviewable reports.
  • Keep people responsible for review decisions and follow-up action.

The platform does not

  • Not a compliance certification platform. CertPilot produces operational evidence, not certification or legal advice.
  • Not employee surveillance. Access Reviews use customer-entered records, not activity tracking or productivity scoring.
  • Not device monitoring, MDM, endpoint monitoring, or device control. Assets are customer-entered records.
  • Not a content scanner. CertPilot does not read email bodies, documents, chats, AI prompts, or AI responses.
  • Not connector sync today. CertPilot does not currently connect to Google Workspace, Microsoft 365, SaaS admin systems, or identity providers.
  • Not a vulnerability scanner or uptime monitor. External checks use public SSL, DNS, RDAP, and email-authentication data.
  • Not AI adoption analytics or license-waste detection. Those connector-derived features are not live.

Public inputs and customer-maintained records only. CertPilot documents the evidence; your team judges and acts on it.

The output

Everything here becomes a report you can hand over.

The platform's job is to create evidence someone else can read. Inspect all six fictional report examples before you sign up.

Current report formatsOn demand
Domain Health
Renewal Risk
Monthly Proof
Weekly Governance — on demand
Access Review Register
Governance Evidence Pack

Start with the evidence

One workspace for checks, registers, and reports.

Run daily public-signal checks, keep operational records in one place, and generate evidence your clients and leadership can review.

Platform FAQ

Questions before you start.

What is CertPilot?

CertPilot is an IT governance evidence platform. It combines public technical checks, customer-maintained registers, and PDF evidence reports for lean IT teams, MSPs, agencies, and founders/operators.

What does Checks + Registers to Evidence mean?

Checks cover public signals like SSL, DNS, RDAP, and email authentication. Registers cover records your team maintains, such as renewals, vendors, people, assets, and access reviews. Evidence reports turn both into dated PDFs.

Which modules are live today?

External Footprint Monitoring, Renewals & Vendor Register, Access Reviews, People & Accounts, Assets Register, Vendor Status Watch, Evidence Reports, and the Sample Reports Gallery are live today. Email Authentication Monitoring is part of External Footprint Monitoring, and Systems Catalog is managed inside Access Reviews.

Does CertPilot need private system access?

No. External footprint checks use public data. Register records are entered or imported by your team. CertPilot does not read email, documents, chats, AI prompts, device telemetry, or private employee activity.

Is CertPilot only for agencies?

No. Lean IT teams and founders/operators can use CertPilot for leadership and audit-preparation conversations, MSPs can use it for client governance evidence, and agencies can use it for client proof.

Does CertPilot certify compliance?

No. CertPilot produces operational evidence that can support governance reviews and audit conversations. It does not certify compliance, provide legal advice, or guarantee any audit outcome.