C
CertPilot

Sample reports

Sample Reports

These are static demo reports using fictional data. They show example evidence outputs CertPilot generates from live checks and customer-maintained registers. All six reports below generate on demand inside the product, and the section further down explains what the live Domain Health evidence workflow can cover today — so you know exactly what the deliverable looks like before signing up.

Static example PDFs, hosted on certpilot.app. They open or download depending on your browser.

Domain Health Report

What it proves — Public-facing domains are actively monitored: SSL certificates, domain registration, and DNS records are checked daily, and issues are caught before visitors or clients see them.

Who uses it — Agencies send it to retainer clients, lean IT teams forward it to leadership, MSPs attach it to client business reviews.

Download sample (PDF)Demo data only — every domain, vendor, person, and date is fictional.

What's inside

  • Executive verdict and summary counts (healthy / warning / critical)
  • Client-grouped tables: SSL expiry, registration expiry, DNS status, overall status
  • Issues needing attention with a recommended action each
  • DNS changes since the previous check (A, AAAA, MX, NS, TXT, CAA)
  • Methodology: public TLS, RDAP, and DNS data only

Renewal Risk Report

What it proves — Renewals are under control: nothing lapses silently and nothing auto-renews unnoticed, because every SaaS subscription, license, certificate, and domain renewal is tracked with an owner and a date.

Who uses it — IT leads and operations managers send it upward before budget or renewal conversations; MSPs use it per client.

What's inside

  • Overdue renewals with vendor, owner, and due date
  • Upcoming renewals in the next 90 days with days-left countdown
  • Incomplete records — entries missing the fields needed to act in time
  • Annualised cost summary
  • Recommendations and methodology
Download sample (PDF)Demo data only — every domain, vendor, person, and date is fictional.

Monthly Proof Report

What it proves — A month of governance work happened: domain health, email authentication readiness, renewal risk, and access review counts in one management-ready summary.

Who uses it — The classic monthly deliverable — agencies to clients, IT teams to a CTO/COO/CFO, MSPs to business stakeholders.

What's inside

  • Executive summary with domain and renewal metrics plus a plain-English narrative
  • Domain health summary and DNS changes
  • Email authentication evidence (SPF, DMARC, MTA-STS grades per domain)
  • Renewal risk summary and cost summary
  • Access review counts (counts only — no names in this report)
Download sample (PDF)Demo data only — every domain, vendor, person, and date is fictional.

Weekly Governance Report

What it proves — Someone looked this week: a short operational snapshot of what changed and what needs action across domains, certificates, DNS, renewals, and access reviews. Generated on demand from the dashboard.

Who uses it — IT teams running a weekly review ritual; MSPs producing a weekly operational check per client.

What's inside

  • Executive verdict and this week's risk snapshot
  • SSL renewal window and domain expiry watch
  • DNS review signals raised in the last 7 days
  • Renewal ledger risks grouped by urgency
  • Access review counts and actions for this week
Download sample (PDF)Demo data only — every domain, vendor, person, and date is fictional.

Access Review Register

What it proves — Access reviews actually happen: a dated register of who has access to what, at what level, who reviewed it, and what follow-up is required — the evidence auditors and insurers ask for by name.

Who uses it — IT leads answering audit or cyber-insurance questionnaires; anyone running quarterly access reviews from a spreadsheet today.

What's inside

  • Summary counts: active, reviewed, action required, revoked, overdue
  • Overdue reviews flagged individually
  • Register grouped by system (this sample uses Email, Teams, Jira, Confluence, Claude, Tableau)
  • Access levels per entry (R, W, A, R/W, R/W/A, Admin)
  • Action-required follow-ups and the access-governance methodology footer
Download sample (PDF)Demo data only — every domain, vendor, person, and date is fictional.

Governance Evidence Pack

What it proves — Operational control is being managed across the whole stack: one executive packet rolls up domain health, email authentication, renewals, access reviews, people, assets, and vendor status into a single dated summary leadership can read in minutes.

Who uses it — IT leads and MSPs taking a single cross-module evidence packet into a board update, client business review, or audit-prep conversation.

What's inside

  • Executive verdict and headline counts across every live module
  • Module coverage snapshot: external footprint, renewals, access reviews, people & assets, vendor status
  • External footprint and email authentication summaries
  • People, accounts, assets, and vendor status as counts only — no names, serials, or keys
  • Recommended actions and a methodology/boundaries note (not certification, not an audit guarantee)
Download sample (PDF)Demo data only — every domain, vendor, person, and date is fictional.

What the Domain Health evidence flow includes today

The static sample above shows the report format. Beyond that sample, current CertPilot workspaces can build their Domain Health evidence from both automated public checks and customer-entered governance context:

Technical domain health

SSL status and expiry, domain/RDAP registration expiry where available, and DNS records with an overall status per domain.

DNS change evidence

The latest DNS snapshot plus what changed between checks — a read-only record of what moved and when. This is evidence of change, not DNS restore.

Domain Governance Review

Customer-entered owner, purpose, lifecycle status, renewal decision, and last reviewed date, recorded alongside the automated checks.

SSL readiness

Customer-entered SSL management method, automation status, and readiness notes — useful for preparing for shorter public TLS certificate lifetimes. CertPilot does not issue or renew certificates.

Email sending sources

A customer-entered register of the systems that send mail from a domain — website forms, CRMs, billing tools, relays, and more. CertPilot does not scan mailboxes or send email.

Management-ready evidence

A dated summary your team can review with management or clients. It is operational evidence, not an audit or compliance guarantee.

What the report helps you answer

  • Which domains need attention?
  • What DNS changed recently?
  • Which domains are missing owner, purpose, or renewal decisions?
  • Which SSL renewal paths are manual, vendor-controlled, automated, or unknown?
  • What evidence can I show to management or clients?

How CertPilot generates these reports

CertPilot runs a daily check on every monitored domain. SSL certificate expiry, issuer, and chain validity come from a live TLS handshake. Domain registration expiry comes from RDAP. DNS records (A, AAAA, MX, NS, TXT, CAA) come from public DNS resolvers, and email authentication evidence comes from public DNS records (SPF, DMARC, MTA-STS). Renewal and access review data comes from registers you maintain yourself — entered by hand or imported from CSV. The reports turn those checks and registers into evidence with plain-English findings and a recommended action per issue.

The report is the deliverable, not the dashboard. Once a recipient — a client, a leadership team, or a business stakeholder — gets the PDF, they expect the next one. That recurring expectation is the point.

What these reports are not

CertPilot produces operational evidence on public-facing assets and customer-maintained records. The PDFs are not, and are not intended to be:

  • Certificate automation. CertPilot does not issue, install, or renew certificates, and runs no ACME/Certbot automation — that stays with the host, CDN, or vendor that owns it today.
  • A DNS editor. CertPilot does not edit, restore, or roll back DNS records and holds no DNS credentials — DNS evidence is read-only, showing what changed so you can revert it in your own provider.
  • A compliance certification. CertPilot does not certify NIS2, ISO 27001, SOC 2, GDPR, or any other regime. The reports support an audit conversation; they do not replace a qualified auditor.
  • A vulnerability scan or penetration test. CertPilot reads public TLS, DNS, and RDAP signals only. No internal scanning, no exploit detection.
  • An uptime monitor. CertPilot does not measure availability, response time, or downtime windows.
  • Employee monitoring. The Access Review Register is customer-entered governance evidence — CertPilot does not track activity, measure productivity, or connect to any directory.
  • Legal advice. The reports are records of operational checks and customer-entered registers. Use a lawyer for legal questions.
  • A read of customer email, documents, chat, or any private content. CertPilot only handles public technical data and metadata the user enters themselves.

Related reading

Go deeper on how the checks, governance metadata, and reports fit together.

See your own data in this format

The samples above are static demos. Inside the product, all six reports generate on demand from your own domains and registers — usually within minutes of importing your first domain list.