Free tool
CT-log tripwire
Certificate Transparency logs every cert issued for any domain. A new cert you didn't request means someone else is standing up infrastructure in your name. This tool watches the logs for you. Free, no signup.
Enter a domain to monitor
We seed the inventory from the public CT log tail, then poll daily for new issuances and notify you.
Standalone tool launching soon. The Certificate Lifecycle category in every Vysiro scan already includes a CT-log tail and surfaces orphan SANs - try a free scan to see yours.
Cert inventory at a glance
Every cert seen in CT logs for your apex and subdomains, grouped by SAN and CA.
Alert on new issuance
Email or webhook the moment a cert is issued under your name - intentional or not.
Subdomain attack-surface map
CT logs reveal subdomains no DNS dump finds. We surface the ones still resolving.
Orphan SAN cleanup
Stale SANs left on legacy certs are a takeover risk. We list them in priority order.