product image
product image

CertLight

$19/ month
14 day trial
1 members

Self-hosted TLS & certificate monitoring

Certificates expire silently and take production down with them. CertLight — formerly CertWatch — watches yours from your own server and audits the TLS configuration most uptime tools ignore.

Features

  • Expiry countdown, staged alerts at 30/14/7/1 days
  • TLS grading: protocols, ciphers, key strength, signatures; catches servers still accepting TLS 1.0/1.1
  • Chain, hostname-mismatch and unexpected self-signed detection
  • Findings carry the fix, deduplicate, auto-resolve when you fix the cause; bursts become one digest, worst first
  • Alerts: webhook (all tiers), Slack/Telegram/email (Pro), syslog to Loglight

Server requirements

  • Linux x86-64; single static binary or Docker
  • Measured: ~10 MB binary, ~10 MB RAM idle, one process, SQLite file — no database server
  • Minimum host: 1 vCPU, 512 MB RAM, 200 MB disk (history grows slowly, MBs per year)
  • Dashboard 127.0.0.1:8422 (set -listen to expose); outbound TLS only to the hosts you monitor

Tiers. Free: 10 hosts (GitHub, Apache-2.0). Pro: 100 hosts, custom interval, scan-now, Slack/Telegram/webhook, 1-year history. Team: unlimited hosts and history, priority support. 14-day trial.

Self-hosted: host list and results never leave your network; offline Ed25519 activation, no phone-home.

Delivery. Automatic: key by Whop DM right after checkout; download in the Downloads tab of your purchase.

Whop sells paid licences only. Free: github.com/nizartuanku/certlight