Built by people who have been paged for an expired certificate.

SSLScan started the way most honest tools do: as a script, written after an avoidable outage, that slowly became the thing we wished we could have bought.

Every organisation of any size runs more certificates than anyone can name - the public website, yes, but also the mail gateway, the VPN concentrator, the domain controllers speaking LDAPS, the storage appliance’s management page, the internal wiki, the staging box that somehow became production. Each one is a small clock, quietly counting down. When one reaches zero the failure is never quiet: browsers throw full-page warnings, integrations stop, and someone spends an evening re-learning OpenSSL flag by flag.

The industry’s answer has been split between free expiry pingers that watch only what you remember to tell them, and enterprise lifecycle platforms that start at five figures and a sales call. The middle - a tool a sysadmin can adopt in an afternoon that genuinely sees the whole estate, the shadow subdomains included - stayed strangely empty. SSLScan is our attempt to fill it.

The timing is not incidental. The CA/Browser Forum has voted to shrink maximum certificate lifetimes from 398 days to 47 by 2029. Renewal work that was annual becomes roughly monthly, and tracking it by spreadsheet stops being merely tedious and starts being how outages happen. Visibility is about to become the difference between a calm Tuesday and an incident bridge.

The principles the product is built on

  • Observe, never touch. SSLScan is read-only end to end. A monitoring tool that can also change your systems is a different risk class, and we refuse to blur the two.
  • Keys are yours alone. Nothing in the product transmits a private key - the toolkit runs in your browser, and a monitor built on TLS handshakes never sees one. This is architecture, not policy.
  • Plain language. Findings say what is wrong and what to do, in sentences. If you need OpenSSL man pages to use a certificate tool, the tool has failed.
  • Honest limits. Where the product cannot see - a name no source revealed, a host that refused - it says so, rather than presenting a confident illusion of coverage.
  • Priced like a tool, not a project. Flat, self-serve, cancellable in a click. No sales call to learn the price, no per-certificate meter that punishes you for the industry’s own rule changes.

The company

SSLScan is operated by SSL Scan, an independent, founder-run company. No venture obligations, no growth-at-any-cost incentives - the product is funded by the people who pay for it, which keeps our interests aligned with exactly one group: you.

Founded
2026
Infrastructure
Google Cloud, EU regions

Questions, procurement paperwork, or just want to talk to a human before trusting us with your estate? We answer e-mail ourselves →