Never let an SSL certificate expire again
Automatic monitoring of TLS certificates across every domain you manage. Get escalating expiry alerts at 30, 14, 7, and 1 day out — so you fix renewals before browsers show your visitors a security warning.
Total Assets
8
Monitored
Protected
6
All checks passing
Down
1
Failing checks
Reviewing
1
Active scan
Avg Uptime
99.97%
Last 30 days
Avg Latency
146ms
Fleet average
Security Score
Assets
upsec.watch
https://upsec.watch99.99%
Protectedapi.upsec.watch
https://api.upsec.watch99.97%
Protectedbilling-worker
worker:billing-prod99.94%
Reviewing404.upsec.watch
https://404.upsec.watch—
DownRecent Events
404.upsec.watch is down (timeout)
api.upsec.watch recovered
cdn-proxy-03 added to monitoring
Security scan completed — A grade
2 medium findings detected
404.upsec.watch recovered
Domain Discovery
Scanning for subdomains…
Every link in the trust chain, validated
Most tools only check if the leaf certificate is valid. UpSec.Watch validates the complete chain — from your server certificate through every intermediate to the trusted root CA. Missing intermediates and incorrect chain ordering cause mobile browser failures that desktop testing never catches.
- Root → Intermediate → Leaf validation on every check cycle
- Detect missing intermediates that break mobile Safari and Android browsers
- Track certificate issuer changes — a potential indicator of compromise
Four warnings before the red screen
Automated renewal fails more often than you think — DNS misconfigurations, rate limits, expired account keys, stale certbot configs. UpSec.Watch sends escalating alerts at 30, 14, 7, and 1 day before expiry, each more urgent than the last. No more emergency certificate renewals at 2 AM.
- Escalating urgency — from gentle reminder to critical alert
- Catch failed auto-renewals before they impact visitors
- Multi-channel delivery — email, Slack, Discord, Telegram, webhook
Know exactly what your server negotiates
TLS 1.0 and 1.1 are deprecated by all major browsers. HSTS headers prevent protocol downgrade attacks. UpSec.Watch checks both — showing you which TLS versions your server offers and whether your security headers are correctly configured. Clear pass/fail results, no cryptography degree required.
- Flag deprecated TLS 1.0/1.1 still enabled on your servers
- Verify HSTS headers prevent protocol downgrade attacks
- Monitor TLS 1.3 adoption across your entire domain portfolio
Comprehensive SSL certificate monitoring
Certificate expiry countdown
Track exact days remaining until certificate expiration for every domain. Dashboard shows a clear countdown with color-coded urgency so expiring certificates never get lost in the noise.
Certificate chain validation
Validates the full trust chain on every scan — leaf, intermediate, and root certificates. Catches missing intermediates and chain ordering issues that cause mobile browser trust failures.
TLS version detection
Identifies supported TLS protocol versions on your server. Flags deprecated TLS 1.0/1.1 configurations and confirms TLS 1.3 availability for modern security compliance.
HSTS header check
Verifies HTTP Strict Transport Security headers are present and correctly configured. Detects missing HSTS, short max-age values, and absent includeSubDomains directives.
Mixed content detection
Identifies pages loading insecure HTTP resources over HTTPS connections. Mixed content triggers browser warnings and degrades the padlock indicator your visitors rely on.
Auto-renewal verification
Monitors certificate issue and expiry dates over time to verify automated renewal is working. Get alerted if an ACME renewal fails silently — before the old certificate actually expires.
Multi-domain support
Monitor SSL certificates across hundreds of domains from a single dashboard. SAN (Subject Alternative Name) certificates are fully parsed so every covered domain is tracked individually.
Wildcard certificate tracking
Supports wildcard certificates (*.example.com) with clear visibility into which subdomains are covered. Tracks wildcard renewal separately from individual domain certificates.
Set up SSL monitoring in three steps
330+
Edge locations
30d
Early warning
99.9%
Platform uptime
6
Alert channels
Explore more features
UpSec.Watch combines uptime monitoring with security scanning in one platform.
Website Monitoring
HTTP & HTTPS checks from 330+ global edge locations with instant multi-channel alerts.
TCP & Port Monitoring
Monitor database servers, mail relays, game servers, and any TCP service on any port.
Security Scanning
Automated vulnerability detection — from passive tech-detect to active scanning with thousands of security checks.
Frequently asked questions
UpSec.Watch sends escalating alerts at 30, 14, 7, and 1 day before your SSL certificate expires. Each alert includes the exact expiry date, the certificate issuer, and a direct link to the affected asset — giving you plenty of time to renew manually or verify that auto-renewal completed successfully.