Frequently asked questions.

Common questions about how CertMoni monitors your public TLS certificates — what we check, what we never touch, and how billing works. CertMoni runs entirely from the public internet, so there is nothing to install and no agent to run on your own servers. If your question is not answered below, email hello@certmoni.com and a real person will reply.

Do you need access to my servers or private keys?

No. Everything is checked from the public internet, using the same TLS handshake any browser makes, plus public data sources.

What counts as one certificate?

Each endpoint you monitor, meaning a hostname and port, counts as one. A wildcard certificate served on three hostnames is three endpoints, because each can break on its own.

Can I monitor internal or private hosts?

Not yet. CertMoni monitors endpoints reachable from the internet. Private addresses are refused.

What happens when my plan runs out?

We email you a month, two weeks and one week before renewal. If it lapses, checks pause but your board and history stay put until you renew.

How do I pay?

By PayPal, a year or more in advance. You can buy 1, 2 or 3 years and top up with more certificates at any time.

Want the detail behind these answers? The feature list sets out every check we make, the pricing page explains exactly what one certificate costs, and our note on shorter certificate lifetimes covers why monitoring matters more every year. You can also start a free trial of five certificates without a card and see your first results within minutes.

Start a free trial