Edge observability / ports 80 + 443

Certificate drift has nowhere to hide.

A compact external watchdog for operators who want raw evidence, deterministic findings, and no integration ceremony. Gapis observes the public edge, saves the baseline, and reports the exact delta.

No agent · No cloud role · No card for Free

External edge check
api.example.net ILLUSTRATIVE
  1. STEP 01resolve   public DNS answersCaptured
  2. STEP 02tls      chain + hostnameVerified
  3. STEP 03http     redirect → final responseTraced
  4. STEP 04diff     observed vs baselineCompared
external verification completeevidence saved
Illustrative interface sample — no customer or live scan data.
One bounded scanWhat Gapis verifies
01Public DNSA · AAAA · CNAME · NS · CAA
02Served TLSChain · SAN · protocol · cipher
03HTTP pathRedirects · status · headers
04Field-level driftBaseline · diff · remediation

Why independent checks matter

Automation can succeed while the public edge is still wrong.

Renewal jobs, DNS changes, and proxy deployments report their own execution. Gapis observes the outcome from outside your stack.

01 / Renewal

The new certificate misses one published edge.

A job can renew correctly while an old load balancer, CDN route, or proxy keeps serving the expiring certificate.

02 / Routing

A DNS or redirect change goes somewhere unexpected.

Stale records and redirect chains are easy to miss until clients hit the wrong origin or an insecure hop.

03 / Hardening

A routine deploy quietly removes a security control.

HSTS, CSP, frame protection, and referrer policy can disappear when proxy or application configuration changes.

One focused scan

Enough evidence to find the broken layer.

Each finding includes observed values, operational impact, and a concrete remediation. Gapis never stores response bodies.

Resolve the route clients receive

Record A, AAAA, CNAME, NS, and CAA observations and surface changes against the saved baseline.

Inspect the certificate actually served

Check hostname coverage, expiry, issuer, SANs, chain validation, negotiated protocol, cipher, and bounded legacy TLS support.

Follow redirects without wandering

Verify port 80 upgrades to HTTPS, trace a bounded public redirect chain, and report the final status.

Detect lost browser protections

Observe HSTS, CSP, nosniff, frame protection, and referrer policy at the final public endpoint.

See what changed, field by field

Compare new observations to the previous successful baseline instead of interpreting a pile of raw scan snapshots.

Move from evidence to repair

Prioritized findings explain impact and the exact configuration outcome to restore. Acknowledge known conditions without deleting history.

Useful in five minutes

Add a hostname. Get an external baseline.

No agent, cloud role, certificate private key, or DNS-provider access is required.

Create an account

Use an email and password. Gapis separates every customer’s endpoints, scans, findings, and audit events.

Enter a public hostname

Gapis validates the target, restricts the scan to public addresses on TCP 80 and 443, and starts immediately.

Review evidence and fixes

See the served certificate, DNS route, redirect chain, headers, prioritized findings, and a saved comparison baseline.

Deliberately bounded

A watchdog, not a vulnerability scanner.

Gapis keeps its permissions and collected data small because public-edge monitoring should not create another privileged integration.

Targets
Public hostnames only. Private, loopback, reserved, and non-global addresses are rejected before connecting.
Network
TCP ports 80 and 443 only, with bounded redirects, response sizes, concurrency, and timeouts.
Stored data
DNS, TLS, HTTP metadata, findings, and changes. No response bodies, cookies, query strings, or authorization headers.
Access
No cloud credentials, agents, private keys, or inbound firewall changes.

Check the edge outside your deployment logs.

Your first endpoint and daily scans are free.