The new certificate misses one published edge.
A job can renew correctly while an old load balancer, CDN route, or proxy keeps serving the expiring certificate.
Edge observability / ports 80 + 443
A compact external watchdog for operators who want raw evidence, deterministic findings, and no integration ceremony. Gapis observes the public edge, saves the baseline, and reports the exact delta.
No agent · No cloud role · No card for Free
api.example.net
ILLUSTRATIVE
resolve public DNS answersCapturedtls chain + hostnameVerifiedhttp redirect → final responseTraceddiff observed vs baselineComparedWhy independent checks matter
Renewal jobs, DNS changes, and proxy deployments report their own execution. Gapis observes the outcome from outside your stack.
A job can renew correctly while an old load balancer, CDN route, or proxy keeps serving the expiring certificate.
Stale records and redirect chains are easy to miss until clients hit the wrong origin or an insecure hop.
HSTS, CSP, frame protection, and referrer policy can disappear when proxy or application configuration changes.
One focused scan
Each finding includes observed values, operational impact, and a concrete remediation. Gapis never stores response bodies.
Record A, AAAA, CNAME, NS, and CAA observations and surface changes against the saved baseline.
Check hostname coverage, expiry, issuer, SANs, chain validation, negotiated protocol, cipher, and bounded legacy TLS support.
Verify port 80 upgrades to HTTPS, trace a bounded public redirect chain, and report the final status.
Observe HSTS, CSP, nosniff, frame protection, and referrer policy at the final public endpoint.
Compare new observations to the previous successful baseline instead of interpreting a pile of raw scan snapshots.
Prioritized findings explain impact and the exact configuration outcome to restore. Acknowledge known conditions without deleting history.
Useful in five minutes
No agent, cloud role, certificate private key, or DNS-provider access is required.
Use an email and password. Gapis separates every customer’s endpoints, scans, findings, and audit events.
Gapis validates the target, restricts the scan to public addresses on TCP 80 and 443, and starts immediately.
See the served certificate, DNS route, redirect chain, headers, prioritized findings, and a saved comparison baseline.
Deliberately bounded
Gapis keeps its permissions and collected data small because public-edge monitoring should not create another privileged integration.
Your first endpoint and daily scans are free.