Certificate discovery
Find certificates you did not issue before they become the ones you forgot.
Discovery here means: import a hostname you named, list bindings a connected panel already knows, or record a Certificate Transparency observation you typed. It does not mean scanning a network you do not operate.
Imported certificates
The discovery screen stores source=import, managed=false, and optional issuer / fingerprint / notAfter. No private key is collected. Expiry visibility does not turn into auto-renew until you create an issuance order.
Connected-infrastructure discovery
Plesk and cPanel connectors can list what the panel thinks is installed. That is the panel store. Still verify the handshake if you later deploy. Cloud and Kubernetes discovery beyond those connectors is not a customer-ready scan product.
CT monitoring — only the form that exists
You can record unexpected_certificate_observed for a hostname. That is an operator-entered observation. It is not a live tail of public CT logs and not evidence of compromise. See Academy for how to speak about CT.
| Hostname | Source | Managed | Not after |
|---|---|---|---|
| vpn.demo-internal.test | import | false | 2026-10-12 |
| shop.demo-merchant.test | panel | true | 2026-10-20 |
Related Solutions and Integrations
Solutions this product surface is built for:
Customer-facing integrations to open next:
Questions people actually ask
Do you scan IP ranges?
No. Import hostnames you named. Observe endpoints you named. Do not treat this as enterprise network discovery.
Can I import a PEM?
The discovery service stores a hostname and optional metadata (issuer, fingerprint, notAfter) without a private key. Use that for expiry visibility.
Is CT live-tailed?
No. You can record an observation. Wording is unexpected_certificate_observed. That is not a compromise claim.
Does discovery enable renewal?
No. Unmanaged stays unmanaged until you create an order and take issuance.
Can panels discover bindings?
Connected Plesk and cPanel integrations can list what the panel thinks is installed. That is the panel’s view, not a live handshake.
Where do MSPs use this?
To put the VPN appliance and the leftover vendor cert into inventory so Friday night is not the first time you see the name. Then decide which names get a connector.
Name the certificate before it pages you.
Import leftovers. Issue what you terminate. Do not ask this product to port-scan the internet.