Certificate Transparency

CT monitoring that respects your time

Detect mis-issuance and unexpected certificates using CT logs, CAA policy, and issuance history — without alert fatigue.

Operated by Cavalry Scout Pty Ltd (Australia).Privacy·Contact·Documentation

Who it is for

Security operations, platform engineering, and IT teams responsible for owned domains, partner zones, and lookalike monitoring. If you have outgrown ad-hoc CT log queries but do not want a firehose of renewal noise, this product is built for you.

What ships today

On the roadmap

Webhooks to Splunk, Slack, Microsoft Teams, and generic SIEM endpoints; richer tenant APIs; SSO for Enterprise. We do not claim global regex CT search or live credit billing in this release — see indicative pricing.

The problem

Certificate Transparency logs make issuance visible, but raw log volume is overwhelming. Security and platform teams need to know when something changed that should not have — a new CA, a name that never appeared before, or a cert that violates your issuance policy.

How Good Roots Work helps

  1. Watch domains and patterns you care about (tenant configuration in the app).
  2. Analyze each issuance against public CAA, optional private CAA, and historical patterns.
  3. Notify only when the event is anomalous — email today; webhooks and SIEM on the roadmap.

Core capabilities

Anomaly-only alerting

We surface unexpected certificate issuance — not every routine renewal — so your team stays focused on real risk.

Public and private CAA policy

Use DNS CAA where available, and define private issuance policy per tenant when you need stricter control than public DNS allows.

Issuance history

Track whether a certificate or name set was seen before, whether the issuing CA changed, and whether issuance follows an expected cadence.

Built on Certificate Transparency

Monitoring is powered by CT log ingestion (via our ctlogdaemon pipeline) and analysis — not periodic certificate store scraping alone.

Compared to manual CT log watching

AspectManual CT reviewGood Roots Work
Noise levelHigh — every renewal and duplicate SAN cert creates workLow — alerts focus on anomalies and policy violations
CAA alignmentManual cross-check against DNS or spreadsheetsAutomatic public CAA evaluation; optional private policy per tenant
Historical contextHard to remember prior issuers and cadenceIssuance history informs whether an event is expected
Operational loadAnalyst time spent triaging CT log queriesContinuous ingestion with edge API access for the tenant app

Try it now