Trust & security
A short, honest answer to "what happens to my data, how do I actually hear about a problem, and does anyone watch CertWatch itself" — see also the live status page and the in-app Security & trust page.
What we collect
Account info (email, hashed password, notification settings), the hostnames/domains you configure and the check history generated for them, billing details (handled by Stripe — full card numbers never reach CertWatch), and standard request metadata for rate-limiting and abuse prevention. We don't sell your data or use your monitored hostnames for advertising.
How alerts are delivered
Email alerts ship on every plan over SMTP via Postmark. Pro accounts can additionally configure Slack or a generic webhook — that payload is sent directly from CertWatch's servers to the URL you provide, so its handling past that point is subject to whatever you've connected it to.
We monitor our own monitor
A monitoring product that silently stops monitoring is worse than having none, so CertWatch's own reachability is checked continuously from outside its own infrastructure, independent of the servers being monitored. A dedicated canary check is also pointed at a permanently-expired public test certificate, designed to fail every run — we alert if that check's result ever stops reporting entirely, which is how we'd notice our own monitoring pipeline had gone dark.
Data security
Connections to CertWatch use TLS in transit, and passwords are stored hashed, never in plain text. Infrastructure runs on Fly.io, with Stripe handling payment data and Postmark handling transactional email delivery.
Questions? support@certwatch.sh