For the people who actually care

Built for the people who
notice when a cert expires.

NetSweep is for the small set of people who actually sweat the public surfaces they depend on — developers, sysadmins, security-curious users, freelancers running their own domains. Four shapes of how that looks in practice.

01 — Your own domain

The cert that almost expired on a holiday.

You ship a small product. The domain is on auto-renew, the cert is on auto-rotate, life is good — until both lapse on the same Saturday and the only person who'd notice is you. NetSweep pins your apex + every subdomain you actually run, re-checks them in the background, and fires a local notification 30 / 14 / 7 / 1 days before expiry.

Pair that with the fingerprint pinning and CT log lookup and you also catch the things you don't auto-renew yourself: an imposter cert quietly logged for your domain, a CDN flipping issuers without telling you.

Your domain · last refresh
yourdomain.comTLS 1.3 · 284d
api.yourdomain.comexpires in 7 days
status.yourdomain.comTLS 1.3 · 312d
staging.yourdomain.comREVOKED
CT log entries (30d)3 expected · 0 unexpected
HSTS preloadeligible
  • Expiry alerts 30 / 14 / 7 / 1 days out
  • Fingerprint changes flagged as possible MITM
  • Header score tracked over time
02 — Your team's infra

Twelve internal services. One pocket dashboard.

You don't have an enterprise monitoring suite for the SaaS your team relies on — Notion, Linear, Vercel, your customer's portal, your own internal admin. You also can't easily stand one up for the half-dozen public surfaces around your business. Pin them in NetSweep and the home canvas becomes a living map of your trust surface, color-coded by health.

Tags ("Work", "Customer", "Internal") let you filter the Health dashboard down to the slice you care about right now.

Health · Work tag
vercel.comTLS 1.3 · 6/6 headers
linear.appTLS 1.3 · 6/6 headers
notion.so5/6 · X-Frame removed
cdn.acme-prod.comexpires in 22 days
admin.acme-corp.comTLS 1.3 · 213d
payments.acme-corp.comredirect missing on http
03 — Your digital footprint

A weather report for your trust surface.

You don't run a website but you care about the ones you use every day. Your bank. Your email. Your password manager. iCloud. NetSweep gives you a calm, on-device way to spot when one of them quietly weakens its security posture: a header gets dropped, a cert rotates to a new issuer, OCSP starts failing.

You don't need to read CVE entries every morning. NetSweep will tell you only when something changed.

What's new · this week
your-bank.comcert renewed (now 397d)
icloud.comunchanged
your-pm.com2 new CVE matches
google.comunchanged
your-email.comCSP header weakened (78 → 60)
github.comunchanged
04 — Shipping a feature

A second-opinion before you ship.

You just deployed a staging URL or a customer-preview domain. Open NetSweep, paste it into Inspect, get the full report in seconds: TLS chain valid, headers scored, CT log clean, redirect in place, CVE matches surfaced. Share the JSON export with a teammate or save it to your watchtower so the next deployment gets diffed automatically.

App Intents and a URL scheme mean you can trigger an inspection from Siri or a Shortcut on a webpage's share sheet — no context-switching out of whatever you were doing.

Inspector · preview.feature.acme.com
TLS handshakeTLS 1.3 · 87 ms · 89d
OCSPgood
HTTP→HTTPS301 redirect
Headers85 / 100 · 5/6
HSTS preloadeligible — not yet submitted
CT log entries1 issued today, all expected
CVE matches0 returned
Sound right?

Start with the sites you already lose sleep over.

Pin 3 or 4. Background refresh handles the rest. You only hear from NetSweep when something actually changes.