Skip to main content

Make sure your site always opens in every browser

A valid certificate is not the same as a trusted one. TLS Radar checks far more than the expiry date - trust stores, chains, ciphers, and known vulnerabilities - and warns you before a silent misconfiguration turns visitors away.

No credit card required. Free tier available.

TLS RADAR
Beacon

Need a certificate? Issue one free in minutes.

Beacon issues free 90-day Let's Encrypt certificates with a guided DNS-validation flow. No account, no command-line tools, no ACME client to install - just a domain you control.

  • Free, 90-day Let's Encrypt certificates
  • DNS-01 validation - works for apex domains, subdomains, and internal hosts
  • Download as PEM or PKCS#12 bundle
  • Pairs with TLS Radar monitoring so you're alerted before renewal
beacon.tlsradar.com
  1. 1

    Enter your domain

    Apex domain or subdomain.

  2. 2

    Add a DNS TXT record

    Beacon walks you through the exact value to set.

  3. 3

    Download your certificate

    PEM chain or PKCS#12 bundle, ready to install.

Everything that decides whether your site loads

Browsers reject certificates for far more than expiry - untrusted roots, weak ciphers, bad EKUs. TLS Radar checks every layer a browser checks, plus the standards coming next.

Expiration monitoring

Tiered alerts at 30, 14, 7, 3, and 1 day before expiry, across every domain you own.

Browser trust & distrust

We track the Chrome, Mozilla, Apple, and Microsoft root programs and flag distrust and discontinued-root events before they break your chain.

Cipher & protocol compliance

Catch weak ciphers, deprecated protocols, and Extended Key Usage combinations that modern browsers now reject.

Known vulnerabilities

Heartbleed, ROBOT, weak Diffie-Hellman, and other historical TLS flaws, flagged automatically.

Compliance-ready reporting

Audit-ready reports and scan history for PCI-DSS, SOC 2, ISO 27001, and HIPAA reviews.

Manage from your AI agent

MCP integration: run scans and manage monitoring from Claude, Cursor, or your own agent - no dashboard login.

Post-quantum readiness

On our roadmap: flag whether your servers negotiate the hybrid post-quantum key exchange browsers are rolling out.

Multi-channel alerts

Notifications via email, Slack, or webhooks the moment something changes.

Every domain, one dashboard

Continuous external monitoring across all your endpoints, from three domains to thousands.

How It Works

Get started in minutes.

1

Create Account

Sign up and choose a plan that fits your needs.

2

Add Domains

Enter the domains you want to monitor.

3

Configure Alerts

Set notification preferences and thresholds.

4

Stay Protected

Receive alerts and reports automatically.

Why Monitor Your Certificates?

Prevent Service Disruptions

Expired certificates take down websites, leading to revenue loss and reputation damage.

Maintain Security Standards

Stay compliant with best practices and industry regulations.

Protect User Data

Properly configured TLS protects sensitive information from interception.

Build Customer Trust

Show commitment to security with properly maintained certificates.

  • Alerts on your channel

    Email, Slack, or webhook - pick what your team already uses.

  • Warn early, warn often

    Reminders at 30, 14, 7, 3, and 1 day before a certificate expires.

  • More than just expiry

    Untrusted roots, weak ciphers, bad EKUs, and known vulnerabilities - all checked automatically.

Don't Wait For Failures

TLS-related outages can cost thousands per minute. Proactive monitoring prevents costly disruptions.

Start Monitoring

Simple, Transparent Pricing

No hidden fees. Choose the plan that fits.

Unified Plans

Choose the right plan for your team

One simple subscription that includes team collaboration, SSL/TLS monitoring, and automated scanning.

Free forever

$0 forever

Start monitoring your certificates in minutes.

  • 1 domain monitored
  • On-demand manual scans
  • Urgent expiry email alert (7-day warning)
  • Claude Code plugin

Your first 30 days also include

  • Automated scans, hourly checks
  • Vulnerability scanning
  • Up to 3 domains
  • 50 alerts / month
  • Proactive 30-day expiry warnings

No credit card. After 30 days you stay on Free forever.

Starter

$9 /month

Starter plan - monthly billing

  • 1 team
  • 3 seats
  • 10 domains
  • Unlimited scans
  • Automated scans

Pro

$49 /month

Pro plan - monthly billing

  • 5 teams
  • 10 seats
  • 50 domains
  • Unlimited scans
  • Automated scans
  • Advanced analytics

Business

$199 /month

Business plan - monthly billing

  • 10 teams
  • 20 seats
  • 200 domains
  • Unlimited scans
  • Automated scans
  • Webhook notifications
  • Advanced analytics
  • Priority support

Enterprise

Custom

Enterprise-grade security monitoring with unlimited scale and dedicated support.

  • Unlimited team members
  • Unlimited domains
  • Custom scan schedules
  • Dedicated account manager
  • SLA guarantees
  • On-premise deployment options

Need a custom solution? Contact us for enterprise pricing.

Frequently Asked Questions

How often are certificates checked?

Depending on your plan, certificates are checked daily, hourly, or by the minute. You can also trigger manual scans anytime.

How will I be notified?

Via email, Slack, or webhooks at intervals you configure (30, 14, 7, 3, and 1 day before expiration).

Stay ahead of certificate expirations

Practical TLS monitoring tips and product updates. No spam, unsubscribe anytime.