Transparent by design

Evidence has a source, a timestamp, and a limit.

CertificateScan is designed to help analysts investigate public infrastructure without disguising inference as fact.

01

Observe

Consume append-only Certificate Transparency logs and licensed historical indexes. Each source observation retains its log identity, index, and timestamp.

02

Normalize

Parse X.509 fields into a stable schema and coalesce duplicate precertificate/final-certificate events without discarding provenance.

03

Connect

Create evidence-backed relationships among certificates, SANs, issuers, public keys, and separately observed live endpoints.

04

Verify

On explicit request, perform a standard public TLS handshake. The resulting observation is timestamped and never substituted for passive CT history.

Interpretation guide

What the data can—and cannot—tell you.

A CT record proves a certificate was logged.

It does not prove the certificate was deployed, trusted by every client, or controlled by the named organization.

A failed live observation is not proof of absence.

DNS, firewalls, geography, rate limits, and transient failures can all prevent a successful connection.

Relationships always carry evidence.

Shared SANs, keys, or endpoints are useful pivots, not automatic proof of common ownership.