expiryledger.
SSL & domain tracking

No more expired-cert outages

Track SSL certificates and domain expirations across every site and client, with reminders long before expiry so nothing goes dark or gets snapped up.

No credit card required · Cancel anytime

The outage you can predict a year in advance

An expired SSL certificate produces one of the most damaging failure modes on the web: the site does not go down quietly, it actively warns every visitor that it is unsafe. Browsers present a full-page interstitial. Search crawlers and integrations that validate the certificate chain start failing. Customers who see the warning rarely proceed, and many do not come back.

What makes it particularly frustrating is that the date was known from the moment the certificate was issued. Nothing about the failure is a surprise except its timing, which is invariably a weekend or the middle of a holiday.

Auto-renewal reduces the frequency of this without eliminating it. Renewal automation fails in mundane ways — an expired payment card, a registrar account whose contact email no longer exists, a DNS validation record that was removed during an unrelated migration, an ACME client that stopped running after a server rebuild. In each case the automation reports nothing and the first real signal is the outage itself.

Sound familiar?

  • An SSL cert expires and a site throws browser warnings
  • A domain lapses and someone else registers it
  • Auto-renew silently fails and nobody notices
  • Certs and domains are spread across multiple providers

How ExpiryLedger prevents certificate and domain lapses

Reminders ahead of auto-renew

Set lead times far enough out that a silent renewal failure is caught with time to intervene manually before expiry.

One inventory across providers

Certificates and domains from different registrars and authorities tracked in a single list rather than several dashboards.

Calendar feed for the team

Subscribe to a private iCal feed so expiries appear alongside change windows in the calendar your team already watches.

Separate workspaces per client

Agencies and MSPs can keep each client's estate in its own organisation, isolated at the database level.

Custom fields for technical detail

Record registrar, issuing authority, environment, and renewal method as structured fields for fast triage.

Audit trail of renewals

Every renewal is recorded with who performed it and when, which is useful for client reporting and post-incident review.

Every certificate and name you depend on

Public SSL and TLS certificates
Certificates on public-facing sites and services where expiry is immediately visible to users.
Wildcard and multi-domain certificates
Certificates covering many hostnames, where a single lapse affects a broad set of services at once.
Internal and private CA certificates
Certificates on internal services that fail less visibly but break integrations and automation.
Domain registrations
Domains across registrars, where a lapse risks outage or loss of the name to a third party.
Code-signing certificates
Certificates whose expiry blocks releases and can invalidate distribution of signed artefacts.
DNS and hosting services
Managed DNS, hosting plans, and CDN commitments with their own renewal cycles.

Who tracks certificates in ExpiryLedger

Managed service providers

Track certificate and domain estates across every client from one place, separated per client.

Internal IT and infrastructure

Maintain a single inventory of expiring assets across environments and providers.

Web agencies and studios

Manage client domains and certificates without relying on registrar notification emails reaching the right person.

Platform and DevOps teams

Turn certificate renewals into planned work on the change calendar rather than incidents.

Track every certificate and domain

SSL CertificatesDomainsDNS RecordsTLS CertsCode-Signing Certs

Frequently asked questions

Does ExpiryLedger scan my domains to detect expiry dates?

No. ExpiryLedger is a tracking and reminder system rather than a monitoring scanner, so dates are entered manually or imported by CSV. Most teams export a list from their registrar or certificate authority once, import it, and maintain it as the estate changes.

We already use automated certificate renewal. Why track it?

Because automation fails silently. Expired payment cards, lapsed registrar accounts, removed DNS validation records, and ACME clients that stopped running after a rebuild all produce no alert. A reminder ahead of the expiry date gives you a window to confirm the renewal actually completed.

Can expiries appear in our team calendar?

Yes. Each workspace has a private iCal feed you can subscribe to in Google Calendar, Outlook, or Apple Calendar. Every tracked expiry appears as an all-day event and the feed updates automatically as items change.

How do I keep client estates separate?

Create a separate organisation per client and switch between them from one login. Each organisation has its own items, team members, and reporting, with access enforced at the database level so estates never mix.

Is there an API to sync from our inventory?

Not currently. CSV import and export cover bulk operations, and an iCal feed covers calendar integration. A public API is on the roadmap but is not available today.

How far ahead should certificate reminders be set?

Most teams set the first reminder 30 to 60 days ahead. That is enough time to validate that automated renewal worked, and if it did not, to complete a manual issuance and deployment without working against a deadline.

Stop tracking renewals in a spreadsheet.

See every upcoming expiry in one dashboard. Free for 14 days — no credit card.

Get started free