Forelight reads every SSL certificate logged to public CT logs (mandatory under RFC 6962) and alerts you the moment a cert appears on your domains — authorized or not.
Free tier · No credit card · Minutes of lag, not hours
crt.sh is a search tool, not a monitoring system. Forelight is a real-time alerting layer with structured enrichment and webhook delivery.
| Capability | Forelight | Manual crt.sh |
|---|---|---|
| Real-time alerts | Yes — webhook on issuance | No — manual search only |
| Watchlist filtering | Yes — monitor any apex domain | No |
| Company enrichment | Name, industry, hosting provider | Raw cert data only |
| Signal scoring | 1–100 risk/signal weight | No |
| Subdomain enumeration | Continuous, real-time | Periodic, manual |
| API access | REST + webhooks | No API |
| Free tier | Yes | Free but no alerting |
Set a watchlist on your apex domains. Every matching cert fires a signal via webhook or API.
A new subdomain cert appeared on your domain. Was it authorized? Continuous enumeration without polling.
*.yourdomain.com issued. Wildcard misissuance or broad-scope certs are a primary attack vector — catch them at issuance.
5+ certs in 24h against one apex domain. Automated tooling, staging spin-up, or attack infrastructure — flag it for review.
yourcompany.cn just got a cert. Recon, squatting, or unauthorized regional presence — visible the minute it happens.
Free tier · 100 requests/day · No credit card · Full API access