Skip to content

Security

We cannot break anything on your side.

DomainVigil looks, and that is all. Here is exactly what it can do, and what it cannot do — even if we wanted to.

We never write anywhere

DomainVigil changes neither your DNS, nor your certificate, nor your domain at your registrar, nor the content of your site. It asks, it records what it saw, it writes to you. Software that could renew a domain for you could also lose one for you.

Nothing to install on your sites

No plugin, no agent, no FTP or SSH access to hand over. DomainVigil queries your domains from the outside, the way any visitor would — which is precisely what lets it see what your visitors see.

The Cloudflare token is read-only, and encrypted

If you import your Cloudflare account, the token you give us only needs permission to READ your zone list. It is encrypted at rest with AES-256-GCM, the key kept outside the database, and you can delete it at any time from your settings.

We read at the source

Expiry comes from the official registries, the certificate from the server presenting it, DNS records from the servers authoritative for your domain — not from a public resolver that might serve a stale answer. What you read in DomainVigil is what is actually published.

Three confirmations before we write to you

An outage must confirm itself three times in a row before an alert goes out. That is what makes a DomainVigil alert worth reading at three in the morning.