On-Demand TLS Reports for Any Domain with SSLBoard
For the past few years, SSLBoard was a subscription service. You signed up, added your domains, and it scanned them daily. It tracked certificate expiry, surfaced deployment issues, and sent alerts. It worked, but it also meant accounts, onboarding, pricing tiers, and the assumption that you’d keep paying to keep watching.
We scrapped all of that.
What SSLBoard is now
SSLBoard is now an on-demand TLS posture report. You type a domain, wait a few minutes, and get a structured assessment of its public TLS configuration. No account required.
Every report starts with a scored overview and prioritised findings. You see what’s wrong, how severe it is, and which hosts are affected. If you need more detail (per-host breakdowns, data tables, CSV exports), you can unlock the complete report.
The report covers certificates (expiration timelines, issuer distribution, key strength, SAN coverage), TLS versions (which endpoints still negotiate 1.0 or 1.1, which support 1.3, associated CVEs), cipher suites (3DES, RC4, EXPORT, NULL, CBC-mode issues mapped to the hosts that accept them), forward secrecy, key analysis (RSA vs. ECC distribution, key sizes), HTTP security (redirect behaviour and HSTS headers), connection errors (self-signed certs, chain issues, name mismatches), and post-quantum readiness.
Each report produces a weighted score broken down by category, so you can track improvement or compare across domains.
Why we changed direction
The SaaS model assumed teams would set up SSLBoard once, check it regularly, and rely on it as a persistent monitoring layer. In practice, most people wanted to answer a simpler question: how does our TLS look right now?
They didn’t want another dashboard. They wanted to run a scan before a compliance review, during an incident, when evaluating a vendor, or after a certificate rotation, and then move on.
An on-demand report fits that pattern better.
Who uses it
Security teams run a scan before an audit or after a major infrastructure change and share the report link with stakeholders who need to see findings without their own login.
DevOps and platform engineers use it to validate that a certificate rotation actually landed everywhere. It catches the one load balancer node still serving the old cert, the IPv6 endpoint that got missed, or the staging subdomain that expired three months ago.
Compliance and risk teams get a structured document with tables that map to the controls they need to evidence. The full report includes CSV exports.
And if you’re evaluating a third party, you can just type their domain. The scan only touches public endpoints, so there’s nothing to coordinate.
What we kept
The core analysis engine is the same one we’ve been building for years: Certificate Transparency log ingestion, active endpoint scanning across all resolved IPs, full TLS handshake analysis including cipher negotiation, and post-quantum readiness detection. None of that changed.
What changed is delivery. Instead of a dashboard you log into, you get a report you can read, share, and act on.
What’s next
We’re working on richer scoring models, historical comparison, and deeper PQC analysis. The format will stay the same: type a domain, get the answers.
If you’ve been putting off a TLS review because you didn’t want to set up another tool, try it now.