Skip to content

Quick start

This page takes you from a new account to a client whose certificates are being tracked and alerted on.

Have ready the name of one client and at least one of their public hostnames, for example example.com or portal.example.com. Tidehawk needs no agent and no access to the client’s servers.

  1. Go to app.tidehawk.co and start the sign-up.
  2. Enter your work email, a password of at least 12 characters, and your company name. You can also pick the PSA you use.
  3. Accept the terms and submit.

Your workspace starts a 14-day trial. See your trial.

2. Verify your email and secure your account

Section titled “2. Verify your email and secure your account”
  1. Open the email titled Verify your Tidehawk email, sent from noreply@tidehawk.co, and click the link. The link expires after 24 hours.
  2. Tidehawk sends you straight to Secure your account. Choose Set up a passkey, described in the app as “Recommended — most secure”, or set up an Authenticator app.
  3. On Save your recovery codes, store the codes somewhere safe, tick the confirmation, then select Continue.

Two-factor set-up happens before you reach the app. More detail is in two-factor authentication.

  1. Open Clients in the sidebar and select Add client.
  2. Enter the Client name. Industry and notes are optional.
  3. Under Domains to scan, paste one hostname per line. Add :port for a non-standard port, for example portal.acme.com:8443.
  4. Select Create & scan n domains.

The panel shows Discovering certificates…, then names each certificate as it is found. You can select Skip → View client at any point.

On the client page, the Certificates tab lists what was found with issuer, expiry date, days remaining and status. If a scan is still running you see a Discovery in progress banner that refreshes the page itself.

A first scan usually finishes in seconds. If nothing appears, read no certificates found.

Your workspace is created with a recommended ladder already switched on: certificate alerts at 60, 30, 7 and 1 days, and domain alerts at 60, 30 and 7 days.

  1. Open Alerts in the sidebar.
  2. Switch between the certificate and domain tabs to read the rules.
  3. Select Add rule to add your own, or open an existing rule to change its trigger, recipients and channels.

By default an alert emails the owners and admins of your workspace. Full detail is in alert rules.

Tidehawk re-scans every tracked domain for new certificates at least every six hours, and re-reads each domain’s registry expiry at most once a day. New certificates appear in Certificates on their own.