FAQ
Setup and access
Section titled “Setup and access”Do I need to install an agent? No. Tidehawk discovers certificates from public certificate transparency directories and from a TLS connection to the hostname. Nothing is installed on your clients’ servers.
Do you need credentials for my clients’ systems? No. Everything Tidehawk reads about a certificate or a domain is publicly available.
What are the password requirements? At least 12 characters.
Do I have to set up two-factor authentication? Tidehawk takes you through it immediately after sign-up, on the Secure your account step, where you choose a passkey or an authenticator app and then save your recovery codes. See two-factor authentication.
How long do sessions last? Seven days, rolling.
Clients and domains
Section titled “Clients and domains”Is there a limit on domains or certificates? No. Only clients are limited, and the limit depends on your plan. See client limits.
Why can’t I put two different domains on one client?
Each client is anchored to a single registrable domain, so acme.com and portal.acme.com belong together but acme.co.uk needs its own client. Tidehawk names both domains in the message and suggests creating a new client.
Why was my domain refused as an overlap? Because a domain your workspace already tracks sits inside, or contains, the same subdomain tree. A transparency lookup for the parent already returns the child’s certificates, so tracking both would scan the same tree twice. See add domains.
Can I track a service that is not on port 443?
Yes. Add the port to the hostname, for example portal.acme.com:8443.
Can I track an internal hostname or an IP address?
No. Tidehawk connects from the internet, so a tracked target has to be a publicly resolvable domain name. IP addresses and single-label names such as localhost are rejected.
What is the difference between archiving and deleting a client? Archiving hides the client, keeps every certificate and all history, frees a slot against your plan limit, and can be undone. Permanent deletion removes the client, its domains, its certificates and its history, and cannot be undone. See archive or remove a client.
Who can delete a client permanently? Owners and admins. Technicians can archive but not delete.
Discovery
Section titled “Discovery”How quickly does a new certificate show up? Every tracked domain is re-scanned at least every six hours. To see a new certificate sooner, open the client and select Re-scan.
How often is a domain’s registry expiry re-checked? At most once a day.
Why does a scan say it is taking longer than usual? It is most likely waiting for a transparency directory’s rate-limit window to refill. Tidehawk waits for a complete scan rather than falling back to a thinner source. See scan is stalled or deferred.
What does a degraded scan mean? Only the live TLS connection ran, and no transparency directory answered. It still finds the certificate being served, but it can miss issued certificates that are not currently deployed. The next sweep tries the directories again.
Certificates and status
Section titled “Certificates and status”Can I change the 7-day and 30-day status thresholds? No. Those decide the colour of a row and are fixed. What you can change is when you are told, which is what alert rules control. See certificate status.
Why is a certificate green when I have already had an alert about it? Because the two are separate. A new workspace alerts at 60 days, while the amber warning tier starts at 30. A certificate 45 days out is genuinely healthy and genuinely worth an early warning.
What happened to the old certificate after a renewal? It was superseded. It leaves the inventory, reads Resolved, its open alerts are resolved and any PSA tickets those alerts raised are closed. See renewals and supersession.
Why has a certificate disappeared from the inventory? Either a renewal superseded it, someone marked it renewed, it was revoked, or its track was set to Excluded.
Does starring a certificate change anything? No. Stars are a personal watchlist that appears on your dashboard. They are private to your account and do not affect urgency or alerting.
Alerts and email
Section titled “Alerts and email”Who receives an alert email by default? The owners and admins of your workspace. A rule can instead name specific addresses.
Why did a technician not get the alert? Because the rule had no explicit recipients, so it went to owners and admins. Add the address to the rule.
An email never arrived. Work through emails not arriving. The usual causes are a notification toggle, a rule addressed elsewhere, or a suppressed address.
Does Tidehawk renew certificates or domains for me? No. Tidehawk tells you what is expiring and when, and raises the ticket. Renewal stays with you and your client’s registrar or certificate authority.
Billing and data
Section titled “Billing and data”Which PSAs are supported? HaloPSA, ConnectWise, Autotask, NinjaOne and Syncro. See PSA integrations.
What happens when my trial ends? The workspace becomes read-only. Monitoring continues, but changes are blocked until you choose a plan. See your trial.
Is there overage billing if I go past my client limit? No. The limit is a hard cap. Creating another client is refused, and you either upgrade or archive a client to free a slot.
Where is my data held? See where your data lives.
How do I get my data out? Use Export CSV on the certificate inventory for a certificate list, and export your data for a full account export.
Still stuck
Section titled “Still stuck”Email support@tidehawk.co or use the form at https://tidehawk.co/contact.