Watch Certificate Transparency logs for your domains, and act on what shows up
Cert Spotter watches Certificate Transparency logs for certificates issued against your domains. Connect it and Luumen can read your monitored domain list, pull issuance history for any name, and open up a single certificate event during an investigation. Adding a domain to monitoring, or authorizing a certificate you recognize, runs as an approved step.
9 tools: 5 read, 4 write. Reads answer instantly. Writes require approval by default. Everything is logged.
What a governed SSLMate Cert Spotter API run looks like inside Luumen.
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Read actions answer immediately. Anything that writes — add monitored domain, authorize certificate, authorize public key, delete monitored domain — is shown as a plan and requires approval by default, including the 1 action classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Every call to SSLMate Cert Spotter API — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.
Connect in minutes. Every action scoped, approved, and audited from day one.