Frequently asked questions

Know exactly what Gapis does—and what it will never touch.

Gapis is intentionally narrow: independent observation of public HTTPS endpoints on ports 80 and 443.

What problem does Gapis solve?
Gapis catches certificate, DNS, redirect, and HTTP security-header drift from outside your infrastructure. It verifies the result a public client receives, independently of renewal jobs, deployment logs, or a cloud control plane.
What does a scan check?
A scan observes A, AAAA, CNAME, NS, and CAA DNS records; the served certificate, chain, hostname match, expiry, issuer, SANs, negotiated protocol and cipher; bounded legacy TLS support; HTTP-to-HTTPS behavior and a bounded redirect chain; final status; and HSTS, CSP, nosniff, frame, and referrer-policy headers.
Do I install an agent or provide cloud credentials?
No. Enter a public hostname and Gapis checks it from the public internet. It does not require a cloud role, DNS API token, certificate private key, inbound network rule, or code change.
How does Gapis prevent server-side request abuse?
Gapis accepts hostnames rather than arbitrary URLs or ports. It rejects IP literals and non-public addresses, pins connections to validated public resolutions, preserves TLS SNI and HTTP Host, revalidates redirect targets, allows only HTTP and HTTPS, and enforces redirect, size, concurrency, and timeout limits.
Is this a vulnerability scanner or uptime monitor?
No. Gapis does not probe arbitrary services, crawl content, scan application vulnerabilities, publish status pages, or claim continuous uptime measurement. It focuses on configuration drift at the public DNS, TLS, and HTTP edge.
What data does Gapis store from my endpoint?
Gapis stores technical metadata needed for observations, findings, comparisons, and scan history. It does not persist response bodies, cookies, query strings, authorization headers, or credentials sent by the monitored service.
How are changes detected?
Each successful scan produces normalized observations. Gapis compares those fields with the saved prior baseline and shows the old and new values, so a certificate, address, redirect, protocol, or header change is explicit.
When do I receive alerts?
All plans show in-app incidents. Paid plans can also send email alerts when the service operator configures SMTP delivery. Acknowledging a known finding preserves the underlying scan and audit history.
Can I run a scan immediately?
Yes. The first scan starts when you add an endpoint, and you can request a rescan from its detail page. Reasonable rate limits prevent accidental or abusive repeated scanning.
Can I export or delete my account data?
Yes. Account settings include a machine-readable export and permanent account deletion. Deletion removes customer-owned monitoring data subject to limited records that must be retained for security, billing, fraud prevention, or legal obligations.
Which plan should I use?
Free is sufficient for one endpoint and daily checking. Operator fits an individual managing up to 10 hostnames who needs six-hour checks and 90-day evidence. Fleet covers up to 50 hostnames with hourly checks and one-year scan and audit history.
Does Gapis issue or renew certificates?
No. Certificate issuance stays with your existing ACME client, CDN, proxy, or certificate authority. Gapis independently confirms what that system ultimately serves to users.

See the public result for yourself.

Add one endpoint and get a complete baseline on the Free plan.

Monitor an endpoint