Pricing

Simple, honest pricing

See every subdomain, cert, and lookalike the internet knows about your domain — then get alerted when it changes.

Agency

$49/mo

For dev shops watching several clients' domains.

  • Up to 10 verified domains under continuous monitoring
  • 6-hourly scans for near-real-time Certificate Transparency alerts
  • Email plus outbound webhook delivery for every alert
  • Per-domain baselines, alert history and CSV export
Get started

Everything in Solo, for up to 10 domains, twice as often, with webhooks.

The one-shot footprint report is always free — no account needed. Verifying a domain you own is free too. You pay only for continuous scheduled monitoring and alerts. Compare that to Censys or Detectify, which start in the hundreds per month and are built for security teams.

Before you ask

The three things everyone wants to know

Will this get my VPS abuse-reported?

No. Perimeter is passive by design — it reads Certificate Transparency logs, public DNS and RDAP registries. It never port-scans, fingerprints or sends unsolicited traffic to any host, including yours. The only outbound connection to a host you control is a single TLS handshake to read a cert's expiry, and only after you've verified you own it.

How is this different from just checking crt.sh myself?

crt.sh shows you a wall of JSON for one domain, once, when you remember to look. Perimeter runs that check for you on a schedule, folds in DNS drift and RDAP typosquat detection, keeps a known-good baseline, and emails you only the diff — the new subdomain, the expiring cert, the freshly-registered lookalike. You find out the hour it changes, not months later.

Is $19/mo worth it for one domain?

One missed incident costs far more: a leaked staging database, a lapsed cert taking your app dark for a workday, or a customer fooled by a lookalike domain. Perimeter is priced so a single caught incident pays for years of it — and you can start with the free report and the free-to-verify tier before paying a cent.

Common questions

FAQ

Is there a free path?

Yes. The one-shot footprint report is free and needs no account — run it on any domain, rate-limited to 3 per hour per IP. Creating an account and verifying a domain you own is also free. You only pay when you turn on continuous scheduled monitoring and alerts.

What happens when I hit my domain limit?

Solo covers 1 verified monitored domain; Agency covers up to 10. If you need more domains than your tier allows, upgrade from Solo to Agency, or contact us about overage for domains beyond Agency's 10. You can always run the free report on any domain regardless of tier.

What's the difference between the free report and a paid subscription?

The free one-shot report shows your current exposure — every CT-logged subdomain, cert expiry dates, DNS records, and registered lookalike domains — right now, with no account. A paid subscription adds continuous monitoring: scheduled scans (daily for Solo, every 6 hours for Agency), diffed against your saved baseline, with an email the moment anything new appears.

How does domain ownership verification work?

Before Perimeter monitors a domain, you prove you control it: either add a DNS TXT record — perimeter-verify=<token> at _perimeter.<yourdomain> — or serve the token at https://<yourdomain>/.well-known/perimeter-challenge.txt, then click Verify. Verification is free; only monitoring requires an active subscription.

Who's behind Perimeter, and where does my data live?

Perimeter is built and run by Thomas Peng (Apten Inc.), a solo founder self-hosting on the same kind of Caddy VPS you are — email reaches me directly at thomas@thomaspeng.ca. Your data is a small, self-contained record: the domains you watch, their known-good baseline, and your alert history. That's it — no third-party trackers, and you can export your alerts or ask for full deletion at any time. Everything Perimeter collects comes from public sources (Certificate Transparency, DNS, RDAP), so there's nothing secret about your infrastructure sitting in our database.

Why not just write a cron job against crt.sh myself?

You could — you self-host, so you script. But the parts that are actually annoying are the ones that stay annoying: generating homoglyph/typo/TLD-swap permutations and checking RDAP for each, keeping a baseline and diffing it without drowning in noise, deduping repeat alerts, tracking cert expiry, and then hosting and monitoring the monitor so it doesn't quietly die. Perimeter is that whole loop, maintained, for less than the time you'd spend keeping a script alive.

How do I cancel, and what happens to my data?

Cancel from your account page (or email support) — monthly, no contract. Monitoring stays active until the end of the period you've already paid for, then scheduled scans pause. Your saved baselines and full alert history are retained, so resubscribing picks up exactly where you left off. Ask us to delete your account and data entirely and we will.

Not ready to subscribe?

Run a free one-shot report on your domain — no account, no credit card. See every CT-logged subdomain, expiring cert, and registered lookalike right now.

See your free report first