Ready in minutes
Sign in via Magic Link or Microsoft, start the trial, then connect your first tenant with admin consent.
Quick flow
The typical onboarding flow from a customer perspective.
- Sign in with Magic Link or Microsoft.
- Start the trial: 14 days free, no payment details required.
- Connect a tenant (optionally with a domain or tenant ID) and grant admin consent.
- The first sync starts automatically; data usually appears within a minute.
- You receive an onboarding email with next steps.
Overview across all tenants
The overview shows what is urgent and whether monitoring works for every tenant.
What you see
A fast status check for all customer tenants.
- KPIs Overdue / Critical (≤ 30 days) / Due soon (31–90 days) / Fine across all tenants. Each tile opens the credentials page with the matching filter.
- The ten most urgent credentials right on the overview; clicking the app name opens every detail, the Entra link and snooze.
- "Credentials" page: every secret, certificate and Intune credential in one table with search, type filter, sorting and CSV export; filters persist in the URL.
- "Tenants" page: the state of each tenant (connected, sync error, connection lost, paused) with the last successful sync and actions such as "Reconnect".
- Ctrl+K opens search: pages, tenants and credentials in one field.
- Notices for payment status, a paused subscription and an exceeded license limit.
Tenant details and actions
Each tenant has a detail page with all app registrations and their secrets/certificates.
What's inside
Everything you need for the current tenant.
- All credentials of the tenant with type, expiry date and status, in the same table as the credentials page.
- Sync state with a plain-language error message and technical details.
- Actions: "Sync now", "Reconnect", a dedicated alert address per tenant, "Send test email", a per-tenant calendar link and "Disconnect" (monitoring stops).
Search, filters and export
Find what is critical quickly, across all tenants or within one tenant.
Filters and export
Every filter works on the complete data set.
- Search by app name, credential, client ID or tenant.
- Filter by status (KPI tiles) and type (secrets / certificates / Intune), freely combinable.
- CSV export of every match of the current filters; direct Entra portal link per credential.
Notifications
SecretExpiry notifies you by email and, if you like, in Teams or Slack as expirations get closer.
Settings
Configurable per account.
- Thresholds in days before expiry (default: 90, 30, 14, 7, 1).
- Cadence: "Immediately" sends one email per tenant per threshold as soon as it is reached; "Weekly" sends a summary per tenant every Monday. The cadence applies to the whole account.
- Recipient: optional notification email, otherwise your login email; each tenant can have its own address. The address only changes the recipient, not the cadence or thresholds.
- Teams or Slack webhook: receives the same alerts for every tenant (Slack as a text message, Teams as an Adaptive Card).
- If there are many alerts: one email per tenant with the 30 most urgent entries plus the total count; the channel gets the ten most urgent.
- Snooze: take a credential out of alerts, the urgent list and the counters until a date. It stays visible in the tables.
- Mark as reviewed: permanently take an expired credential that was replaced or is no longer used out of the urgent list, the counters and the alerts. Expired credentials whose app already holds a newer valid one are shown as "replaced" automatically.
- After an expiry under monitoring, "Immediately" reminds you once more after 7 and after 30 days; legacy credentials that were already expired when you connected get no reminders.
- Calendar feed: every expiry date as an ICS feed for Outlook or Google, per account or per tenant.
- If consent is revoked or the sync keeps failing, you receive a notice email immediately, regardless of the cadence.
- "Send test email" sends a sample alert to the address real alerts would use and triggers the webhook.
- E-mail format: HTML (formatted) or plain text, for ticket systems such as Autotask that flatten HTML mails into text. Applies to all notifications; the info icon in the settings shows the difference.
Billing and licenses
You pay per tenant and choose monthly or annual billing.
Key points
Transparent control of your licenses.
- Licenses define how many tenants are actively monitored.
- If you exceed the limit, the most recently connected tenants are paused; the overview names them.
- Subscription management runs through Stripe.
- Active plans sync daily; without an active subscription, monitoring is paused.
Security and privacy
The architecture is privacy-first - we only see metadata.
What we do (not) read
We store no secret values.
- We request metadata only and store no secret or token values. Microsoft does not release client secret values; it may include the value of a VPP token in a response, which is discarded on read.
- Via Microsoft Graph we read app names, IDs and expiry dates, and from Intune the ID, expiry date, organisation or token name and Apple ID.
- EU hosting (Frankfurt) plus TLS and AES-256 encryption.
- Row-level security, CSP, and rate limiting protect your data.
API and integrations
There is no public API at the moment. For integrations there is the Teams/Slack webhook and the calendar feed (ICS).
Integration status
Webhook and calendar feed live in Settings. Reach out to support if you need further integrations or exports.