Free tier live now — useful on day one, no credit card

Your deadline-first operational radar

OpsBlip is operational asset lifecycle management for DevOps, IT, and agencies: expirations, notice windows, ownership, and public-surface drift — not just uptime. One workspace, no agents.

Lifecycle & renewalsDNS, TLS & endpoint driftAlerts, reminders & digestsFlows, findings & analyticsCSV import/exportSecurity, verification & admin

50 objects · 10 endpoints · Weekly scans · Alerts, reminders, digest, flows, analytics · Free forever (not a trial)

app.opsblip.com/app
Urgency queue
8notice windows open
OVERDUE

Let's Encrypt wildcard

Expired 3 days ago

30 DAYS

Cloudflare annual contract

Non-renewal window opens this week

Changed endpoints
DNS

api.northwind.io

NS drift detected from baseline

TLS

status.northwind.io

New certificate, approval needed

SSH

deploy.northwind.io

Banner changed after maintenance

How it works

From scattered spreadsheets to a deadline-first radar

Three steps for teams who need expirations, drift, and ownership in one place — built for real infrastructure portfolios, not toy monitors.

01

Model assets & import

Track 22 object kinds (domains, DNS, certificates, servers, databases, containers, cloud accounts, and more) with auto-renew, notice periods, and criticality. Bulk in via CSV; export columns you need. Verify your org domain to unlock onboarding and sensitive workflows.

02

Monitor public endpoints

Attach HTTPS, DNS, SSH, and TCP checks. Weekly scans compare results to approved baselines so drift surfaces as severity-based findings — no agents or firewall holes.

03

Act before deadlines bite

Email rules, in-app repeating reminders, drift notifications, and a weekly digest. Pair with flowchart runbooks for renewals, drift, and incidents while the dashboard keeps risk, renewals, and the operations inbox in view.

Features

Lifecycle, drift, and accountability in one workspace

Built for DevOps, IT, and agencies managing real infrastructure — deadlines, ownership, public-surface drift, and the workflows around them.

Deadline-first dashboard

Everything that expires or needs attention is front and center.

  • Risk change cards & renewal timeline
  • Owner workload & coverage
  • Scan freshness tracking
  • Decision queue & ops inbox

HTTPS & TLS monitoring

Public endpoint checks for expiry, hostname mismatch, chain changes, and drift versus an approved baseline.

  • Certificate expiry tracking
  • Drift vs. approved baseline
  • SSH banners & TCP port state

DNS drift detection

Watch A, AAAA, CNAME, MX, NS, and TXT for unauthorized changes, with nameserver sync validation across providers.

Baselines, flows & drift

Approve known-good state, then let scans surface drift. Use flowchart-style runbooks for incident response and renewal.

Findings & remediation

Severity-based findings with remediation tracking: acknowledge, resolve, snooze, or assign.

Alerts & reminders

Email rules, in-app reminders, deadline alerts, drift notifications, and a weekly digest.

Rich object model

22 asset kinds: domains, DNS, certificates, servers, databases, containers, cloud accounts, and more.

Timeline & audit trail

Full activity history with filtering. Actor and timestamp on every entry.

Analytics workspace

Customizable charts with forecasting, period comparison, drilldowns, and resizable widgets.

CSV import & export

Bulk import with duplicate detection. Configurable column export, formula-safe.

TOTP & session security

Authenticator-app codes, active session management, and recovery codes.

Support & admin ops

In-app support tickets plus admin portal for multi-org oversight.

Domain verification

Prove domain control before enabling sensitive workflows.

Monitor catalog

HTTPS, DNS, SSH, and TCP — compared to baselines

External checks against public endpoints: approve a baseline, scan on a schedule, and let drift show up as findings with alerts, digest, and runbooks — no agents or inbound firewall rules.

HTTPS / TLS

Live
  • Certificate expiry and chain summary
  • Hostname mismatch and issuer or serial drift
  • Scan-to-scan comparison against approved baseline
  • Severity-based findings when state diverges
  • Pairs with renewal flows and deadline alerts

DNS

Live
  • A, AAAA, CNAME, MX, NS, and TXT drift detection
  • Nameserver sync validation across providers
  • Baseline capture after you approve known-good records
  • Drift surfaced as findings with remediation tracking
  • Weekly scans with freshness visible on the dashboard

SSH banner

Live
  • Banner string change detection across scans
  • Useful for post-change verification workflows
  • Baseline comparison so only intentional drift alerts
  • Works with public endpoints only (no agents)
  • Feeds the same findings and alert pipeline as HTTPS

TCP port

Live
  • Fixed-port open, closed, or timeout drift
  • Service reachability from the external scanner
  • Approved baseline for expected availability
  • Change detection without opening your network
  • Complements TLS and DNS for layered coverage

OpsBlip focuses on operational lifecycle and public-surface drift; deeper synthetic transactions, browser journeys, and vuln scanning are natural extensions as the product grows.

Pricing

Free to start, built to grow

Start with a real free workspace now. Planned tiers add shared ownership, routing, and audit workflows when they launch.

Compare subscriptions in detail

Free

Available now
$0forever

For one real portfolio with one accountable owner. No credit card needed.

  • 50 tracked objects
  • 10 public endpoints
  • 1 owner on the default team
  • 2 manual resolution flows
  • Weekly scans and email alerts
  • Scan windows and maintenance holds
  • 1 external email recipient without user seats
  • 30-day history
Start free

Pro

Launching soon
$29/user/month

Launch pricing preview - final price confirmed at GA.

For small ops teams that need shared ownership, faster scans, and routing.

  • 500 tracked objects planned
  • 50 public endpoints planned
  • 5 members and custom teams planned
  • 50 shared resolution flows planned
  • Daily scans target with Slack and webhooks planned
  • Scan windows included at launch
  • 180-day history
  • Faster manual rescans and shared ownership planned
Upcoming release

Team

Launching soon
$99/month (up to 25 users)

Launch pricing preview - final price confirmed at GA.

For broader access control, auditability, and higher-scale deadline coverage.

  • 3,000 tracked objects planned
  • 250 public endpoints planned
  • 25 members with advanced roles planned
  • 250 cross-team resolution flows planned
  • 6-hour scans target and richer routing planned
  • Scan windows included at launch
  • 1-year history
  • Audit export planned after Team GA
Future release
Detailed comparison

Choose your perfect plan

Free is live and ready today. Pro and Team are coming soon — join the waitlist to get early access and launch pricing.

Free

$0 forever

Available Now
Core Platform
Object & endpoint tracking
Full access
Finding detection
Real-time
Tracking & Limits
Tracked objects
50
Public endpoints
10
Workspace members
1 owner only
Scanning & Alerts
Scheduled scan cadence
Weekly
Manual rescans
30min cooldown
Scan windows / maintenance holds
Included
Email alerts
Included
External alert recipients
1
Slack & webhook alerts
Workflows
Resolution flows
2 flows
Flow complexity
20 nodes/flow
Reporting & AI
Analytics & reports
Core + export
Deep Research AI
Data history retention
30 days
Security & Access
API access tokens
Audit log export
Advanced RBAC
SAML SSO
Security & trust

Isolation, strong auth, and traceability by default

Database-enforced tenancy, TOTP and session controls, encrypted scanner jobs, and a filterable audit timeline — baseline expectations for production operations data.

Row-level security

PostgreSQL RLS enforces tenant isolation in the database. Cross-org reads and writes are blocked by design so each workspace stays private.

TOTP, sessions & recovery

Time-based one-time codes from your authenticator app, recovery codes for lockouts, full session management, and password reset — not optional hardening, just how sign-in works.

Timeline-grade auditing

The in-app timeline captures object edits, endpoint and scan activity, imports, security events, and more with actor identity and timestamps for investigations and compliance-style review.

No agents on your estate

Monitoring originates from our scanner toward public targets only. No daemons on servers, no inbound holes, and a smaller blast radius than traditional inside-the-VPC agents.

Scanner SSRF guardrails

Only public-routable targets are accepted. Loopback, private, link-local, and multicast destinations are rejected before a job ever leaves the queue.

Encrypted scanner transport

Scanner traffic uses TLS, mutual authentication where applicable, pinned internal CAs, and short-lived signed job tokens so jobs are tamper-resistant end to end.

Free tools

What you get without paying

The free tier is built to run real portfolios: objects, endpoints, dashboard signal, imports, alerts, digest, and reminders — move to larger launch tiers when they go live, not because the starter tier expired.

In the app

Free HTTPS & drift checks

Attach TLS endpoints on the free tier: expiry, chain, hostname alignment, and drift versus an approved baseline — same findings pipeline as paid workspaces, with weekly scans.

Create free workspace
Included

Deadline-first dashboard (free)

Risk cards, renewal timeline, vendor heatmap, workload, ownership coverage, scan freshness, decision queue, and operations inbox — a genuinely useful free tier, not a time-limited trial.

Create free workspace
Included

CSV import & export

Bring your spreadsheet: import objects in bulk with duplicate detection, then export with configurable columns for finance, ITSM, or auditors — available on the free plan.

Create free workspace
FAQ

Common questions

Yes. Free includes 50 objects, 10 public endpoints, weekly scans, email alerts, repeating in-app reminders, the weekly digest, dashboard views, CSV import, configurable export, timeline, flows, analytics widgets, customizable email templates, support tickets, and 30-day history. No credit card and no trial countdown - it is meant to stay useful for real teams, not expire as a teaser.

Objects are operational assets you track across 22 kinds: domains, DNS zones, mail domains, certificates, servers, databases, containers, cloud accounts, APIs, storage, contracts, licenses, warranties, and more. Each supports deadlines, auto-renew flags, notice periods, criticality, and an accountable owner, and can have HTTPS, DNS, SSH, or TCP endpoints attached for drift monitoring.

HTTPS/TLS (expiry, chain, hostname mismatch, drift vs baseline), DNS (A, AAAA, CNAME, MX, NS, TXT with nameserver sync checks), SSH banners, and TCP port reachability. Scans run from our external scanner; you approve baselines so only meaningful drift becomes severity-based findings with remediation tracking.

Configure email rules for deadlines, drift, and other signals; add in-app repeating reminders and deadline alerts; and send a weekly digest so quieter issues still surface. Notification copy can follow customizable email templates, and free plans still support a small number of external recipients who do not need user seats.

Flows are flowchart-style runbooks inside the product for repeatable work: incident response, certificate renewal, domain renewal, and endpoint drift. They complement the dashboard and findings queue so teams execute the same steps when something crosses from signal to action.

A dedicated analytics area with customizable charts, forecasting, period-over-period comparison, drilldowns, and resizable widgets so you can explore risk and operational trends without exporting everything to a BI tool first.

After the first successful scan, you can approve a snapshot as the known-good baseline. Later scans compare to that approved state; drift drives findings and notifications instead of noise on every cosmetic diff.

Yes. Free plans include one external email recipient so finance, legal, or domain owners can receive deadline or drift mail without full user seats. Higher tiers expand routing and limits as they ship.

No. Monitoring is external to your public endpoints. That keeps firewall posture simple and aligns OpsBlip with lifecycle and drift use cases rather than inside-the-network instrumentation.

Workspaces can open in-app support tickets. Platform operators get an admin portal for multi-organization management: announcements, user lifecycle, recovery assistance, audit logs, and operational charts.

Pro and Team are planned but not yet generally available. Join the pricing waitlist to influence priority. Expect higher limits, faster scan cadence, richer alert routing, shared ownership models, and Team-grade audit controls as those tiers ship. API access and SSO remain planned work, not current MVP functionality.

Yes. CSV import creates or updates objects with duplicate detection. Export lets you choose columns and remains formula-injection safe for Excel or Google Sheets, so finance and auditors can keep working in familiar tools.

OpsBlipDeadlines & drift

Put expirations, drift, and ownership on one radar

Spin up a free workspace in minutes: import assets, wire up HTTPS, DNS, SSH, or TCP checks, and let the dashboard, findings, flows, alerts, and timeline carry you from signal to action.

Free tier built to stay useful · No credit card · Cancel anytime

Support the project

OpsBlip is free and community-driven. If it saves your team time, consider a donation to the project jar. Every contribution helps keep the lights on.

Donate via Mono Jar