TLS
The certificate actually being served
Sitewatch opens a connection to port 443 and reads the certificate the server hands back, then reports who issued it and the day it stops being valid. It is the certificate a visitor's browser would be given, not one looked up in a database.
A site behind a proxy is reported as proxied rather than as a reading, because the party serving that certificate is also the party renewing it, and there is nothing for you to act on.