Issues, renews and installs TLS certificates across an estate automatically — by orchestrating public certificate authorities, not by becoming one.
Why it exists
Nobody has an interesting certificate problem. They have a boring one that happens at 2am on a Sunday, because a certificate nobody owned expired on a system nobody remembered.
The solution manages the complete lifecycle — request, prove, issue, install, renew — on an automated schedule. It deliberately avoids acting as a certificate authority: it leverages public authorities, so the certificates it issues are already trusted by everything that matters.
What it does now
- Running in production on Braincap infrastructure
- Issuing and automatically renewing certificates through public authorities
- Installing certificates onto hosting panels and application delivery controllers
- No external tenants yet
Capabilities
- Renewal automation — certificates renew daily, ahead of expiry, with escalating alerts.
- DNS validation — domain control is proven by a DNS record. The system being certified never has to be reachable from the internet.
- Certificate installation — the system deploys results to TLS-terminating systems without re-binding or downtime.
- Multi-authority support — multiple public authorities behind a single interface.
- Dual approval — ordering and approval are separate roles for critical infrastructure.
- Audit ready — private material is encrypted at rest and scrubbed after use; every action leaves a permanent audit trail.
Roadmap
- Additional certificate authorities behind the same interface
Interested in this product?
Write to us or call directly. A person answers, not a form.