Scroll
Self-hosted · Enterprise · On-Premise

Certificate lifecycle on autopilot.

Discover certificates across your network, automate issuance and renewal via ACME and Microsoft AD CS, and distribute to your entire infrastructure. One platform, relentless auto-renewal.

250+REST endpoints
10CA providers
18DNS providers
17Distribution targets
24/7Automated renewals
47-daySC-081 Ready
PQCAssessment
AES-256Envelope encryption
PKCS#11HSM support
certautopilot.local/dashboard
CertAutoPilot Dashboard Certificate Detail View 47-Day Readiness Dashboard
Real-time overview with CA usage breakdown, renewal trends, and action items
Features

Everything you need for certificate management.

From issuance to distribution, CertAutoPilot handles the full certificate lifecycle with enterprise-grade security and compliance.

Certificate Lifecycle Automation

Automated issuance, renewal, and revocation via ACME v2 and Microsoft AD CS, validated by DNS-01 (automatic through 18 DNS providers), HTTP-01, or manual DNS, with ACME Renewal Information (ARI) honored on renewal. Supports Let's Encrypt, Google Trust Services, Sectigo, DigiCert, and more. Already have a certificate? Import externally-issued certs (bring-your-own) to distribute and track them alongside CA-managed ones. Managed certificates are continuously re-checked against OCSP and CRL, so a CA-side revocation is detected and alerted on.

ACME v2DNS-01 · HTTP-01ARICES/CEPWSTEPBring-your-ownOCSP/CRL10 CAs

Certificate Discovery

Scan networks, monitor CT logs, and pull hostnames from DNS zones (AXFR) and cloud DNS (Cloudflare, including proxied records, and Google Cloud DNS) to build a complete inventory. Automated security findings, drift detection, PQC assessment, and managed transition.

CIDR scanCT logAXFRCloud DNSDriftPQC

Multi-Target Distribution

Deploy certificates to 17 built-in targets with fan-out execution, dry-run validation, and versioned rollback on all 17 modules. Pick IIS sites and bindings, Kubernetes Secrets, Vault paths, Exchange servers, PAN-OS objects or cloud certificates (Azure Key Vault, AWS ACM, Cloudflare) straight from the live target, and preview which IIS bindings a deploy will touch. Agentless architecture — no agents to install.

SSHK8sIISF5Vault

Approval Workflows

Request/approve/reject flow with preflight warnings for certificate operations, configuration changes, and distribution actions. Self-approval blocked. Integrated with the notification system.

RBACPreflight

Multi-Tenant RBAC

Owner, Admin, Operator, Viewer hierarchy with project-scoped permissions. LDAP/AD integration, 2FA, JWT with refresh-token reuse detection.

4-tierLDAP/AD2FA

Domain Monitoring

WHOIS expiry tracking, SPF/DMARC/DNSSEC/CAA health checks, and dangling-DNS takeover detection across your domain inventory.

WHOISDMARCDNSSEC

Tamper-Proof Audit

HMAC-chain integrity verification on all audit entries. Event sourcing for complete certificate lifecycle timeline. Syslog forwarding in RFC 5424, CEF (ArcSight/Splunk), or LEEF (QRadar).

HMAC chainSyslogSIEMCEF / LEEF

Dashboard & Observability

Prometheus metrics, OpenTelemetry tracing, and 47-day readiness scoring. CA usage breakdown, renewal trends, and live action items.

PrometheusOTelSC-081

API & Automation

250+ REST API endpoints with JWT Bearer authentication, project-scoped RBAC, Go template variables, webhook events, and full CI/CD integration. Everything in the UI is in the API.

RESTWebhooksGo templates

PQC Readiness

Classify Post-Quantum Cryptography readiness per certificate across your inventory. Identify which certs are vulnerable today and plan migration.

Per-certClassify

Envelope Encryption

AES-256-GCM with per-field DEK/KEK architecture. Private keys, credentials, and secrets encrypted at rest with versioned key management — or keep distribution credentials out entirely and read them live from HashiCorp Vault, OpenBao or ManageEngine PAM360 on every use. Never stored, never cached.

AES-256-GCMDEK/KEKExternal secret stores

Smart Notifications

Email, Slack, Microsoft Teams and signed generic-webhook alerts for 26 event types with templates. Renewal failures, expiry windows, distribution and rollback status, approvals, domain health, and discovery changes.

EmailSlackTeamsWebhook
Discovery & Visibility

Find every certificate in your network.

Scan networks, monitor Certificate Transparency logs, and read hostnames from DNS zones and cloud DNS. Identify risks, track changes, and transition to managed lifecycle.

01

Network Scanning

Define IP ranges and ports. The discovery engine connects to each endpoint, retrieves TLS certificates, and builds a real-time inventory with cipher suite analysis.

02

Security Findings

Actionable findings with severity levels and remediation guidance. Weak ciphers, deprecated TLS, expiring certificates, and PQC vulnerability assessment.

03

Drift Detection

Schedule recurring scans to detect certificate replacements, issuer changes, and key rotations. Track change history and get notified on drift events.

certificate-discovery live
How it works

From configuration to delivery.

Set it up once. CertAutoPilot handles the rest — continuously, reliably.

Discover & Configure

Scan your network for existing certificates. Configure CA providers, DNS credentials, and distribution targets.

→

Issue Certificates

Request certificates via ACME or Microsoft AD CS with policy enforcement and optional approval workflows.

→

Distribute

Deploy to SSH, Kubernetes, IIS, F5, NetScaler, Vault, and cloud providers with dry-run validation.

→

Auto-Renew

The scheduler monitors expiry windows and automatically renews and redistributes before certificates expire.

↻
Ecosystem

Certificate authorities, DNS providers,
and native integrations.

Connect to your existing infrastructure with native integrations — no adapters or agents required.

— Certificate Authorities

Let's EncryptFree DV · ACME
Google TrustEAB auth
SectigoDV · OV · EV
DigiCertIndustry CA
GlobalSignAtlas ACME
SSL.comDV · ACME
ZeroSSLFree 90-day DV
ActalisEuropean CA
GoDaddyDV · OV · EV
Microsoft AD CSCES/CEP · WSTEP

— DNS Providers for Challenge Validation

Cloudflare
AWS Route 53
Google Cloud DNS
Azure DNS
DigitalOcean
GoDaddy
Lightsail
UltraDNS
Akamai EdgeDNS
Hetzner
OVH
Namecheap
RFC 2136
Windows DNS · WinRM
Hostinger
cPanel · WHM
Plesk
DirectAdmin

— Distribution Targets

SSH
Kubernetes
IIS
Windows · WinRM
F5 BIG-IP
Citrix NetScaler
HashiCorp Vault
Huawei Cloud
AWS ACM
Azure Key Vault
Cloudflare
Webhook
Email · SMTP
Microsoft Exchange
MerlinCDN
cPanel · WHM
Palo Alto PAN-OS

— Integrations & Observability

Slack
Microsoft Teams
Email · SMTP
Webhook
Prometheus
Syslog · SIEM
Comparison

How CertAutoPilot stacks up.

Self-hosted, agentless, and built for the post-quantum, 47-day-renewal era.

Feature CertAutoPilot Venafi TLS Protect Sectigo CM ManageEngine KMP
Self-Hosted / On-Premise✓✓Cloud only✓
ACME Protocol✓✓✓✗
Microsoft AD CS✓✓✗✓
Distribution Modules17 built-inCustom adaptersLimitedAgent-based
SSH · K8s · IIS · WinRM · F5 · NetScaler · Vault · Huawei · AWS ACM · Azure KV · Cloudflare · cPanel/WHM · Webhook · SMTP · Exchange · MerlinCDN · PAN-OS✓ All nativePartial✗Partial
Certificate Discovery✓ Network · CT logs · AXFR · Cloud DNS✓✓✓
47-Day Readiness (SC-081)✓✗✗✗
PQC Readiness Assessment✓Roadmap✗✗
Agentless Architecture✓Agent required✓Agent required
HSM Key Storage (PKCS#11)✓ PKCS#11 — validated on Fortanix DSMPaid tierCloud-managed only✗
KEK Rotation (Fleet-Aware)✓ Zero-downtimePaid tier✗✗
Versioned Rollback (every module)✓ All 17 modulesPartial✗✗
Approval Workflows✓ Issuance + distribution✓LimitedPartial
Tamper-Evident Audit + SIEM (CEF / LEEF)✓ HMAC chain✓✓Partial
External Secret Stores (Vault / OpenBao / PAM360)✓ Read on every usePartial✗✗
All Features, Every Tier✓ No paywallsPaid tiersSubscriptionPer-cert
FAQ

Frequently asked questions.

What infrastructure does CertAutoPilot require?+

CertAutoPilot requires MongoDB 6.0+ as its primary data store. The application runs as a single Go binary that can operate in three modes: API server, worker, and scheduler. For small deployments, run all three modes in a single instance. For high availability, run several replicas against a MongoDB replica set — the scheduler is leader-elected, so only one instance runs the sweeps at a time. Install with the standalone Linux installer (including a one-command multi-node install that builds its own MongoDB replica set), Docker Compose, or the Helm chart.

Can it run in air-gapped environments?+

Yes. CertAutoPilot is fully self-hosted with no external service dependencies. For certificate issuance in air-gapped environments, use Microsoft AD CS (internal CA) instead of public ACME providers. All data stays within your network. SSRF protection prevents unintended outbound connections.

How are private keys and credentials stored?+

All sensitive data is encrypted using envelope encryption: each field gets a random AES-256-GCM data encryption key (DEK), which is itself encrypted by a key encryption key (KEK). The KEK version is tracked per record for seamless key rotation. Private keys are stored in a separate collection from certificates, and credentials use the same envelope encryption pattern. Alternatively, a distribution credential can reference an external secret store — HashiCorp Vault, OpenBao or ManageEngine PAM360 — in which case CertAutoPilot stores no value at all: the credential is read from your secret manager at the moment it is used, never cached, so a rotation on your side takes effect immediately.

How does certificate distribution work?+

Distribution uses a module system with 17 built-in targets: SSH, Kubernetes, IIS, Windows (WinRM), F5 BIG-IP, Citrix NetScaler, HashiCorp Vault, Huawei Cloud (ELB/CDN/WAF), AWS ACM, Azure Key Vault, Cloudflare, cPanel/WHM, Webhook, Email (SMTP), Microsoft Exchange, MerlinCDN, and Palo Alto PAN-OS. Every module supports Execute, DryRun, and Validate. Rollback is centralized and versioned: all 17 modules can re-deploy any retained previous certificate version through the module's normal deploy path, either from a version picker in the UI or automatically after a failed run (push modules like Webhook and Email re-send the previous version). Large distributions can use fan-out execution — splitting targets into batches with configurable concurrency (enabled via a configurable threshold). Post-distribution validation verifies certificate deployment via TLS fingerprint checks.

What happens when a renewal fails?+

The scheduler automatically retries failed renewals on an escalating backoff ladder (15 minutes up to 24 hours), and a safety-net sweep keeps re-driving a failing certificate every couple of days until it renews or actually expires. Notifications are sent via your configured channels (Email, Slack, Microsoft Teams, generic webhooks) when renewals fail or when certificates approach critical expiration windows. The dashboard shows real-time renewal status, and the 47-day readiness score tracks your automation coverage.

Does it support approval workflows?+

Yes. Certificate operations (issue, renew, reissue, revoke, download), configuration changes, and distribution actions can require approval before execution. Operators submit requests with preflight warnings, and designated approvers can approve or reject with comments. Self-approval is blocked. The approval workflow integrates with the notification system so approvers are alerted immediately.

What about API access and automation?+

CertAutoPilot exposes 250+ REST API endpoints under /api/v1. Automation authenticates with JWT Bearer tokens — create a dedicated least-privilege service user per pipeline and scope it to a project with the built-in RBAC roles. Go template variables are available for dynamic configuration. All operations available in the UI are also available via API, enabling full CI/CD integration.

How does certificate discovery work?+

Define discovery sources with CIDR ranges, hostnames, and port lists — or let CertAutoPilot find the hostnames for you from Certificate Transparency logs, DNS zone transfers (AXFR), and cloud DNS (Cloudflare and Google Cloud DNS). The scanner connects to each endpoint, performs a TLS handshake, and captures the certificate chain with cipher suite information. Results are stored as an inventory with security findings (weak ciphers, deprecated TLS, self-signed certs, PQC vulnerability). Recurring scans detect drift — certificate replacements, issuer changes, and key rotations — with full change history per endpoint.

Ready to take off

Automate your certificates.
End the renewal panic.

See how CertAutoPilot can discover, manage, and distribute certificates across your entire infrastructure.