Privacy Policy
Last updated: 2 September 2026This policy explains what data CloudNativeWorks ("we", "us") collects when you visit www.certautopilot.com and when you run the CertAutoPilot software, and what we do with it. It is written to match how the product actually works, so it is short.
The short version. CertAutoPilot is self-hosted. Your certificates, private keys, credentials, users, and audit trail live on your infrastructure, in your database. We have no access to any of it. The only data an installation ever sends us is a license-validation request — and with offline licensing, not even that.
1. The website
This website is a static site. It has no user accounts and no sign-up forms.
- Server logs. Like any website, our hosting provider records standard access logs (IP address, requested page, browser user-agent, timestamp) for security and capacity purposes. These logs are kept for a limited period and are not used to identify visitors.
- Analytics — only with your consent. We use Google Tag Manager to load website analytics, but the script is not loaded until you accept the cookie banner. If you decline (or simply ignore the banner), no analytics script loads and no analytics cookies are set — the site works exactly the same. If you accept, the tools may set cookies and collect usage data — pages visited, approximate location derived from IP, device and browser information — processed by Google under Google's privacy policy. We use this data only in aggregate. Your choice is stored in your browser and you can change it at any time via the Cookie settings link in the footer.
- Web fonts. Fonts are self-hosted on this site — rendering a page makes no request to Google Fonts or any other third-party font service.
2. The CertAutoPilot product
CertAutoPilot is installed and operated entirely on your own servers. Everything the product manages — certificates, private keys, ACME accounts, DNS and device credentials, discovery results, users, and audit logs — is stored in your own MongoDB instance, encrypted where applicable with keys that only you hold. None of this data is transmitted to us, and we have no means of accessing it.
The product contains no usage analytics and no telemetry. Its only communication with our infrastructure is license validation, and only when you use online licensing:
- What is sent: your license key, an installation fingerprint (an opaque machine identifier), and the product version.
- Where it goes:
license-api.cloudnativeworks.com, over TLS. - Why: to confirm the license is valid and read its certificate allowance.
If you activate an offline license instead, the installation makes no connection to us at all and can run fully air-gapped. Any other outbound connections the software makes — to certificate authorities, DNS providers, your distribution targets, or your notification channels — go to services you configure, under your own accounts, and never through us.
3. Email and support
If you contact us at support@cloudnativeworks.com, we receive your email address and whatever you choose to include in your message. We use it to answer you, handle licensing, and maintain the commercial relationship. Support correspondence is retained as long as needed for those purposes. Please do not send private keys or credentials in support requests; diagnostic material you share is used only to resolve your issue.
4. Sharing
We do not sell or rent personal data. The only third parties that process visitor data on our behalf are our website hosting provider (server logs) and Google (analytics and fonts, as described above). We disclose data beyond that only if legally required to.
5. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict its processing. Since we hold very little — essentially license records and support correspondence — exercising these rights is usually simple: email support@cloudnativeworks.com and we will respond. For data inside a CertAutoPilot installation, contact the organization that operates that installation; they are the data controller for it, not us.
6. Security
License records and support correspondence are protected with access controls and encryption in transit. Within the product itself, sensitive material is envelope-encrypted with AES-256-GCM under keys that never leave your infrastructure — the product's security model is documented in detail in the documentation.
7. Changes
If we change this policy, we will update this page and its "last updated" date. Material changes to what an installation transmits would additionally be called out in the product's release notes.
8. Contact
CloudNativeWorks — support@cloudnativeworks.com