Certificates, risk, accountability

TLS operations with a clear command view.

CertCockpit turns scattered certificates into a controllable operations cockpit: discover, assess, assign, renew, and prove every change.

30 / 60 / 90

Expiry forecasts

A plannable view of certificates that will need attention soon.

100

Health score

A fast portfolio signal for expiry, ownership, automation, and policy risk.

SHA-256

Token hashing

Webhook tokens are stored only as hashes and can be disabled individually.

ULID

Non-guessable IDs

Certificates and workflows are referenced through robust public identifiers.

Live Operations Board

Health

92

Excellent

At Risk

7

30 days

Automation

84%

covered

Domain

api.certcockpit.test

Owner

Platform

Status

Active

Domain

*.prod.example

Owner

Security

Status

Review

Domain

vpn.edge.local

Owner

Network

Status

Renewal

Top finding

Production renewal is manual

Next action

Confirm owner

What makes CertCockpit useful

Everything certificate operations usually leaves scattered.

CertCockpit connects technical certificate data with the context operations teams actually need: who owns it, where it is deployed, whether renewal is automated, and which policies are failing.

Inventory

TLS inventory with operational context

Domains, wildcards, SANs, issuers, fingerprints, deployment targets, environments, owners, and assignment groups live in one place.

Risk

Health scores instead of guesswork

Policy checks evaluate expiry, ownership, crypto metadata, manual renewals, wildcards, and legacy signatures.

Discovery

Automated discovery

Remote scans check SaaS endpoints, load balancers, and clusters by TLS handshake. Webhook clients import local certificates without private keys.

Governance

Accountability becomes visible

The Action Center, audit log, and approval workflows make open work, changes, and approvals traceable.

Automation

Discovery that fits your infrastructure.

For systems that cannot send actively, CertCockpit scans remote targets through a TLS handshake. For servers with local certificates, webhook clients import PEM, CRT, CER, or DER-compatible files automatically and securely.

Remote Scans

HTTPS without HTTP

Capture the TLS handshake, certificate, and chain. No redirects, no HTTP requests.

Webhook Clients

One token per sender

Tokens are stored as hashes and can be disabled per server.

Import pipeline

01

Discover

Remote targets, webhook clients, and local scanners bring certificates into inventory automatically.

02

Assess

Policy findings prioritize critical certificates by expiry, crypto risk, and missing ownership.

03

Act

Action items, renewal workflows, and reports guide teams from signal to completed work.

Governance

Warnings become accountable work.

Action Center

Prioritize open work

Expiry, missing owners, failed scans, policy violations, and renewal confirmations become managed action items.

Audit Log

Prove every change

Create, update, renew, revoke, owner changes, user actions, exports, and integration changes become traceable.

Approval Workflows

Approvals for risky operations

Requested Approved Completed

Renewal requests, revocation requests, production wildcard approvals, and owner assignments get a controlled workflow instead of informal handoffs.

Ready for the full view?

Start directly in the CertCockpit workspace.