Nothing is probed until you accept it
Discovery fills a review queue. Contacting a host is a decision somebody makes on the Discovery page, not a default. Accept the entries you want and CertCommand creates the asset and probes it.
CertCommand inventories certificates across your Windows hosts and network endpoints, records every place each one is bound, and tells the right people before anything expires. One Windows Server, no agents on your hosts, no internet access required.
Agentless over WinRM Runs as a gMSA Read-only JEA endpoint
| Subject | Bound at | Left | Window |
|---|---|---|---|
| app12.corp.local | IIS / Default Web Site | 4d | |
| sql-clu01.corp.local | SQL Server / MSSQLSERVER | 11d | |
| www.example.org:443 | TLS endpoint / TLS 1.2 | 26d | |
| rds01.corp.local | RDP / listener | 58d | |
| vault.corp.local | Store / LocalMachine\My | 173d |
Discovery fills a review queue. Contacting a host is a decision somebody makes on the Discovery page, not a default. Accept the entries you want and CertCommand creates the asset and probes it.
Windows collection runs through a JEA endpoint that exposes three read-only functions in a NoLanguage session. Certificates come back as public DER. Private key material never leaves the host.
A single Windows service on Kestrel, running as a gMSA. No IIS, no database server, and nothing installed on the hosts you inventory. Licensing never touches the network. The daily update check is the one outbound call, and you own the switch.
Public TLS certificates were capped at 398 days in 2020, and the CA/Browser Forum has since voted to bring that ceiling down in stages toward 47 days. A job you did once a year turns into a job you do every few weeks, and every extra renewal is another chance to miss one.
The harder half is the certificates nobody issued on purpose. AD CS hands out certificates that never reach a spreadsheet. RDP generates its own. SQL Server, WinRM, HTTP.sys reservations, and a rack of appliances each hold something with an expiry date on it. The outage rarely comes from the certificate you renewed. It comes from the one you did not know was there.
Four jobs the product does today, and a fifth that retires the nag: renewal automation, over ACME under Pro and against AD CS under Enterprise.
01Discover
Four independent sources feed one review queue. If a source fails, the others still run.
02Monitor
Two collection paths, one inventory. Assets and certificates are separate records joined by bindings.
03Alert
Rules scoped globally, to a tag, or to one asset, with day thresholds you set.
04Deploy
One command on a domain controller stages the files and builds the GPO that does the rest.
binding types inventoried per Windows host
discovery sources feeding the review queue
GPO command to roll the collector role to an OU
day evaluation, unlimited targets, one click
endpoints on the free edition, with no time limit
network calls made to verify your license
Built for the people who inherited a domain, keep servers running past their warranty, and cannot justify a certificate platform priced per seat.
The discovery sources, both probe paths, the JEA role, and what the alert rules actually do.
What the app server needs, which PowerShell versions the targets need, and the quickstart in five steps.
Three editions with the prices on the page, offline license files, and what happens to monitoring when one expires.
The evaluation is one click in the console, covers unlimited targets, and needs no key from us. Binaries are not on public download yet, so email us and we will send the build.