What does Community's 50-endpoint soft limit do?
It nags. Community counts the assets you have enabled, and once
you are past 50 the console shows a notice on every page
suggesting Pro. Nothing else happens. Probes run on their normal
schedule, alert rules keep firing, and enabling asset 51 works
the same way enabling asset 12 did. There is no countdown, no
read-only mode, and no feature that quietly switches itself off.
Are the Pro and Enterprise bands soft as well?
No. Those are contract limits and the console enforces them. A
Pro 100 license declines target 101 and tells you which band
covers you. Everything already enabled carries on while you sort
the paperwork out, and moving up a band is a new license file
rather than a reinstall or a migration.
Which features actually need a Pro license?
The estate collection, which is most of what makes this a Windows
tool rather than an endpoint checker: agentless WinRM collection
over JEA covering certificate stores, IIS, SQL Server, the RDP
listener, the WinRM listener and HTTP.sys reservations; Active
Directory and AD CS discovery; GPO fleet deployment; the
off-domain push collector; and webhook alerting with escalation
recipients. Community keeps TLS endpoint monitoring with full
chain capture, subnet sweep and Certificate Transparency
discovery, email alerting, and the whole dashboard.
What does renewal automation actually do?
It renews certificates across the estate from one console.
Renewal for publicly trusted certificates over ACME is in Pro,
covering HTTP-01, DNS-01, and wildcards, against Let's Encrypt,
ZeroSSL, or any other RFC 8555 authority. Renewal against AD CS
templates for internal PKI is in Enterprise, including templates
that require a certificate manager to approve each request. Both
are included at no extra cost for any license inside its
maintenance window.
The private key is generated on the host that will use it and
never leaves; the console only ever handles the signing request
and the issued public certificate. After the new certificate is
installed and every binding moved, the same monitoring you
already run re-observes the host, and the renewal is only
considered done when the new fingerprint is present at every
binding with a valid chain. If it is not, the bindings go back to
the old certificate.
Subscription or perpetual?
Perpetual if you can get the money approved once, subscription if
you cannot. That is most of the decision. The subscription suits
starting small, and it suits a shop with operating money and no
capital line to draw on. A perpetual license suits an install you
mean to keep: it is yours once the payment clears, it keeps
working whatever happens to us or to your budget, and it costs
less to own over time.
How does a subscription license work?
Mechanically it is the same signed text file as a perpetual
license, dated to the period you have paid through. We reissue it
each time you renew and you paste the new block in. The dates
carry a grace margin on purpose, because an invoice sitting in
somebody's approval queue is normal and should not put a console
into a warning screen over it. If a subscription does lapse for
good, the installation drops to the Community feature set and
keeps monitoring: nothing is switched off, deleted, or hidden,
which is the same promise a lapsed perpetual maintenance window
gets.
Monthly, or one annual invoice?
Either. The annual price is ten times the monthly, so a year on
one invoice costs two months less than twelve monthly ones:
$790 for Pro 100, $1,990 for Pro 500, and
$4,990 for Enterprise. Public sector buyers almost always
want the annual invoice, because it goes against a purchase order
like everything else they buy. Monthly suits smaller shops that
would rather start without a procurement round. There is no
checkout on this site and no card billing behind it, so either
way it is an invoice from us and a payment from you.
What happens when a license expires?
The product keeps running. Probes and alert rules carry on for
what is already enabled, and nothing is deleted or hidden. What a
lapsed license changes is what the installation can do next: it
falls back to Community, so the Windows estate collection waits
for a current license and growth past the soft line earns you a
notice rather than a refusal. Paste a renewed file and it all
comes back.
How does licensing work on an air-gapped network?
The same way it works everywhere else. A license is a signed text
block you paste into Settings, and the console verifies it against
a public key compiled into the build. There is no activation
server, no online check, and no periodic revalidation, so a
machine that has never had a route to the internet is licensed the
same as one that has. The daily update check is a separate thing
entirely and has no bearing on licensing. On an isolated network
it fails quietly, or you turn it off and it never tries.
Can we have longer than 14 days to evaluate?
Yes. The in-console evaluation runs once for 14 days, but we can
issue a short-dated license file that does the same job for a
longer window. Ask for one at
sales@certcommand.app
and say roughly how many targets and how long. It installs like
any other license and reverts to Community when it ends.
Is the license tied to a specific machine?
No. The license carries a licensee name, an edition, a target
count, and its dates. There is no hardware fingerprint and no
machine binding, so rebuilding the app server is a matter of
pasting the same file back in.
What does the maintenance window actually cover?
Upgrades. Builds released inside the window are yours to install
and keep running forever, including after the window closes. The
first year comes with every purchase. Renewing after that is
optional and priced per edition, and letting it lapse costs you
newer builds and nothing else. It has no effect on monitoring,
alerting, or your target count.
How do we place an order, and can we prepay maintenance?
Email
sales@certcommand.app
with the edition and band you want, and whether you want it
outright or on subscription, and we will send a quote you can
attach to a purchase order. Quotes hold for 90 days, a W-9
comes with them on request, and purchase orders are accepted with
no credit card anywhere in the process. Multi-year maintenance
prepay is available on request, which is usually what a budget
cycle wants rather than a small invoice every year.
How exactly do you count targets?
A target is an enabled asset. A Windows host is one target however
many certificates, stores, and bindings it turns out to hold. A
TLS endpoint is one host and port pair. Disabling an asset frees
its slot, and items sitting in the discovery review queue are not
counted because nothing has contacted them yet.
Do you collect telemetry or usage data?
No. Nothing reports what you monitor, how many assets you have, or
who is signed in. Two features reach outward at all, both covered
below: the update check, and the optional Certificate Transparency
discovery source, which queries public CT data and ships off.
Does it check for updates, and can we stop it?
It checks a manifest over HTTPS once a day to see whether a newer
build has been published. That is on by default and one setting in
the console turns it off. If the manifest cannot be reached, the
check gives up quietly and nothing changes, which is what happens
on an isolated network. It never downloads or installs anything on
its own. Applying an update is always a deliberate step an
administrator takes.