Early access for infrastructure teams

The infrastructure trust control plane for certificates, secrets, and host access.

CertLocker gives DevOps, SRE, and security teams one governed place to issue and deliver certificates, store operational secrets, grant just-in-time SSH, verify live endpoints, and prove who accessed what.

See Platform Overview
Certificates Lifecycle, ACME delivery, probes
Secrets PEMs, credentials, configs
Host access JIT SSH, bastions, audit
CertLocker dashboard showing certificate, secret, token, host, and probe status

What changed

Certificate expiry is only the visible failure.

The real infrastructure trust problem is fragmented control: certs in one tool, SSH keys on laptops, secrets in scattered stores, cloud hosts imported by hand, and audit evidence stitched together after the fact.

Ops teams need live truth

Inventory is not enough. CertLocker checks what endpoints actually serve, which tokens exist, and which hosts are in scope.

Security teams need scope

Machines, users, and sessions should only get the certificate, secret, or host access they need.

Leaders need platform clarity

CertLocker is not a nicer expiry dashboard. It is the operational layer for trust workflows across infrastructure.

Auditors need evidence

Every certificate, secret, token, bastion, and access event belongs in one reviewable trail.

Control plane

One workflow for the assets that prove and protect trust.

Start with certificates. Extend the same scoped-token, RBAC, and audit model to secrets and just-in-time host access.

CertLocker certificate inventory and expiry status

Certificate operations

Issue, renew, rotate, deliver, and verify TLS certificates across HAProxy, Nginx, IIS, OpenVPN, MT4/MT5, internal services, and ACME clients.

  • Scoped certificate tokens for machine pull
  • ACME-compatible delivery and renewal
  • Live endpoint probes for served-certificate truth
Explore certificate lifecycle →
CertLocker private secrets management

Secrets management

Keep PEM material, credentials, configs, service secrets, and private operational values under the same control model as certificates.

  • System and private secret stores
  • Role-based access and team visibility
  • Secret activity tied into platform audit
Explore secrets management →
CertLocker bastion environments and host access

Just-in-time host access

Replace long-lived shared SSH keys with token-scoped access to hosts and environments, including browser terminal access when the operator path needs to be fast.

  • Time-limited SSH through bastion layers
  • Host and environment scoping
  • Access logs for incident review and compliance
Explore JIT SSH →

How CertLocker works

Centralize control. Scope every token. Verify production.

CertLocker gives teams a practical trust operating model without forcing every server, load balancer, or admin workflow into a new custom agent.

View All Features
1

Bring trust assets into one inventory

Certificates, hosts, secrets, tokens, channels, and teams live in one governed product surface.

2

Issue scoped credentials instead of broad access

Machine tokens, ACME clients, and SSH sessions get narrow permissions that can be rotated or revoked.

3

Deliver and verify where infrastructure runs

Servers keep using familiar ACME and SSH paths while CertLocker records delivery, endpoint checks, and access events.

CertLocker audit log with infrastructure trust events

Audit evidence

Answer infrastructure trust questions without rebuilding the timeline.

When something changes, CertLocker records the event close to the workflow: certificate issuance, token updates, ACME activity, secret access, host import, bastion access, and endpoint verification.

Who had access?

Review user, token, role, and group activity from one place.

What was served?

Probe production endpoints and compare live TLS against intended state.

What changed?

Trace certificate, secret, token, and host workflow changes over time.

What can be revoked?

Remove token or session access without chasing keys across machines.

Where it fits

Built for teams that own production trust.

CertLocker is built around infrastructure buyers who need reliability, access control, and evidence before compliance or outages force the issue.

Join early access before launch pricing locks in.

Join early access and help shape the control plane for certificates, secrets, and just-in-time host access.

View Early Access Pricing