CertControl gives security teams full visibility across certificates, TLS exposure, internal networks, and attack paths — in one unified platform.
14-day free trial · No charges during trial · Cancel anytime
CA/Browser Forum has voted to reduce TLS certificate lifetimes to 47 days by March 2029. The transition starts March 2026. Manual tracking will not survive this.
Learn more ↓Certificate expiry is only part of the story. Hidden services, weak TLS, exposed admin ports, and disconnected findings are where incidents begin.
Assets appear faster than teams can inventory them. Shadow infrastructure operates in silence — until an attacker finds it first.
Manual tracking via spreadsheets breaks down. One missed renewal takes down login flows, APIs, and customer-facing services.
Deprecated protocols, weak cipher suites, and missing security headers quietly expand your risk surface without triggering any alarms.
Most tools show isolated issues. Very few show how exposed services, CVEs, and business systems connect into real attack paths.
The CA/Browser Forum has unanimously voted. The timeline is set. For most organisations, this represents an 8× increase in renewal frequency — and spreadsheets simply won't scale.
CertControl tracks every certificate, alerts before expiry, and supports ACME/Let's Encrypt automation to remove the manual burden entirely.
Built for teams that need real operational control, not five separate tools that don't talk to each other.
Track every certificate — expiry, chain health, revocation, SAN validation, and risk scoring across all environments.
Detect weak protocols, deprecated ciphers, and missing security headers. Full A+ to F grading per endpoint.
See how CVEs, shadow assets, and open ports connect into exploitable paths from internet to critical systems.
Four professional report types: Executive Summary, Operational Risk, Expiry Forecast, and Change/Drift detection.
From real-time scanner operations to board-ready executive reports.
Cloud-only tools miss internal assets. CertControl deploys a lightweight Docker agent behind your firewall — it scans locally and pushes only metadata outbound.
Outbound HTTPS only. No inbound ports, no VPN, no remote execution.
Internal hostnames replaced with [masked] before data leaves your network.
Alpine-based, non-root. Runs anywhere Docker runs. No database.
Local disk spool queues results when cloud is unreachable. Never lose scan data.
How the agent works
TLS scan · OCSP check · HTTP headers · Service fingerprint · Hostname redaction
Unified dashboard · Security scoring · Expiry alerts · Push config to agents
Enterprise-grade capabilities at a price that makes sense. No shared tenants, no legacy architecture, no compromise.
Every customer gets a fully isolated Docker environment with a separate database and network. Your data is never co-mingled.
A Danish company with all infrastructure in EU data centres. Full GDPR alignment, standard DPA available for all paid plans.
No six-month roadmap. No enterprise sales cycle. Tell us what you need — we build and ship quickly to match your operational reality.
Security is not a feature added later. It's built into every line of code from day one.
CertControl is designed by engineers who have experienced certificate-related outages firsthand — when login flows break and the board asks how it happened.
Deep expertise in OIDC, SAML, and OAuth2. We understand how certificates underpin authentication flows and what breaks when they expire unexpectedly.
Hands-on experience with container orchestration and cloud-native architectures — and the certificate complexity they introduce at scale.
Experience with F5, ISVA, and other reverse proxies — where certificate misconfigurations cause the most visible and painful outages.
We know audit and governance requirements firsthand. CertControl is built to satisfy them — not as an afterthought, but from the ground up.
Start your 14-day free trial with full platform access. No charges during the trial. Takes 5 minutes to set up.
Credit card required to provision your dedicated environment. No charge before trial ends.