CERTIFICATE LIFECYCLE MANAGEMENT

An expired cert
is an outage.
We don't let it happen.

NOLAPSE discovers, issues, renews and deploys every SSL/TLS certificate across your estate — automatically. From Let's Encrypt and Private CA to Post-Quantum, with an agent that pushes to your endpoints and reloads them for you.

Start free → Read the docs No credit card
318 certs
managed automatically per estate, on average
0
expiry-driven outages after NOLAPSE
4
CAs — LE · Google Trust · Private · reseller
ML-DSA
Post-Quantum issuance, today
estate/monitor WATCHING
*.app.example.com
Let's Encrypt · DNS-01
62d
RENEWED
api.internal.corp
Private CA · ML-DSA
211d
VALID
vpn.example.com
PAN-OS · agent
9d
AUTO-RENEW
mail.example.com
Google Trust · ACME
147d
VALID
legacy.example.net
discovered · RSA-1024
EXP
FLAGGED
318 tracked · 14 expiringall handled ✓
issued *.shop.example.com via Let's Encrypt renewed api.corp.local 90d before expiry deployed to nginx · IIS · FortiOS CT alert: unknown cert for example.com — caught discovered 28 forgotten certs on 10.0.0.0/16 issued *.shop.example.com via Let's Encrypt renewed api.corp.local 90d before expiry deployed to nginx · IIS · FortiOS CT alert: unknown cert for example.com — caught discovered 28 forgotten certs on 10.0.0.0/16
[ 01 / CAPABILITIES ]

One platform for the
entire certificate lifecycle

From finding the certs your team forgot to
deploying onto endpoints — run the whole estate
from a single console.

DISCOVERY

Network Discovery

Scan your network for certificates that were issued by hand, forgotten, or created outside the system — see every one before it expires, not after it takes you down.

02

ACME + Private CA

Issue free DV certs from Let's Encrypt / Google Trust Services, or run your own Private CA for internal identities.

ML-DSA

Post-Quantum ready

Issue certs with quantum-resistant algorithms and score the PQC readiness of your whole estate.

04

Automated renew + deploy

A Go agent pushes new certs to your endpoints and reloads the service for you — no touching machines one by one.

nginxIISPAN-OSFortiOSKubernetes
05

CT Monitoring

Know instantly if anyone issues a cert for your domains.

Policy Engine · RBAC · MFA · 4-eyes approval

Enforce issuance standards · per-team permissions · mandatory admin MFA · critical actions (revoke/delete) need a second approver.

Read the security model →
[ 02 / WORKFLOW ]

Four steps, then it runs itself

Set it up once — NOLAPSE watches expiry dates so you don't have to.

[01]

Discover

scan · import

Scan the network and import existing certs so you can see every certificate in the estate — including the ones you didn't issue.

[02]

Issue

LE · GTS · Private · reseller

Pick a CA and issue against your org's policy — free DV, OV/EV via a reseller, or an internal Private CA.

[03]

Deploy

agent → reload

The agent pushes the cert to the endpoint and reloads the service automatically — nginx, IIS, PAN-OS, FortiOS.

[04]

Renew

auto · CT watch

Renews automatically before expiry, with alerts, and watches Certificate Transparency logs around the clock.

[ 03 / SECURITY ]

Built for enterprises
and government

Private keys are encrypted throughout, agents speak mTLS, and every action is recorded in a tamper-evident log.

Keys encrypted at rest (AES-256)KEK kept outside the database · Vault / KMS supported
mTLS for every agentAuthenticated with a per-machine client certificate
Hash-chained audit logEvery event is verifiable and tamper-evident · SIEM-ready
Mandatory MFA + 4-eyes approvalCritical actions require a second approver
PDPA · data-residency · on-premHosted in Thailand · on-premise deployment supported
PQC READINESSscore 74
ML-DSA-65ready
ECDSA P-25664%
RSA-204838%
RSA-1024at risk

Score how ready your estate is for the post-quantum era, then work through the fragile certs.

[ 04 / PRICING ]

Start free, scale when ready

No setup fee, cancel anytime.

FREE
$0 /mo
For small teams and evaluation
Get started
  • Let's Encrypt / Private CA issuance
  • Basic Discovery
  • Agent auto-renew + deploy
  • Expiry alerts
PRO
Contact — usage-based
For organisations running a whole estate
Start free
  • Everything in Free +
  • CT Monitoring + PQC Readiness
  • Policy Engine · RBAC · MFA
  • reseller OV/EV + Google Trust
ENTERPRISE
Contact — org / gov
on-prem · data-residency · SLA
Talk to sales
  • Everything in Pro +
  • On-premise / data-residency
  • SSO (OIDC) · SIEM feed
  • Dedicated support + SLA
[ 05 / CONTACT ]

Talk to the NOLAPSE team

Want a demo, enterprise pricing, or on-prem / government deployment? Fill in the form and we'll get back to you fast.

Reply within one business day
Live demo on a sample estate
PoC for enterprise / government

Stop losing time to expired certs

See your whole estate, then let NOLAPSE run it for you.