CLM & PKI AUTOMATION PLATFORM
Automate certificate renewal. Keep control of your PKI.
Discover, renew and deploy certificates from one place, on your own infrastructure. Verify that services use the new certificate, with automatic rollback when verification fails.
Dashboard: expiry heatmap, issuers, key strength
Illustrated example
What happens when renewal fails verification?
Explore a renewal workflow with a failed service check. This is an illustration; ask for a product demo to see it on a running system.
Renew
The configured CA issues the replacement certificate.
How it works
From finding a certificate to proving the renewal worked: six steps the platform runs on its own.
Discover
TLS scans of targets and CIDR ranges; agents reach the networks the server can't.
Inventory
Deduplicated by fingerprint, with observation history and ownership metadata.
Issue
Internal CA, ACME, DigiCert, EJBCA or ADCS — plus SCEP/EST for devices.
Deploy
Agents install into PEM, PKCS#12, JKS and IIS stores — agentless into appliances and cloud.
Renew
Zero-touch, on schedule, before expiry.
Verify
A service check proves the new certificate is serving — or the agent rolls back.
Service verification and automatic rollback are built into the renewal workflow.
What ens0key solves
Certificate outages, untracked keys, manual renewals: ens0key covers the full machine-identity lifecycle.
Certificate lifecycle
Know every certificate you have, where it lives, and when it expires — before it takes production down.
- ▸Network discovery of targets and CIDR ranges, plus agent-side discovery
- ▸Inventory deduplicated by SHA-256 fingerprint with observation history
- ▸Automatic flags: expired, expiring, self-signed, weak key, SHA-1
- ▸Expiry alerts via e-mail digests and Slack-compatible webhooks
PKI automation
Issue, renew, and revoke from one place — whether the CA is yours or someone else's.
- ▸Built-in issuing CA with a real CRL and OCSP responder
- ▸Connectors for ACME (RFC 8555), DigiCert CertCentral, and EJBCA
- ▸AES-256-GCM encrypted key vault; KMS/HSM integration scoped in the proposal
- ▸Optional approval workflow before anything gets issued
Hands-free deployment
Agents put renewed certificates where they belong and reload the services that use them.
- ▸Pull-model agents over mTLS — no inbound connections, NAT-friendly
- ▸PEM, PKCS#12, and JKS certificate stores
- ▸Auto-renewal with reload hooks and service verification
- ▸Blueprints for mass rollout across your fleet
Built for your team
PKI & security teams
One inventory for public and internal certificates, your own issuing CA, issuance policies and approvals, with an audit trail your auditors can actually use.
See the features →Network & platform ops
Certificates on F5, Cisco ISE/ESA/WLC, FortiGate, NetScaler and cloud stores deployed without an agent; servers on auto-renewal with reload hooks and verification. No more 2 a.m. expiry calls.
See the platform →CISO & compliance
47-day certificate lifetimes are coming. Reports, RBAC, SIEM forwarding and an audit log you can hand straight to an auditor.
Why ens0key →Built for operators
Expiry heatmap, CA breakdown, key-strength report: inventory health at a glance, in designed dark and light themes.
Enterprise-grade from the first login
SSO & LDAP
OIDC sign-in with a Microsoft Entra ID preset, LDAPS, and a local break-glass admin.
RBAC
Viewer, operator, and admin roles mapped from SSO/LDAP groups — enforced server-side.
Audit log
Every mutation and every login attempt, recorded.
Backup & restore
Scheduled encrypted dumps to local, SFTP, SCP, or TFTP repositories; transactional in-app restore.
Plays well with what you already run
The documentation is public, from appliance import to daily operations. Read it before you register. Open the docs →
See ens0key on your own estate
A pilot uses one server and one PostgreSQL database. We agree the schedule and success criteria with you in the proposal.
Talk to us