CLM & PKI AUTOMATION PLATFORM

Automate certificate renewal. Keep control of your PKI.

Discover, renew and deploy certificates from one place, on your own infrastructure. Verify that services use the new certificate, with automatic rollback when verification fails.

Dashboard: expiry heatmap, issuers, key strength

1+1
one Go binary + PostgreSQL — the whole stack; no JVM, no app server
4096
addresses per discovery scan, ad-hoc or scheduled
mTLS
pull agents — no inbound connections, works behind NAT
30
days of trial — every feature, up to 10 issued certificates →

Illustrated example

What happens when renewal fails verification?

Explore a renewal workflow with a failed service check. This is an illustration; ask for a product demo to see it on a running system.

Renew

The configured CA issues the replacement certificate.

See it in a demo →

How it works

From finding a certificate to proving the renewal worked: six steps the platform runs on its own.

01

Discover

TLS scans of targets and CIDR ranges; agents reach the networks the server can't.

02

Inventory

Deduplicated by fingerprint, with observation history and ownership metadata.

03

Issue

Internal CA, ACME, DigiCert, EJBCA or ADCS — plus SCEP/EST for devices.

04

Deploy

Agents install into PEM, PKCS#12, JKS and IIS stores — agentless into appliances and cloud.

05

Renew

Zero-touch, on schedule, before expiry.

06

Verify

A service check proves the new certificate is serving — or the agent rolls back.

Service verification and automatic rollback are built into the renewal workflow.

What ens0key solves

Certificate outages, untracked keys, manual renewals: ens0key covers the full machine-identity lifecycle.

01

Certificate lifecycle

Know every certificate you have, where it lives, and when it expires — before it takes production down.

  • ▸Network discovery of targets and CIDR ranges, plus agent-side discovery
  • ▸Inventory deduplicated by SHA-256 fingerprint with observation history
  • ▸Automatic flags: expired, expiring, self-signed, weak key, SHA-1
  • ▸Expiry alerts via e-mail digests and Slack-compatible webhooks
02

PKI automation

Issue, renew, and revoke from one place — whether the CA is yours or someone else's.

  • ▸Built-in issuing CA with a real CRL and OCSP responder
  • ▸Connectors for ACME (RFC 8555), DigiCert CertCentral, and EJBCA
  • ▸AES-256-GCM encrypted key vault; KMS/HSM integration scoped in the proposal
  • ▸Optional approval workflow before anything gets issued
03

Hands-free deployment

Agents put renewed certificates where they belong and reload the services that use them.

  • ▸Pull-model agents over mTLS — no inbound connections, NAT-friendly
  • ▸PEM, PKCS#12, and JKS certificate stores
  • ▸Auto-renewal with reload hooks and service verification
  • ▸Blueprints for mass rollout across your fleet

Built for your team

Built for operators

Expiry heatmap, CA breakdown, key-strength report: inventory health at a glance, in designed dark and light themes.

Reports your auditors will ask for — CSV/HTML export, e-mailed now or on a schedule.
Certificate detail — chain, SANs, observations, locations, and lifecycle actions in one place.

Enterprise-grade from the first login

SSO & LDAP

OIDC sign-in with a Microsoft Entra ID preset, LDAPS, and a local break-glass admin.

RBAC

Viewer, operator, and admin roles mapped from SSO/LDAP groups — enforced server-side.

Audit log

Every mutation and every login attempt, recorded.

Backup & restore

Scheduled encrypted dumps to local, SFTP, SCP, or TFTP repositories; transactional in-app restore.

Plays well with what you already run

Built-in issuing CAACMESCEPESTMicrosoft ADCSDigiCertEJBCAF5 BIG-IPCisco ISECisco ESACisco WLCFortinet FortiGateCitrix NetScalerAzure Key VaultAWS ACMGCP Certificate ManagerIISEntra IDLDAPSPrometheusSyslog / SIEMAll integrations →

The documentation is public, from appliance import to daily operations. Read it before you register. Open the docs →

See ens0key on your own estate

A pilot uses one server and one PostgreSQL database. We agree the schedule and success criteria with you in the proposal.

Talk to us