Why ens0key

The market gives you three ways to solve certificate lifecycle — each with a catch. ens0key was built for the gap between them. Here is the comparison by category, honestly, including where we are not the right choice.

Why now: certificate lifetimes are collapsing

CA/Browser Forum ballot SC-081v3 (passed April 2025) caps the lifetime of publicly trusted TLS certificates on a fixed schedule. That is roughly 8× today's renewal volume by 2029 — annual renewals and spreadsheets are mathematically over. Every organization will need automation; the only question is how heavy it has to be.

Until March 2026398 days
Today200 days
From March 2027100 days
From March 202947 days

Maximum validity of publicly trusted TLS certificates. OV/EV shorten on the same schedule.

Three ways the market solves this

Enterprise suites

Deep and proven at very large scale — but typically heavy: months-long rollouts, professional-services projects, six-figure licensing, and a substantial infrastructure stack underneath.

CA-bundled managers

Convenient if you buy that vendor's certificates — but lifecycle automation tends to stop at their own CA, the management plane is usually their cloud, and switching CAs often means switching platforms.

DIY & open source

Excellent renewal execution on the node where they run — but no inventory, no RBAC, no audit trail. The certificates nobody scripted still expire silently.

The gap: full lifecycle governance, CA-agnostic, on-prem and air-gap friendly — at a footprint and price a mid-size team can actually run. That is exactly where ens0key sits.

The market at a glance

A comparison of product categories, not specific vendors — individual products differ in detail.

Criterionens0keyEnterprise suitesCA-bundledDIY / OSS
Full lifecycle loop (discover → verify)own CA only
CA-agnosticACME only
Own issuing CA (CRL/OCSP)✓ built intypically fronts another CAtheir CAseparate product
On-prem / air-gapvariescloud
Governance (RBAC, audit, approvals)
Post-deploy verification + rollback✓ built intypically scriptedyou build it
Time to productiondays–weekstypically monthsweeksper node
Footprint1 binary + PostgreSQLlarge stackSaaSengineer time

Choosing by scenario — honestly

Mid-size estate (hundreds to a few thousand certificates), on-prem or hybridens0key
Air-gapped, regulated, or no-cloud-allowed environmentsens0key
Internal PKI and public certificates under one roof, without a dedicated PKI teamens0key
Global 10,000+ certificate estate, multi-cloud, dedicated PKI teaman enterprise suite is defensible
All certificates from one public CA, cloud-only, no internal PKIa CA-bundled manager may suffice

Everything between the extremes is exactly where ens0key fits best.

What we combine that others don't

Renewal with a safety net

Post-deploy TLS verification with automatic rollback, built into the product — the agent proves the new certificate is actually serving, or restores the previous one.

PKI in the box

A real issuing CA with CRL and OCSP responder — internal PKI without buying or running a second product.

Runs where suites can't

One Go binary + PostgreSQL, licensing verified fully offline (Ed25519), air-gap friendly, no phone-home.

A vendor you can reach

Store and CA integrations developed per customer and per use case — and maintained when third-party versions change. EN / HR / DE interface.

Compare us on your own infrastructure

  • 0130-day trial — every feature, up to 10 managed certificates; register with us and you're off
  • 02Guided POC: your network scanned and one service on verified auto-renewal
  • 03An expired license never holds your data hostage — inventory, monitoring, discovery and reports keep working