Certificate governance, end to end
One ACME gateway, one CT watcher. Issue certificates for internal services without exposing them. Find the ones you didn't know about. Skip the next renewal-day outage.
The problem
Self-signed internals, surprise certificates from teams you've never met, and a renewal cadence about to be measured in weeks.
Anyone with domain access can pull a certificate. You have no idea who, when, or why.
Internal APIs, admin panels, and microservices run with self-signed certs because "it's just internal." Your engineers learn to click through warnings.
Services go down because someone forgot to renew. At 47-day lifetimes, manual tracking is over.
The approach
One control point for every ACME request. Visibility across every CA, every team.
Certificate discovery engine
Central ACME gateway
Capabilities
Everything end-to-end certificate governance needs.
One pane for certificates from Let's Encrypt, DigiCert, Sectigo, ZeroSSL, and anything else that publishes to CT.
OIDC sign-in, team-scoped permissions, delegated domain ownership. Out of the box.
Configurable approvals for certificate requests. RBAC where you need it, none where you don't.
One control point for every ACME request. certbot, acme.sh, cert-manager. Unchanged.
Upcoming expiry, unauthorised issuances, policy drift. You hear about it before someone else does.
Real certificates for internal services without exposing them. api.company.com, admin.company.com, anything else behind your perimeter.
Trace any certificate to the request, the requester, and the policy that signed it off.
Single-domain, multi-domain, and wildcard certificates. Subdomain-aware policy throughout.
Cloudflare, Route 53, Google Cloud DNS, PowerDNS, RFC 2136. Bring your DNS, keep your provider.
Use cases
The three problems that get AcmeGuard purchased.
Free ACME services do the job. AcmeGuard adds the governance you'd otherwise buy from a CA, without the invoice.
Real SSL for api.company.com and admin.company.com without exposing them. No browser warnings. No more "trust me" prompts.
Discover the certificates you didn't know existed. Gate every new one through the same approval flow.
How it works
Drops into your existing infrastructure. No client migration.
AcmeGuard streams Certificate Transparency logs and surfaces every certificate issued for your domains, from any CA, within minutes.
One control point for every ACME request. certbot, acme.sh, cert-manager keep working. You get the governance.
One portal, every certificate. Approval workflows, RBAC, audit-ready reports. The chaos becomes a process you can hand to compliance.
Architecture
One credential-scoped DNS-01 proxy. One CT watcher. Your ACME clients don't notice the difference.