Public and private visibility, priced by certificate coverage

Every hosted plan keeps issuance and private keys in your existing stack. Business adds exact Compliance analysis, governance, and evidence, not better discovery. Every new organization starts with a full 14-day Business trial, with no payment card required and no paid plan activated automatically.

Choose your plan

Billing
Currency

Pro

290 /month

billed annually · €3,480/year

Public and private discovery for 200 active certificates, with unlimited Sentinels, DNS discovery, alerting, an aggregate Compliance preview, and a review status on every visible certificate and endpoint.

Add-on packs +50 certificates · 50/month each
0
Total certificates 200

Same billing cycle. Prorated when changed mid-cycle. From 400 certificates, Business costs the same at equal annual coverage and unlocks exact Compliance findings, governance, and evidence.

Request an evaluation
Compliance + governance

Business

490 /month

billed annually · €5,880/year

The same discovery foundation for 400 active certificates and unlimited Sentinels, plus complete Compliance analysis, SSO, RBAC, rule-level findings, and timestamped evidence.

Add-on packs +50 certificates · 50/month each
0
Total certificates 400

Same billing cycle. Prorated when changed mid-cycle.

Request an evaluation

Enterprise / Custom

starting at
16,000 /year

negotiated billing terms

Unlimited Sentinels, custom certificate capacity, hosted or self-hosted options, SLA, support, and negotiated terms.

Discuss requirements

Prices are shown excluding VAT. French businesses are charged 20% VAT; eligible EU businesses outside France can be invoiced under reverse charge with a valid VAT ID.

Feature comparison

Scroll horizontally to compare plans

Feature ProBusinessCustom
Limits
Active certificates 200 400 Custom
Sentinel agents Unlimited Unlimited Unlimited
Local password accounts 10 20 Custom
Product boundary
Works alongside your existing CA, ACME client, or CLM Included Included Included
Private-key custody Never Never Never
Discovery
Public endpoint discovery and scanning Included Included Included
Internal network scanning Included Included Included
Filesystem and Kubernetes TLS Secret scanning Included Included Included
SNI-aware endpoint detection Included Included Included
Read-only DNS zone import Included Included Included
Manual certificate upload Included Included Included
Alerting
Discord webhook Included Included Included
Email notifications Included Included Included
Slack Included Included Included
Microsoft Teams Included Included Included
Notification rules 10 20 Custom
Escalation rules Included Included Included
Certificate and endpoint filters Included Included Included
Compliance & Evidence
Compliance workspace Preview Included Included
Problem categories and affected counts Included Included Included
Status and review count per visible certificate or endpoint Included Included Included
Certificate and TLS compliance scores No Included Included
Machine and certificate compliance details No Included Included
Rule-level findings for ANSSI, BSI, NIST, and Mozilla/TLSRef No Included Included
Post-quantum readiness tracking No Included Included
Timestamped CSV evidence (5 datasets) No Included Included
Access Control & Audit
Role-based access control (RBAC) No Included Included
SSO (OpenID Connect) No Included Included
Activity audit trail Included Included Included
Support & SLA
Email support Included Included Included
Priority support No Included Included
Dedicated account manager No No Included
Enterprise SLA No No Included

Pro and Business support response times are best-effort. Custom agreements can include negotiated support targets and availability commitments. Business compliance findings and CSV evidence support review work; they do not establish compliance, provide certification, or replace an audit opinion.

Frequently asked questions

What counts toward my certificate limit?

Each distinct leaf-certificate fingerprint counts once, regardless of how many endpoints, files, or Kubernetes Secrets expose it. It counts while recently served or still present in a configured file or Secret.

Which plan should I choose?

Choose Pro for public and private discovery, alerting, an aggregate Compliance preview, and a policy-agnostic status plus review count on each visible certificate or endpoint. Choose Business when you need exact certificate and TLS scores, rule-to-asset drill-downs, rule-level findings, remediation, post-quantum readiness, SSO, RBAC, and timestamped evidence.

Can I evaluate Nocert before subscribing?

Yes. Every new organization starts with a full 14-day Business trial, with no payment card required and within the applicable usage limits. After the trial, Pro keeps the aggregate Compliance preview and per-asset review status/count; Business retains exact findings, rule-to-asset drill-downs, evidence, and remediation. No paid plan is activated automatically.

Does Nocert handle private keys?

No. Nocert observes certificates and TLS endpoints after issuance. Your existing CA, ACME client, vault, or CLM remains responsible for issuance, renewal, deployment, and private keys.

Can I switch plans at any time?

Upgrading from Pro to Business is self-serve and applies immediately, prorated for the rest of your billing period. Downgrades and switching between monthly and annual billing are handled by our support team and take effect at your next renewal.

Where is my data hosted?

For hosted plans, application data is hosted primarily in the European Union on OVHcloud infrastructure in France and Germany, with limited sub-processor transfers documented in the DPA and protected by appropriate safeguards. A self-hosted deployment option can be scoped in a signed Custom order.

Do agents require inbound connections?

No. Agents initiate outbound communication to sentinel.nocert.io using signed HTTP requests. No inbound firewall rules or open ports required.

Are support response times guaranteed?

Pro and Business support are best-effort. Custom agreements can include negotiated support response targets and availability commitments.