Public and private visibility, priced by certificate coverage
Every hosted plan keeps issuance and private keys in your existing stack. Business adds exact Compliance analysis, governance, and evidence, not better discovery. Every new organization starts with a full 30-day Business trial, with no payment card required; when it ends, the workspace continues on the free plan and no paid plan is activated automatically.
Choose your plan
Free
no card, no time limit
Certificate monitoring for a small footprint: public and private discovery, email expiry alerts, one Sentinel, one account. 10 active certificates included.
Start for freePro
billed annually · €2,148/year
Public and private discovery with unlimited Sentinels, DNS discovery, alerting, an aggregate Compliance preview, and a review status on every visible certificate and endpoint. 50 active certificates included, then €1.00 per additional active certificate per month.
Usage beyond the included 50 is billed monthly in arrears, on monthly and annual billing alike.
Business
billed annually · €4,188/year
The same discovery foundation with unlimited Sentinels, plus complete Compliance analysis, SSO, RBAC, rule-level findings, and timestamped evidence. 50 active certificates included, then €1.00 per additional active certificate per month.
Usage beyond the included 50 is billed monthly in arrears, on monthly and annual billing alike.
Enterprise / Custom
starting atbilled annually · €16,200/year
Unlimited Sentinels, custom certificate capacity, hosted or self-hosted options, SLA, support, and negotiated terms.
Discuss requirementsPrices are shown excluding VAT. French businesses are charged 20% VAT; eligible EU businesses outside France can be invoiced under reverse charge with a valid VAT ID.
Feature comparison
Scroll horizontally to compare plans
| Feature | Free | Pro | Business | Enterprise / Custom |
|---|---|---|---|---|
| Limits | ||||
| Active certificates | 10 | 50 included + €1.00/certificate beyond | 50 included + €1.00/certificate beyond | Custom |
| Sentinel agents | 1 | Unlimited | Unlimited | Unlimited |
| Local password accounts | 1 | 10 | 20 | Custom |
| Product boundary | ||||
| Works alongside your existing CA, ACME client, or CLM | Included | Included | Included | Included |
| Private-key custody | Never | Never | Never | Never |
| Discovery | ||||
| Public endpoint discovery and scanning | Included | Included | Included | Included |
| Internal network scanning | Included | Included | Included | Included |
| Filesystem and Kubernetes TLS Secret scanning | Included | Included | Included | Included |
| SNI-aware endpoint detection | Included | Included | Included | Included |
| Read-only DNS zone import | Included | Included | Included | Included |
| Manual certificate upload | Included | Included | Included | Included |
| Alerting | ||||
| Discord webhook | No | Included | Included | Included |
| Email notifications | Included | Included | Included | Included |
| Slack | No | Included | Included | Included |
| Microsoft Teams | No | Included | Included | Included |
| Notification rules | 3 | 10 | 20 | Custom |
| Escalation rules | Included | Included | Included | Included |
| Certificate and endpoint filters | Included | Included | Included | Included |
| Compliance & Evidence | ||||
| Compliance workspace | No | Preview | Included | Included |
| Problem categories and affected counts | No | Included | Included | Included |
| Status and review count per visible certificate or endpoint | No | Included | Included | Included |
| Certificate and TLS compliance scores | No | No | Included | Included |
| Machine and certificate compliance details | No | No | Included | Included |
| Rule-level findings for ANSSI, BSI, NIST, and Mozilla/TLSRef | No | No | Included | Included |
| Post-quantum readiness tracking | No | No | Included | Included |
| Timestamped CSV evidence (5 datasets) | No | No | Included | Included |
| Access Control & Audit | ||||
| Role-based access control (RBAC) | No | No | Included | Included |
| SSO (OpenID Connect) | No | No | Included | Included |
| Activity audit trail | Included | Included | Included | Included |
| Support & SLA | ||||
| Email support | Included | Included | Included | Included |
| Priority support | No | No | Included | Included |
| Dedicated account manager | No | No | No | Included |
| Enterprise SLA | No | No | No | Included |
Pro and Business support response times are best-effort. Custom agreements can include negotiated support targets and availability commitments. Business compliance findings and CSV evidence support review work; they do not establish compliance, provide certification, or replace an audit opinion.
Frequently asked questions
What counts toward my certificate limit?
Each distinct active leaf-certificate fingerprint counts once, regardless of how many endpoints serve it or how many files or Kubernetes Secrets contain it. A certificate counts while it is actively served or still present in a configured file or Secret; replaced or disappeared certificates are removed from the count automatically. Certificates beyond the 50 included in your plan are billed per certificate on a monthly usage invoice, in arrears, including on annual plans.
Which plan should I choose?
Choose Pro for public and private discovery, alerting, an aggregate Compliance preview, and a policy-agnostic status plus review count on each visible certificate or endpoint. Choose Business when you need exact certificate and TLS scores, rule-to-asset drill-downs, rule-level findings, remediation, post-quantum readiness, SSO, RBAC, and timestamped evidence.
Can I evaluate Nocert before subscribing?
Yes. Every new organization starts with a full 30-day Business trial, with no payment card required and within the applicable usage limits. When the trial ends, the workspace continues on the free plan: monitoring and email expiry alerts for up to 10 active certificates, one Sentinel, and one account. Compliance analysis, Slack, Teams, and Discord notifications, and the other paid features pause until a plan is activated. No paid plan is activated automatically.
Is there a free plan?
Yes. After the 30-day Business trial, every workspace continues on the free plan: monitoring and email expiry alerts for up to 10 active certificates, one Sentinel, one local account, and 3 notification rules. Going over the allowance does not stop discovery or alerting; configuration changes are blocked after a seven-day grace period until the inventory shrinks or a paid plan is active.
Does Nocert handle private keys?
No. Nocert observes certificates and TLS endpoints after issuance. Your existing CA, ACME client, vault, or CLM remains responsible for issuance, renewal, deployment, and private keys.
Can I switch plans at any time?
Upgrading from Pro to Business is self-serve and applies immediately, prorated for the rest of your billing period. Switching from monthly to annual billing is also self-serve in the app. Downgrades are handled by our support team and take effect at your next renewal.
Can I cancel at any time?
Yes, from the billing settings, with no notice period. A monthly subscription ends at the end of the paid month and an annual subscription at the end of the prepaid year; neither renews after cancellation. Afterwards the workspace continues on the free plan, within its limits. The trial needs no cancellation at all: it ends on its own into the free plan, and no card is on file.
Can I pay by bank transfer?
Pro and Business are paid by card through Stripe, and every charge produces an invoice. Custom agreements can be invoiced for payment by bank transfer, with terms set in the signed order.
Where is my data hosted?
For hosted plans, application data is hosted primarily in the European Union on OVHcloud infrastructure in France and Germany, with limited sub-processor transfers documented in the DPA and protected by appropriate safeguards. A self-hosted deployment option can be scoped in a signed Custom order.
What happens to my data if I stop using Nocert?
Your workspace continues on the free plan: scanning and email expiry alerts keep running for up to 10 active certificates, the organization owner can still sign in, and your data stays in place. Nothing is deleted on a schedule. You can retrieve a full export of your data at any time and request deletion of the organization, which removes it from production and from backups within a further 30 days. Billing records are kept only as long as French accounting law requires.
Do agents require inbound connections?
No. Agents initiate outbound communication to sentinel.nocert.io using signed HTTP requests. No inbound firewall rules or open ports are required.
Are support response times guaranteed?
Pro and Business support are best-effort. Custom agreements can include negotiated support response targets and availability commitments.