Deployment-aware certificate inventory

Enterprise SSL Certificate Inventory & Deployment Visibility

Keep one record per certificate fingerprint, with location evidence from public endpoints, private services, files, and Kubernetes. Investigate current exposure and older sightings without moving issuance or private keys into another platform.

Full 30-day Business trial, then a free plan for up to 10 certificates. No payment card. No paid plan starts automatically.

From certificate list to inventory

Issuance data cannot tell you where a certificate is still used

An issuance record answers what exists: a CA record or a Certificate Transparency entry proves a certificate was issued. An inventory has to answer where: which endpoint presented it, on which port and SNI, when it was last seen, and whether an earlier copy is still mounted inside a private environment.

Nocert joins repeated observations by SHA-256 fingerprint and keeps their location context. That turns discovery signals into an operational inventory: certificate, expiry, source, observed locations, and freshness in one place.

Why Certificate Transparency is not a deployment inventory
Observed deployment locations

Connect a certificate fingerprint to the places that matter

Each source preserves a different kind of evidence. Nocert keeps those distinctions visible instead of flattening every signal into an unexplained certificate count.

Public endpoints

Record what a service presents

Live, SNI-aware scans associate the certificate served by a reachable hostname or IP with its port and TLS observation.

Host or IP, port, SNI, TLS details, and last observation
Private networks

See services from an internal vantage point

Outbound-only Sentinels observe TLS services through configured CIDR and port sweeps and targeted hostname probes derived from newly observed certificate SANs.

Network mode gates both probe types; no inbound firewall rule
Filesystems

Keep certificate paths attached

Sentinel reports retained filesystem findings for leaf certificates with the observing machine and path, without sending private-key bytes.

A CA file read from disk can be kept as a certificate without a filesystem finding or path
Kubernetes

Locate certificate material in clusters

Configured Kubernetes discovery preserves cluster, namespace, object, and data-field context for observed certificates.

Read-only scope using the credentials and RBAC you provide
Inventory model

One fingerprint, multiple observations

A renewed certificate becomes a new record. Reusing the same certificate across several systems adds locations to its existing record instead of inflating the inventory count.

  1. 01

    Observe

    Public scanners and configured Sentinels report certificates with source and location context.

  2. 02

    Normalize

    Nocert groups the same certificate by SHA-256 fingerprint inside your workspace.

  3. 03

    Map

    Endpoint, filesystem, Kubernetes, and chain sightings remain linked to the certificate record.

  4. 04

    Refresh

    Recurring observations distinguish current exposure from records that have stopped appearing.

Search and investigate

Move from fleet view to deployment evidence

Search by subject common name, issuer common name, SAN, serial number, or fingerprint. Open a certificate to inspect its validity, cryptographic details, chain sightings, observed endpoints, file paths, and Kubernetes locations when those sources are present.

  • Freshness: separate currently active observations from historical records.
  • Multiplicity: see the locations attached to one leaf-certificate fingerprint.
  • Evidence: export timestamped inventory datasets on Business and Custom.
  • Pricing: multiple observed locations do not count as extra certificates.
Review inventory limits and exports
Evidence boundaries

Know what each source can establish

Useful certificate inventory is explicit about the difference between a discovery lead, a live endpoint observation, and stored certificate material.

Source Evidence Boundary
Public records and DNS Candidate certificates and hostnames worth checking A record or DNS name is not, by itself, proof of a current deployment
Live endpoint scan The certificate served on a reachable host, port, and SNI at observation time Cannot see a private or blocked service from the public internet
Sentinel network scan The certificate presented to a configured sweep or SAN-derived targeted probe from the Sentinel vantage point Periodic sweeps follow configured CIDRs and ports; targeted SAN probes are not confined to that CIDR list
Sentinel filesystem or Kubernetes scan A retained filesystem finding or configured Kubernetes certificate location Stored material does not prove that a service currently presents it
A visibility layer, not another CA

Keep certificate control in your existing stack

Nocert observes certificate material and TLS outcomes. Your CA, ACME client, Vault or OpenBao, cert-manager, AD CS, and deployment systems remain responsible for issuance, renewal, revocation, and rollout.

No private-key custody

Certificate DER and scoped metadata can leave the environment; private-key bytes do not.

Customer-controlled modes

Inventory coverage uses network, filesystem, and Kubernetes modes. A separate local-listener mode probes the Sentinel host but does not populate deployment inventory.

Observed, not omniscient

The inventory returns location evidence within configured coverage and result limits. It does not claim every deployment or observation is returned.

Freshness, not decommission proof

A retired observation means it stopped appearing within the freshness window, not that removal is guaranteed.

Technical questions

SSL certificate inventory FAQ

How does Nocert avoid duplicate certificate records?

Within a workspace, Nocert groups observations by the certificate's SHA-256 fingerprint. The same certificate observed at several endpoints, paths, or Kubernetes locations remains one certificate record with multiple sightings.

Can I see where an SSL certificate is deployed?

Nocert returns endpoint, filesystem, and Kubernetes location evidence for the certificate, subject to configured coverage and result limits. This is not a claim that every possible deployment or observation has been returned.

What do active and retired records mean?

The state is based on observation freshness. A retired record has not been seen within the current freshness window; it is historical evidence, not proof that the certificate was deliberately decommissioned everywhere.

Which certificate fields can I search?

The inventory search covers subject common name, issuer common name, SAN, serial number, and fingerprint. Certificate details also preserve validity, cryptographic, chain, source, and location context when available.

Can I export the SSL certificate inventory?

Business and Custom plans include timestamped CSV evidence exports for certificate inventory and related posture datasets. A separate workspace portability export is available to organization owners.

Does renewal create a new certificate record?

Yes. A renewed certificate has a new fingerprint, so it becomes a separate record. That lets you see the new certificate alongside earlier observations and check whether the previous one is still being observed.

Start with a public domain

Build your first certificate inventory

Enter your company domain, continue with a work email, and evaluate the full Business feature set for 30 days. Add private sources only when you are ready to review and set their Sentinel modes.

See how discovery sources work

Enter your company domain to prefill signup.

We use this domain to prefill signup. Public discovery starts for the domain of the work email you verify, backed by an index of over 3 billion certificates.