Internal discovery
Find certificates outside public scans
- Good fit
- Platform, infrastructure, and security teams with private APIs, databases, appliances, mTLS services, files, or Kubernetes clusters.
- Problem
- Public scanners cannot see certificates on private networks or stored inside hosts and clusters, leaving expiration and policy blind spots.
- What Nocert does
- Outbound-only Sentinels run configured CIDR and port sweeps, filesystem discovery, and Kubernetes discovery. With network mode enabled, new leaf certificates can also seed targeted probes for their SAN hostnames.
- Boundary
- Network, local-listener, filesystem, and Kubernetes modes are independently switchable. SAN-derived hostname probes are gated by network mode but are not confined to the configured CIDR list; local-listener observations stay outside deployment inventory. Sentinel sends observations, not private keys, and provides no inbound administration channel.