Use cases

Certificate visibility for teams that already have a PKI

Nocert is built for European platform and security teams managing hundreds of SSL/TLS certificates across public and private infrastructure. Keep the issuing stack; add one inventory across reachable services and the Sentinel discovery modes you enable.

Internal discovery

Find certificates outside public scans

Good fit
Platform, infrastructure, and security teams with private APIs, databases, appliances, mTLS services, files, or Kubernetes clusters.
Problem
Public scanners cannot see certificates on private networks or stored inside hosts and clusters, leaving expiration and policy blind spots.
What Nocert does
Outbound-only Sentinels run configured CIDR and port sweeps, filesystem discovery, and Kubernetes discovery. With network mode enabled, new leaf certificates can also seed targeted probes for their SAN hostnames.
Boundary
Network, local-listener, filesystem, and Kubernetes modes are independently switchable. SAN-derived hostname probes are gated by network mode but are not confined to the configured CIDR list; local-listener observations stay outside deployment inventory. Sentinel sends observations, not private keys, and provides no inbound administration channel.
Explore automatic certificate discovery
Public + private inventory

See endpoints, files, and Kubernetes in one inventory

Good fit
Teams with public domains plus private APIs, databases, appliances, service meshes, certificate files, or Kubernetes clusters.
Problem
Issuer records and CT data do not prove what is live, while internal certificates and stored material are invisible from the public internet.
What Nocert does
Nocert scans reachable endpoints from the hostnames it discovers for your domains. Outbound-only Sentinels add configured network sweeps, SAN-derived targeted probes, filesystem findings, and Kubernetes observations.
Boundary
Periodic sweeps and storage discovery use configured scopes. SAN-derived hostname probes require network mode but are not confined to configured CIDRs. Sentinel sends certificate findings, not private keys, and provides no inbound administration channel.
Explore the deployment-aware inventory
Alert routing

Send actionable findings to the right destination

Good fit
Organizations where platform, application, IT, and security teams share certificate responsibility.
Problem
A single mailbox becomes noisy as certificate volume grows. Critical endpoints need different expiry thresholds, destinations, and escalation paths.
What Nocert does
Notification rules filter by common name, SAN, endpoint tag, or CA status. Ordered rules set expiration thresholds and destinations, with separate targets at a more urgent escalation threshold.
Boundary
A daily cycle sends one digest to each matching email target on every plan, and to each matching Discord, Slack, or Microsoft Teams channel on paid plans and during the trial. Team ownership mapping and automated renewal are not part of the current product.
Explore internal certificate expiration alerts
Business compliance

Prepare certificate and TLS evidence for reviews

Good fit
Teams asked to show certificate inventory, TLS posture, expiration controls, and remediation history during security or compliance reviews.
Problem
Auditors usually ask for evidence, not screenshots of a single host. Teams need repeatable exports and a clear inventory boundary.
What Nocert does
The organization-wide Pro preview shows coarse problem categories and affected counts without mapping a category to asset identities; tag-restricted views suppress those aggregates. Every certificate and endpoint already visible to a Pro user also shows a policy-agnostic status and actionable review count. Business and Custom evaluate observations against ANSSI, BSI, NIST, and Mozilla/TLSRef policies, with certificate and TLS scores, affected-asset drill-downs, rule-level findings, remediation, post-quantum readiness, and timestamped CSV evidence.
Boundary
The findings and exports can support PCI DSS, ISO 27001, and NIS2 reviews. They do not establish compliance or provide certification.
Evaluation

Bring one domain and one approved private scope

Start with one registered domain and a configured network, filesystem, or Kubernetes scope. Every new organization gets the full Business feature set for 30 days. After the trial, a workspace without a paid subscription continues on the Free plan for up to 10 certificates; a Pro subscription retains the aggregate Compliance preview and the per-asset review status and count.

Enter your company domain to prefill signup.

We use this domain to prefill signup. Public discovery starts for the domain of the work email you verify, backed by an index of over 3 billion certificates.