Use cases

Certificate visibility for teams that already have a PKI

Nocert is built for European platform and security teams managing hundreds of certificates across public and private infrastructure. Keep the issuing stack; add one inventory across reachable services and the private scopes you explicitly configure.

Internal discovery

Find certificates outside public scans

Good fit
Platform, infrastructure, and security teams with private APIs, databases, appliances, mTLS services, files, or Kubernetes clusters.
Problem
Public scanners cannot see certificates on private networks or stored inside hosts and clusters, leaving expiration and policy blind spots.
What Nocert does
Outbound-only Sentinels scan the private CIDRs, ports, filesystems, and Kubernetes namespaces you approve, then add the observed certificates to the same inventory as public endpoints.
Boundary
You control every private scope. Sentinel sends certificate observations and scoped metadata, not private keys, and provides no inbound administration channel.
Public + private inventory

See endpoints, files, and Kubernetes in one inventory

Good fit
Teams with public domains plus private APIs, databases, appliances, service meshes, certificate files, or Kubernetes clusters.
Problem
Issuer records and CT data do not prove what is live, while internal certificates and stored material are invisible from the public internet.
What Nocert does
Nocert scans reachable endpoints from verified hostnames. Outbound-only Sentinels cover approved private hosts, ports, files, and Kubernetes scopes.
Boundary
You control every private scope. Sentinel sends certificate findings and scoped metadata, not private keys, and provides no inbound administration channel.
Alert routing

Send actionable findings to the right destination

Good fit
Organizations where platform, application, IT, and security teams share certificate responsibility.
Problem
A single mailbox becomes noisy as certificate volume grows. Critical endpoints need different thresholds, priorities, destinations, and escalation paths.
What Nocert does
Notification rules filter by common name, SAN, endpoint tag, CA status, and priority. Escalation can use a separate target after a configurable delay.
Boundary
Delivery is available through email, Discord, Slack, and Microsoft Teams. Team ownership mapping is not part of the current product.
Business compliance

Prepare certificate and TLS evidence for reviews

Good fit
Teams asked to show certificate inventory, TLS posture, expiration controls, and remediation history during security or compliance reviews.
Problem
Auditors usually ask for evidence, not screenshots of a single host. Teams need repeatable exports and a clear inventory boundary.
What Nocert does
The organization-wide Pro preview shows coarse problem categories and affected counts without mapping a category to asset identities; tag-restricted views suppress those aggregates. Every certificate and endpoint already visible to a Pro user also shows a policy-agnostic status and actionable review count. Business and Custom evaluate observations against ANSSI, BSI, NIST, and Mozilla/TLSRef policies, with certificate and TLS scores, affected-asset drill-downs, rule-level findings, remediation, post-quantum readiness, and timestamped CSV evidence.
Boundary
The findings and exports can support PCI DSS, ISO 27001, and NIS2 reviews. They do not establish compliance or provide certification.
Evaluation

Bring one domain and one approved private scope

Start with one registered domain and a configured network, filesystem, or Kubernetes scope. Evaluate the observations and alert routing included with Pro and Business. The full 14-day Business trial also lets every new organization review exact Compliance scores, rule-to-asset drill-downs, evidence, and remediation before choosing a paid plan. Pro then keeps the aggregate preview and per-asset review status/count; no payment card is required and no paid plan is activated automatically.