CLM & PKI AUTOMATION PLATFORM

Every certificate. One control plane.

ens0key discovers, inventories, and automates the lifecycle of every X.509 certificate in your organization — and runs the PKI behind it: your own issuing CA with CRL/OCSP, external CA connectors, and agents that deploy and renew certificates hands-free.

1+1
one Go binary + PostgreSQL — the whole stack; no JVM, no app server
4096
addresses per discovery scan, ad-hoc or scheduled
mTLS
pull agents — no inbound connections, works behind NAT
30
days of trial — every feature, up to 10 managed certificates

Three problems. One platform.

Certificate outages, untracked keys, and manual renewals — ens0key covers the full machine-identity lifecycle.

01

Certificate lifecycle

Know every certificate you have, where it lives, and when it expires — before it takes production down.

  • Network discovery of targets and CIDR ranges, plus agent-side discovery
  • Inventory deduplicated by SHA-256 fingerprint with observation history
  • Automatic flags: expired, expiring, self-signed, weak key, SHA-1
  • Expiry alerts via e-mail digests and Slack-compatible webhooks
02

PKI automation

Issue, renew, and revoke from one place — whether the CA is yours or someone else's.

  • Built-in issuing CA with a real CRL and OCSP responder
  • Connectors for ACME (RFC 8555), DigiCert CertCentral, and EJBCA
  • Encrypted key vault: AES-256-GCM envelope encryption, KMS/HSM-ready
  • Optional approval workflow before anything gets issued
03

Hands-free deployment

Agents put renewed certificates where they belong and reload the services that use them.

  • Pull-model agents over mTLS — no inbound connections, NAT-friendly
  • PEM, PKCS#12, and JKS certificate stores
  • Auto-renewal with reload hooks and service verification
  • Blueprints for mass rollout across your fleet

Built for operators

Expiry heatmap, CA breakdown, key-strength report — inventory health at a glance, in designed dark and light themes.

The ens0key dashboard — the landing page of your certificate estate.

The ens0key dashboard — the landing page of your certificate estate.

Reports your auditors will ask for — CSV/HTML export, e-mailed now or on a schedule.
Reports your auditors will ask for — CSV/HTML export, e-mailed now or on a schedule.
Certificate detail — chain, SANs, observations, locations, and lifecycle actions in one place.
Certificate detail — chain, SANs, observations, locations, and lifecycle actions in one place.

Enterprise-grade from the first login

SSO & LDAP

OIDC sign-in with a Microsoft Entra ID preset, LDAPS, and a local break-glass admin.

RBAC

Viewer, operator, and admin roles mapped from SSO/LDAP groups — enforced server-side.

Audit log

Every mutation and every login attempt, recorded.

Backup & restore

Scheduled encrypted dumps to local, SFTP, SCP, or TFTP repositories; transactional in-app restore.

See ens0key on your own estate

A pilot takes one server and one PostgreSQL database. We'll help you scan your first ranges the same day.

Talk to us