Product · Platform
Every certificate in Certheim moves through the same five steps (request, approve, sign, issue, deliver), whether a person asked for it or a renewal timer did. Configure a template once and the lifecycle runs itself.
Users request one or many certificates from the dashboard. Bare hostnames get your configured domain appended; IP addresses become IP SANs automatically. Named subject profiles switch organizational identity per request.
Per-template policy decides who may approve and what gets auto-approved. Trusted templates can skip straight to signing; sensitive ones require an explicit approver, and every decision lands in the audit log.
Approvers sign in-UI against the CA backend the template names: OpenBao, AD CS, EJBCA, Venafi, AWS Private CA, ACME, or the built-in local CA. Keys never transit a workstation. More on signing →
The issued certificate is verified against the request's public key before it's accepted. A mismatched or substituted cert is rejected, not stored.
Certheim pushes the certificate to where it lives (an SSH host, a Kubernetes Secret, a vault, or a webhook) with retry and backoff. More on delivery & renewal →
Request to delivery in one approval-gated flow, then renewed on its own. The same CA backend re-signs, the same destinations receive, and scheduled timers keep certificates from ever lapsing.
The pipeline is the same whether a request is brand-new or a scheduled renewal, so once a template is configured, certificates issue, deliver, and renew themselves, end to end.
The same application runs on a VM, in a container, on Kubernetes, or fully air-gapped. Pick the shape that fits your boundary, not ours.
A signed tarball with an interactive installer for RHEL/AlmaLinux 9. Choose SQLite (zero-dependency) or PostgreSQL, your TLS mode, and local or CAC/PIV authentication. systemd-native with hardened service sandboxing.
A hardened, non-root image with SBOM + provenance attestations, published to Docker Hub. The Helm chart deploys a clustered install against managed PostgreSQL; a deployment generator emits your values.yaml.
The offline bundle ships everything, a Python wheelhouse included, so nothing is fetched at install time. The license verifies offline; the app makes no outbound calls, ever.
No telemetry, no license server callbacks, no update pings. Premium editions verify an offline-signed license file. What happens in your enclave stays there.
Every request, approval, signature, delivery, and admin change is written to a full audit log, exportable and upgradeable to tamper-evident WORM storage in the Government edition.
Checksummed release artifacts, container images with SBOM and build-provenance attestations, and a published security.txt with a real disclosure path.
Next up
Generate a key and CSR in your browser, walk the guided setup, or stand up Community for free. No sales call required.
Questions first? Talk to us. Design partners and air-gapped evaluations are welcome.