Certificate Discovery

You can only protect
what you know.

Shadow certificates, forgotten subdomains, orphaned S/MIME keys: NextPKI Discovery actively and passively scans every layer of your network and delivers the completeness no spreadsheet ever will.

Active scans · CT logs · passive trafficTLS · S/MIME · code signing · internal CAsConfigurable, daily or faster
Scan läuft · 1.247 Hosts412api.example.comCT-LogTLSGültiglegacy.intra.netSensorShadowShadowmail.example.comCloud-SyncS/MIMESchwachvpn.example.comScanTLSGültig
Sensors Active scans · CT logs · passive traffic
Detects TLS · S/MIME · code signing · internal CAs
Cadence Configurable, daily or faster
Data residency EU region · auditable
What Discovery surfaces

Visibility without blind spots.

Not just what's already in the inventory. Also what should never have stayed hidden.

01

Active network scans

TLS handshakes across internal and external scopes. Subdomain enumeration with a per-tenant auth vault.

02

Passive observation

Sensor mode listens on traffic mirrors, load balancer logs and SNI streams, finds certificates no scanner reaches.

03

Certificate Transparency

Continuous crawling of CT logs for your domains. New issuances mirrored into your inventory in real time.

04

Weak crypto at a glance

RSA-1024, SHA-1, expired roots, wildcard sprawl, every risk class with owner and expiry date.

05

Multi-CA inventory

DigiCert, Sectigo, Let's Encrypt, GlobalSign, ZeroSSL, SwissSign and your Private CA, one consistent data model.

06

Ownership mapping

Every certificate gets an owner. Slack/email alerts reach people, not orphaned mailboxes.

How Discovery rolls in

From first scan to continuous visibility.

A typical rollout takes less than a week, without any agent on your servers.

01
Day 1 Define scopes

DNS domains, IP ranges, reseller accounts. NextPKI checks permissions and auth endpoints.

02
Day 2-3 Initial scan & CT sync

Full inventory including historical CT issuances, grouped by domain, CA and expiry.

03
Day 4 Risk triage

Sorted by severity: expired, expiring, weak crypto, unknown owner. Ownership assigned.

04
From day 5 Steady state

Daily deltas, Slack/email alerts, drill-down via API into SIEM, ITSM or your spreadsheet.

Start Discovery

A first scan brings clarity to your certificate inventory.

Try Discovery on one of your own domains. The result is usually more surprising than expected.