Blackfort Technology
One certificate register across all your PKI worlds
Validated against real CA software in the Blackfort PKI test lab

Blackfort Certificate Intelligence

One certificate register across all your PKI worlds

Certificate Intelligence consolidates certificates from ADCS, EJBCA, Vault PKI, step-ca, Kubernetes, cloud vaults, TLS endpoints and CT logs in one audit-ready register. Read-only, operated in your environment, without access to private keys and without changes to your existing PKI. For DORA, information security and audit.

Read-only Operated in your environment Air-gap capable No private keys No changes to your PKI

Microsoft ADCS · EJBCA · HashiCorp Vault PKI · smallstep step-ca · Kubernetes/cert-manager · Azure Key Vault · AWS Certificate Manager · Google Certificate Manager · TLS scan · CT logs · File import

DORA

DORA requires an up-to-date certificate register

“Financial entities shall create and maintain a register for all certificates and certificate-storing devices for at least ICT assets supporting critical or important functions. Financial entities shall keep that register up to date.”
“Financial entities shall ensure the prompt renewal of certificates in advance of their expiration.”
Delegated Regulation (EU) 2024/1774, Art. 7(4) and (5)

Para. 4: the register

Certificate Intelligence provides the technical basis: one register across all sources, mapping to critical or important functions, owners, expiry dates, revocation status and an audit-ready export. It stays current because the sources are re-read regularly.

Para. 5: timely renewal

Upcoming expiries appear staggered by criticality and go to your monitoring, to Jira and as a daily summary to Teams. Renewal continues with your existing tools; Certificate Intelligence shows whether it happened in time.

The register also supports the identification of ICT assets and the cryptography requirements of DORA Art. 8 and 9, as well as the inventory expectations of NIS2 and ISO 27001. It supports implementation and evidence; it does not replace a legal assessment, and which obligations apply to your organisation depends on your classification under DORA.

Grown PKI

Every source only knows its own slice

Certificates come from several CAs, cloud vaults and public orders and live on servers, devices and services. A shared governance model across them is usually missing, so audit questions get answered with Excel lists.

Today

  • Microsoft ADCSknows what ADCS has issued
  • EJBCA, Vault, step-caeach know their own inventory
  • Azure Key Vaultknows the certificates in the vault
  • Public CAsknow their orders
  • Monitoringknows the endpoints it watches

No shared register, no shared ownership

With Certificate Intelligence

All sources flow into one register:

  • one register across all sources
  • owners and functions
  • critical / important per certificate
  • expiry by criticality
  • revocation status via CRL and OCSP
  • crypto findings
  • audit trail
  • Jira tickets, monitoring, Teams, auditor export

How it works

Collect, consolidate, assess

01

Collect

Small, openly readable export scripts at CAs and key stores, a built-in TLS scanner, Certificate Transparency logs and file import for isolated networks. Only public certificates are transferred.

02

Consolidate

One register across all sources, each certificate held once. Plus your governance data: owners, function or process, critical or important function.

03

Assess and report

Expiry by criticality, revocation status, weak cryptography, key reuse, orphans. Findings become Jira tickets with a due date and go to your monitoring, as a daily summary to Teams and as a complete export to auditors.

Certificate Intelligence in just over two minutes. Synthetic demo data; the product interface is shown in German. Product names mentioned are trademarks of their respective owners and describe compatibility.
Show technical architecture
  • All sources write into a stable, versioned JSON exchange format (exchange-v1). The logic lives in the register; the export scripts stay simple and individually reviewable.
  • The primary key is the SHA-256 fingerprint; imports are merged, never replaced. Governance data survives every new import.
  • Three field classes per certificate: technical fields from the certificate (immutable), governance fields (maintained, including custom columns) and provenance (last imported, last seen, source class internal / external / mixed).
  • Two transfer paths per source: HTTPS push with a token, or file export for isolated segments. Tokens are created, revoked and rotated centrally.
  • Findings: expiry by criticality, revocation status via CRL (CDP) and OCSP (AIA), weak cryptography (RSA below 2048, SHA-1), self-signed on a critical function, wildcard, key reuse (shared SPKI), orphans, chain and trust resolution via AKI/SKI.

The application

What Certificate Intelligence looks like today

The views are taken from the running application; its interface is in German.

Demo data / synthetic
Central register
Central certificate register of Blackfort Certificate Intelligence with synthetic demo data
All sources in one view, with fingerprint, source class and status.
Governance fields
Governance fields of a certificate including critical function, with synthetic demo data
Critical or important function, owners, function or process and custom columns per certificate.
DORA quick filter
DORA quick filter for expiry of critical and important functions, with synthetic demo data
Expiry of critical and important functions in one click.
Revoked but active
View of revoked but still active certificates, with synthetic demo data
Revocation status from CRL and OCSP, including the risky combination of revoked and still reachable.

All data shown is synthetic (example domains such as example.com / demo.internal). A public demo is available at certintel.demo.blackfort-tec.de (login demo / demo).

Findings

What Certificate Intelligence makes visible

Example finding types, illustrative and not taken from a specific customer inventory.

Certificate expires in 14 days

high

CN=portal.intern.example • critical function

Critical certificate of an internal portal with no documented owner responsible for renewal.

Revoked but still in use

high

OCSP: revoked • endpoint still serves the certificate

Revoked according to OCSP, yet still served by a reachable endpoint.

Weak cryptography

medium

RSA 1024 • SHA-1

Outdated key length and weak signature algorithm on an important function.

Unknown public certificate

medium

CT log • *.example.com

Discovered via Certificate Transparency, not part of the managed inventory.

34certificates without an ownerOften the most important governance finding: nobody responsible means nobody renews.

Positioning

The governance layer over your PKI

Certificate Intelligence does not take over your PKI and migrates nothing. It looks across all sources and makes inventory, ownership and risks auditable, including where a CLM platform is already in place.

Your CA

Issues certificates and knows its own inventory. A view across several CAs, cloud vaults and public certificates is not its job.

Your monitoring

Warns about expiry on the endpoints it knows. It does not see owners, critical functions or certificates outside monitored endpoints.

A CLM platform

Issues, renews and deploys. For that it needs extensive privileges and becomes a privileged system itself, often with a migration of the existing PKI.

Certificate Intelligence

Reads from all of these sources, consolidates them in one register and makes governance auditable. Your CAs and your CLM stay as they are.

Deliberately not included: issuance, automated renewal and deployment of certificates. If you want to build Certificate Lifecycle Management from scratch, you need a CLM platform for that; Certificate Intelligence checks its results.

Security architecture

No new privileged system

A system that issues and deploys certificates needs extensive privileges in your PKI. Certificate Intelligence does not. It is an inventory and only sees what is public on the certificate anyway.

Read-only

No changes to CAs, templates, vaults or services. No issuance, no revocation, no deployment.

No access to CA or keys

The register receives public certificates only, by push or as a file. It connects neither to your CA nor to key stores.

Openly readable export scripts

At the CA and key stores, small scripts of 72 to 220 lines run; for the Microsoft CA a PowerShell script with a SHA256 checksum. Your security team reads the source code beforehand.

Air-gap capable

Runs as containers in your environment, with an offline package and file import for isolated segments.

Roles

Web login with the roles admin (writes) and viewer (reads). Sign-in via OIDC/Entra ID is planned.

Audit trail

Append-only history of all changes; archiving instead of deletion, reversible and logged.

Integrations

Certificate status where your team already looks

Jira Cloud and Data Center · Prometheus + Grafana · PRTG · Nagios · Icinga · Checkmk · Zabbix · Elastic · Splunk · Datadog · Dynatrace · New Relic · SolarWinds Observability · ManageEngine OpManager

Findings become Jira tickets with a due date, and Certificate Intelligence keeps checking until they are resolved. Plus 13 monitoring integrations, tested in the Blackfort lab against the real software in October 2026, a daily summary card in a Microsoft Teams channel and the complete Excel/CSV export for auditors.

Show all integrations and connection methods

Jira Cloud and Data Center

Finding becomes a ticket with a due date, re-checked until resolved

Prometheus + Grafana

Metrics endpoint, dashboard, alert rules

PRTG

HTTP Data Advanced sensor

Nagios

Check plugin

Icinga

Check plugin

Checkmk

Check plugin as a classic check

Zabbix

Template with items and triggers

Elastic

Metricbeat, queries via ES|QL

Splunk

OpenTelemetry Collector to HEC

Datadog

Datadog Agent, OpenMetrics check

Dynatrace

OpenTelemetry (OTLP)

New Relic

OpenTelemetry (OTLP)

SolarWinds Observability

OpenTelemetry (OTLP)

ManageEngine OpManager

Script monitor via SSH

Jira is connected with an API token (Cloud) or personal access token (Data Center) that is stored only and never displayed again. Monitoring fetches the values from two read-only endpoints (Prometheus format and PRTG JSON) with a dedicated monitoring token that cannot submit or change anything. Product names mentioned are trademarks of their respective owners and describe compatibility; no partnership exists.

Benefits

Who gets what out of it

PKI operations

One inventory across all CAs instead of scattered Excel lists. Expiry by criticality, sources and data age in one view.

Information security

Weak cryptography, unknown public certificates, missing owners and revoked but active certificates visible in one place.

DORA and IT risk

Link certificates to critical or important functions and keep the register demonstrably up to date.

Internal and external audit

Receive the current inventory with governance fields and history as an Excel file, without an account in the system.

Offers and pricing

Try it, license it or have it introduced

Pilot

Certificate Inventory Pilot

free of charge

  • 30 days
  • up to 500 certificates
  • full feature set
  • self-install in your environment
  • support by email
  • price band and decision date agreed upfront
Request a pilot

Licence

Annual licence

from €2,490 net

Certificatesper year
up to 250€2,490
up to 1,000€4,900
up to 5,000€9,900
up to 10,000€14,900
up to 25,000€19,900
over 25,000on request
  • twelve months, updates and standard product support included
  • all released connectors and features in every tier
  • no surcharges per user, source or feature
  • 20 % growth tolerance until renewal
  • self-install without an installation fee

We count unique end-entity certificates in the operational inventory; duplicate finds, chain CA certificates and archived certificates do not count. We confirm the inventory size and band in your environment before contract signature. Capacity measured up to 30,000 certificates on 4 vCPU and 8 GB RAM. Guided introduction on a time-and-material basis at €150 per remote hour with an agreed budget cap (typically €450 for one source, €1,200 for up to three sources).

Request a quote

Guided

Assessments

  • Quick Assessment€4,900

    PKI and certificate check

    Orientation on one PKI or trust environment: interviews, documents, technical samples, risks and a prioritised action plan.

  • PKI Assessment€9,900

    Technology and governance

    In-depth review of up to two PKI/trust environments, including software-supported analysis of up to five exports.

  • Enterprise Intelligence Assessment€14,900 to €19,900

    PKI and certificate register

    Technical review plus introduction of the register at your site: source connection, governance mapping, critical functions, findings, management summary. Includes a 60-day project licence.

Fixed prices after scoping. Review and action plan; no remediation and no attestation. If you sign an annual licence within 60 days of the final report, we credit €1,000, at most 20 % of the first licence year.

Request an assessment

All prices for business customers, net plus VAT.

Frequently asked questions

Is Certificate Intelligence a Certificate Lifecycle Management product?+

No. Certificate Intelligence does not issue, renew or deploy certificates. It consolidates the inventory from your CAs, cloud vaults, network scans and CT logs in one register, assesses it and makes governance auditable. An existing CLM stays in place; Certificate Intelligence reads its inventory as well.

Which sources are supported?+

The connectors for Microsoft ADCS, EJBCA, HashiCorp Vault PKI and smallstep step-ca are validated against real CA software in the Blackfort PKI test lab. Kubernetes with cert-manager is tested in the lab against a real cluster. There are also read-only connectors for Azure Key Vault, AWS Certificate Manager and Google Certificate Manager. In addition there is a built-in TLS scanner (read-only fetch per host:port, no cipher probing), Certificate Transparency logs for your domains and a file import for isolated segments.

Is the Microsoft CA changed, or does the software see private keys?+

No. No templates are changed, no certificates are issued or revoked and no settings are modified. The export runs as an openly readable PowerShell script on or next to the CA; in its default mode it writes a file, with no token on the CA and no outbound connection from the CA. Private keys are never read.

Does the DORA certificate register requirement apply to us?+

Art. 7(4) of Delegated Regulation (EU) 2024/1774 applies to financial entities within the scope of DORA that are not subject to the simplified ICT risk management framework. Small and medium-sized insurance intermediaries are exempt from DORA. The regulation requires an up-to-date register, not a particular product. Certificate Intelligence supports implementation and evidence; it does not replace a legal assessment and does not guarantee compliance.

Can Certificate Intelligence be integrated into our monitoring?+

Yes. The register provides two read-only endpoints, in Prometheus format and as JSON for PRTG, accessed with dedicated monitoring tokens that cannot submit or change anything. Tested in the lab against the real software: Prometheus and Grafana, PRTG, Nagios, Icinga, Checkmk, Zabbix, Elastic, Splunk, Datadog, Dynatrace, New Relic, SolarWinds Observability and ManageEngine OpManager. Each integration comes with a guide and a template.

Are tickets created in Jira or ServiceNow?+

In Jira, yes. A finding becomes a ticket with a due date based on your deadline and a link back to the register. On every run Certificate Intelligence keeps checking: once the finding is resolved, the ticket is commented and, if you wish, closed; the same finding never creates a second ticket. You decide which finding types raise tickets. Tested against Jira Cloud; Jira Data Center is supported with a personal access token. ServiceNow and generic webhooks will follow.

How do external auditors get access?+

The simplest way needs no account: you export the complete register with all fields as an Excel or CSV file. Without an active filter, the export contains all certificates of the current inventory; archived certificates are left out. Alternatively, auditors get an account with the viewer role, which can only read.

How is the product operated?+

In your environment as containers (Docker Compose); for isolated networks there is an offline package. The licence is a signed offline licence, no connection to Blackfort is required. If a licence expires, reading and the complete export remain available.

Does it support Kubernetes, AWS or Google Cloud?+

Yes. The Kubernetes connector reads TLS secrets and cert-manager certificates read-only and is tested in the lab against a real cluster with cert-manager; a separate mode works without read access to secrets. There are also read-only connectors for AWS Certificate Manager and Google Certificate Manager. The TLS scanner is platform-independent.

Kontakt aufnehmen

Do you know which certificates are in use across your organisation?

Try Certificate Intelligence free for 30 days in your environment, or have your inventory captured in an assessment.