CertKit Review, Pricing & Features

CertKit review covering certificate discovery, automated issuance and renewal, deployment across servers and appliances, pricing tiers, and monitoring features.

Category
Security
Pricing
Freemium tiered subscription (Community, Professional, Business, Enterprise), from Free (Community plan); paid plans start at $99/month (Professional)
Verified
Not yet
Last updated
July 19, 2026
Founded
2024
Headquarters
United States

The Certificate Lifecycle Problem CertKit Solves

Every organization running HTTPS services accumulates SSL/TLS certificates across an increasingly fragmented set of infrastructure: primary web servers, load balancers, CDNs, internal tools, VPN appliances, and third-party services, often provisioned by different engineers or teams at different times using different processes. Over time this makes it easy to lose track of which certificates exist, who issued them, and when they expire, and a single missed renewal on a production-facing certificate can cause an outage that is both embarrassing and entirely avoidable. CertKit's core value proposition is turning this scattered, manual tracking problem into a centralized, largely automated process: rather than relying on a spreadsheet of expiration dates and calendar reminders, or a patchwork of separately configured ACME clients on individual servers, teams get a single dashboard showing every certificate's status, source, and deployment target.

The discovery capability, built on scanning Certificate Transparency logs, is particularly useful for surfacing certificates an organization may not even know exist, since any publicly trusted certificate issued for a domain is required to be logged in these public, append-only CT logs by modern browser policy. This means CertKit can retroactively build a complete inventory of an organization's certificate footprint even for certificates that were issued outside CertKit itself, which is valuable for security and compliance audits as well as for simply avoiding the surprise of an unexpected expiration on infrastructure nobody remembered was there.

Deployment Model and Pricing Tiers

A key technical differentiator CertKit emphasizes is its deployment approach: instead of requiring every individual server or appliance to run its own ACME client configured with separate credentials, a single CertKit Agent handles deployment to a wide range of supported platforms, including major web servers (Nginx, Apache, IIS), load balancers (HAProxy, F5, AWS-style balancers), and network security appliances (Palo Alto, Citrix, Fortinet). Setup is designed around a one-time CNAME DNS record rather than ongoing per-integration API credential management, which the company argues reduces both the initial configuration burden and the long-term maintenance overhead of keeping multiple sets of API keys valid and secure across dozens of systems.

CertKit's pricing follows a fairly standard freemium SaaS structure: a genuinely free Community tier supports a small footprint of 2 certificates and 1 agent, suitable for individuals or very small setups evaluating the product. The Professional tier at 99 dollars per month scales that up to 10 certificates and 10 agents across 3 users, aimed at small IT teams. The Business tier at 399 dollars per month raises the ceiling to 50 certificates and 50 agents while adding single sign-on and audit logging, features that matter more once an organization has compliance or multi-team access requirements. An Enterprise tier above that offers custom, high-volume pricing along with multi-tenant account support, aimed at managed service providers or large IT organizations managing certificates across many separate client or business unit environments. All paid tiers include a 90-day free trial with no credit card required, a notably generous trial window relative to typical SaaS norms.

Key Features

Pros & Cons

Pros

  • Free Community tier makes it easy to evaluate the platform's core discovery and monitoring capabilities without cost.
  • Deployment via a single agent to a wide range of servers and network appliances, without needing ACME configured everywhere, simplifies rollout across heterogeneous infrastructure.
  • Certificate Transparency-based discovery surfaces forgotten or unauthorized certificates that manual tracking would likely miss.
  • Generous 90-day free trial on paid tiers with no credit card required lowers the barrier to a full evaluation.
  • Purpose-built and narrowly focused on certificate lifecycle management rather than being a small feature bolted onto a broader security suite.

Cons

  • A relatively new product, launched in 2024, with less of a long-term track record than established certificate lifecycle management vendors.
  • Small company (TrackJS LLC) behind the product means less scale of support and resources compared to larger enterprise security vendors.
  • Free and entry-level paid tiers cap certificate and agent counts fairly low (2 and 10 respectively), meaning larger organizations will need Business or Enterprise pricing quickly.
  • Enterprise pricing is custom and not published, requiring a sales conversation for large-scale or multi-tenant deployments.
  • As with any tool crawling Certificate Transparency logs, discovery is limited to publicly logged certificates and won't surface internal-only or private CA-issued certificates not logged publicly.

Pricing

Frequently Asked Questions

What is CertKit used for?

CertKit is used to discover, issue, renew, deploy, and monitor SSL/TLS certificates across an organization's servers, load balancers, and network appliances, aiming to prevent unexpected certificate expirations that can cause outages.

Who makes CertKit?

CertKit is built by TrackJS LLC, a small US-based software company that also makes the TrackJS error monitoring tool, Request Metrics, and RemoteJS.

Is CertKit free?

CertKit offers a free Community tier limited to 2 certificates and 1 agent. Paid plans start at $99/month for the Professional tier, which supports 10 certificates and 10 agents, with higher Business and custom Enterprise tiers above that.

How does CertKit deploy certificates without ACME on every server?

CertKit uses a centralized CertKit Agent that handles deployment to supported platforms like Nginx, Apache, IIS, HAProxy, F5, Palo Alto, Citrix, and Fortinet, after a one-time CNAME DNS record setup, rather than requiring a separately configured ACME client on each individual server.

How does CertKit find certificates I did not know existed?

CertKit crawls public Certificate Transparency logs, which are required by browser policy to record every publicly trusted certificate issued for a domain, allowing it to surface forgotten, orphaned, or unauthorized certificates alongside the ones an organization is actively managing.

Does CertKit support Kubernetes and Docker environments?

Yes, according to the company's published platform support, CertKit works with Linux, Windows, Kubernetes, and Docker environments in addition to traditional servers and network appliances.

Does CertKit offer a free trial?

Yes. All paid tiers include a 90-day free trial that does not require a credit card, in addition to the permanently free Community tier.

Is CertKit suitable for managed service providers?

Yes. CertKit's Enterprise tier supports multi-tenant account structures designed for managed service providers or large IT organizations managing certificates across multiple separate client or business unit environments.

Related Tools