CertKit review covering certificate discovery, automated issuance and renewal, deployment across servers and appliances, pricing tiers, and monitoring features.
Every organization running HTTPS services accumulates SSL/TLS certificates across an increasingly fragmented set of infrastructure: primary web servers, load balancers, CDNs, internal tools, VPN appliances, and third-party services, often provisioned by different engineers or teams at different times using different processes. Over time this makes it easy to lose track of which certificates exist, who issued them, and when they expire, and a single missed renewal on a production-facing certificate can cause an outage that is both embarrassing and entirely avoidable. CertKit's core value proposition is turning this scattered, manual tracking problem into a centralized, largely automated process: rather than relying on a spreadsheet of expiration dates and calendar reminders, or a patchwork of separately configured ACME clients on individual servers, teams get a single dashboard showing every certificate's status, source, and deployment target.
The discovery capability, built on scanning Certificate Transparency logs, is particularly useful for surfacing certificates an organization may not even know exist, since any publicly trusted certificate issued for a domain is required to be logged in these public, append-only CT logs by modern browser policy. This means CertKit can retroactively build a complete inventory of an organization's certificate footprint even for certificates that were issued outside CertKit itself, which is valuable for security and compliance audits as well as for simply avoiding the surprise of an unexpected expiration on infrastructure nobody remembered was there.
A key technical differentiator CertKit emphasizes is its deployment approach: instead of requiring every individual server or appliance to run its own ACME client configured with separate credentials, a single CertKit Agent handles deployment to a wide range of supported platforms, including major web servers (Nginx, Apache, IIS), load balancers (HAProxy, F5, AWS-style balancers), and network security appliances (Palo Alto, Citrix, Fortinet). Setup is designed around a one-time CNAME DNS record rather than ongoing per-integration API credential management, which the company argues reduces both the initial configuration burden and the long-term maintenance overhead of keeping multiple sets of API keys valid and secure across dozens of systems.
CertKit's pricing follows a fairly standard freemium SaaS structure: a genuinely free Community tier supports a small footprint of 2 certificates and 1 agent, suitable for individuals or very small setups evaluating the product. The Professional tier at 99 dollars per month scales that up to 10 certificates and 10 agents across 3 users, aimed at small IT teams. The Business tier at 399 dollars per month raises the ceiling to 50 certificates and 50 agents while adding single sign-on and audit logging, features that matter more once an organization has compliance or multi-team access requirements. An Enterprise tier above that offers custom, high-volume pricing along with multi-tenant account support, aimed at managed service providers or large IT organizations managing certificates across many separate client or business unit environments. All paid tiers include a 90-day free trial with no credit card required, a notably generous trial window relative to typical SaaS norms.
CertKit is used to discover, issue, renew, deploy, and monitor SSL/TLS certificates across an organization's servers, load balancers, and network appliances, aiming to prevent unexpected certificate expirations that can cause outages.
CertKit is built by TrackJS LLC, a small US-based software company that also makes the TrackJS error monitoring tool, Request Metrics, and RemoteJS.
CertKit offers a free Community tier limited to 2 certificates and 1 agent. Paid plans start at $99/month for the Professional tier, which supports 10 certificates and 10 agents, with higher Business and custom Enterprise tiers above that.
CertKit uses a centralized CertKit Agent that handles deployment to supported platforms like Nginx, Apache, IIS, HAProxy, F5, Palo Alto, Citrix, and Fortinet, after a one-time CNAME DNS record setup, rather than requiring a separately configured ACME client on each individual server.
CertKit crawls public Certificate Transparency logs, which are required by browser policy to record every publicly trusted certificate issued for a domain, allowing it to surface forgotten, orphaned, or unauthorized certificates alongside the ones an organization is actively managing.
Yes, according to the company's published platform support, CertKit works with Linux, Windows, Kubernetes, and Docker environments in addition to traditional servers and network appliances.
Yes. All paid tiers include a 90-day free trial that does not require a credit card, in addition to the permanently free Community tier.
Yes. CertKit's Enterprise tier supports multi-tenant account structures designed for managed service providers or large IT organizations managing certificates across multiple separate client or business unit environments.