Automate Certificates

TLS renewal
without the hunt.

Tracks certificates, runs ACME renewal, and deploys to cloud and database targets.

UK GDPR · NIS Regulations

Capabilities

Discovery, ACME renewal, and deployment to 22 targets

  • ACME issuance and renewal

    Request Let's Encrypt certificates via ACME v2 with DNS-01 or HTTP-01 challenges; the cron job renews 30 days before expiry.

  • Tenant-wide discovery

    Scan Azure subscriptions, Key Vaults, App Services, and App Gateways to surface certificates that never made it into your inventory.

  • Multi-target deployment

    Push renewed certs to 22 target types — Azure Key Vault, App Service, App Gateway, AWS ACM, ALB, GCP load balancers, PostgreSQL, and more.

  • Expiry alerting

    Slack, Microsoft Teams, Graph email, and SMTP notifications when a cert enters the renewal window or a renewal attempt fails.

  • Audit records per renewal

    Append-only log with CSV export and webhook delivery for every issuance, deployment, and Marketplace lifecycle action.

  • Entra SSO and scoped API keys

    Azure service principal authentication for tenant scans; OIDC sign-in with TOTP MFA and API keys scoped to specific operations.

In the product

Inside Automate Certificates.

Real product screens — dashboard, certificate inventory, deployments, discovery, monitoring, alerts, and sign-in.

Automate Certificates dashboard
Automate Certificates certificates screen
Automate Certificates deployments screen
Automate Certificates discovery screen
Automate Certificates monitoring screen
Automate Certificates alerts screen
Automate Certificates sign-in screen

Dashboard — valid, expiring, and failed certificates

How it works.

  1. Discover your inventory

    Run an Azure tenant scan or import existing certs — every domain, issuer, and expiry date lands in one inventory with risk badges on the ones due soon.

  2. Issue and schedule renewal

    Request certificates through ACME v2; Automate Certificates renews 30 days before expiry and records each attempt in the audit log.

  3. Deploy and alert

    Push the renewed cert to linked targets on schedule or immediately; Slack, Teams, or SMTP alerts fire if deployment or renewal fails.

Pricing.

From €199/month (Team), Business at €499/month, and MSP from €1,499/month. Monthly billing only. Every plan starts with a 30-day trial (card checkout). Invoice billing is paid from day one.

Team

€199 / month

30-day trial (card checkout)

Managed certificates
50
Domains
10
Deploy targets
5
Discovery scans
Daily
  • Managed certificate estate
  • Deployment workflows and scoped API keys
  • Team access and core features
Start a 30-day trial

MSP

from €1,499 / month

30-day trial (card checkout)

Managed certificates
1,000+
Domains
250+
Deploy targets
All 21
Discovery scans
Hourly
  • Customer-tenant certificate and deployment workflows
  • Per-customer reporting
  • White-label notification templates
Talk to us

Questions.

  • Where is certificate data stored?

    One shared Cloudflare Worker, operated by Spot Cloud B.V., serves every customer. Customer data sits in one Postgres database that Supabase, a subprocessor, hosts in the EU. On your own environment host (yourcompany.automate-certificates.com), certificate data is kept in a schema of its own. Data created through app.automate-certificates.com or the API at api.automate-certificates.com, Azure agent scan results, and accounts, sign-in sessions and API keys live in a shared central schema, where every query is filtered by organisation. There are three exceptions. Private keys and credentials are encrypted with AES-256-GCM and held in Cloudflare Workers KV, which is not limited to EU locations. Our hourly backup dump of the database is kept in Cloudflare object storage in Western Europe under Cloudflare's default jurisdiction, not its EU jurisdiction. Workspaces bought through Azure Marketplace are stored in the Azure region the buyer picks at purchase: North Europe, West Europe or a US region. UK GDPR applies; UK-to-EU data flows rest on the UK-EU adequacy decision, with a UK Addendum and IDTA available on request.

  • How does sign-in work?

    Operators sign in through Spot Suite OIDC with passkeys, authenticator-app MFA, or Entra ID federation. Azure tenant scans authenticate via a service principal with RS256 JWKS validation; programmatic access uses scoped API keys with fine-grained permissions.

  • What compliance records does it produce?

    UK GDPR and NIS Regulations-aligned audit reports, per-renewal exports with CSV download and webhook delivery. The append-only log records every issuance, deployment, and Marketplace lifecycle action with reviewer identity and timestamp.

  • What does the 30-day trial include?

    Every plan starts with a 30-day trial (card checkout). Invoice billing is paid from day one. Full ACME issuance, auto-renewal, and deployment. After the trial, choose Team at €199 per month, Business at €499 per month, or MSP from €1,499 per month.

Stop hunting expired certificates

Connect your first target, run a discovery scan, and let ACME handle renewal. Every plan starts with a 30-day free trial (card checkout). Invoice billing is available (paid from day one).