Skip to content

Autonomous Machine Identity & Certificate Lifecycle Management

Know every certificate. Replace it before it expires.

Guardian CLM autonomously discovers every TLS certificate across your external domains and internal subnets. It visualizes systemic exposure before failures occur, and is engineered for zero-touch, pre-expiry renewals across servers and network appliances (including F5 BIG-IP and FortiGate) over agentless SSH—with zero software installed on your infrastructure.

Guardian CLM dashboard: a system health score of 72 out of 100, certificate counts by state, and the start of the blast radius map

One platform, built to run without you.

The core engine discovers, renews and deploys without agents. Intelligence layers are being added on top, and each card shows where it stands.

Core

Agentless discovery

Sweeps IP ranges and domains over standard TLS, then recognises the platform behind each certificate from its handshake fingerprint. Nothing to install on any server.

Core

Renewal & deployment engine

Renews certificates and deploys them over SSH and SFTP, with a service-specific pre-check and an atomic file swap. Zero-touch scheduling is being built on this engine.

Core

Blast radius map

Draws your whole estate as one map, grouped by Cloud, On-Prem and Hosting, and lights up every certificate that is expired or revoked.

Planned

AI anomaly detection

Flags unknown issuers, sudden certificate swaps and scan spikes. It starts with clear rules, then learns what normal looks like for your estate.

Planned

MCP integration

Lets your own AI assistants ask Guardian about expiring certificates through the Model Context Protocol, with every action permissioned and logged.

Planned

Post-quantum readiness

Shows which certificates rely on quantum-vulnerable keys and which servers already negotiate hybrid post-quantum key exchange, so migration is a plan and not a scramble.

Core features are part of the platform engine. Planned features are on the roadmap.

Simple on the surface. Autonomous underneath.

We designed Guardian CLM around the things that make certificate tools painful to adopt, and removed them.

  • No agents, no sidecars

    Guardian reaches your servers over SSH, SFTP and standard TLS. There is nothing to install, patch or keep alive on production machines, which also keeps the security review short.

  • Finds the certificates nobody tracked

    Discovery does not wait for you to register a host. It sweeps your ranges, identifies the platform behind each certificate, and lists unmanaged devices you can bring under management in one click.

  • Shows impact, not just dates

    The blast radius map groups your estate by Cloud, On-Prem and Hosting and highlights risk, so you see what is exposed at a glance instead of scrolling a spreadsheet.

  • Works with the CA you already use

    Connectors for DigiCert CertCentral, Active Directory Certificate Services and OpenBao or Vault PKI feed one inventory. You are not tied to a single issuer.

  • Deploys without taking services down

    Each deployment runs a service-specific pre-check, such as nginx -t, and swaps files atomically. A bad certificate never reaches a live service.

  • Multi-Tenant & MSSP Architecture

    Architected with strict database-level tenant isolation (RLS), ready for MSSP operations.

  • Built for data that has to stay put

    Designed to run as SaaS or inside your own network. Secrets are kept in OpenBao, an open-source vault.

Certificates are about to live eight times shorter.

Browsers and certificate authorities agreed to cut the maximum lifetime of public TLS certificates from 398 days to 47 by March 2029. Spreadsheets and calendar reminders will not keep up.

  • Until March 2026Old maximum
    398days
  • From March 2026In force today
    200days
  • From March 2027
    100days
  • From March 2029Final step
    47days

A fleet of 1,000 certificates needs roughly 900 renewals a year today. At 47 days it needs 7,766. Every one touches a different server, owner and process, and every missed one is an outage.

Built for global enterprise compliance.

Regulators in every region ask the same question: do you know what you run, and who is accountable for it?

EU NIS2 & DORA

Cyber-resilience inventory for financial and critical-infrastructure entities: which cryptographic assets you run, who owns them, and proof that they are controlled.

Zero Trust Architecture

NIST SP 800-207

Continuous machine identity verification. Guardian keeps a live record of which certificate identifies which system, so trust is checked and not assumed.

National cybersecurity frameworks

Visibility and control that align with GCC and international critical-infrastructure regulation, wherever your estate runs.

Guardian CLM supplies a live inventory of every certificate, its owner, its expiry and an audit log of every change. It supports your compliance work and does not replace it.

Autonomous discovery, drawn as one estate.

Guardian CLM reaches your network from the outside, finds every certificate, and maps what each one protects. Select a pulsing marker to inspect an exposed certificate.

Blast radius map from the Guardian CLM dashboard. Certificates are grouped into Cloud, On-Prem and Hosting nodes around the IT Expert tenant, and expired certificates are marked red.
Expired or revoked. Tap a marker to open details.Product screenshot. Certificate details shown are sample data.

Discover

Sweeps IP ranges and domains over standard TLS and recognises the platform behind each certificate. Nothing is installed on your servers.

Map

Groups every certificate into Cloud, On-Prem and Hosting, and lights up what is expired, revoked or about to be.

Deploy

Pushes replacements over SSH and SFTP, runs a service-specific pre-check, and swaps files atomically.

The product, as it runs today.

Real screens from the Guardian CLM console, not mock-ups.

Full visibility from edge to core.

Sweeps public domains and internal RFC1918 subnets over standard TLS handshakes. Identifies rogue and self-signed certificates, platform fingerprints, and key health without deploying a single sensor.

Certificate detail dialog for itexpert.com.tr showing status, expiry, serial number, public key, signature algorithm, platform, subject, issuer and fingerprint

Tap the screen to view it full size.

Where Guardian CLM is going.

Three phases, from a dependable agentless core to a certificate estate that runs itself.

  1. Active

    Phase 1: Agentless Core & Discovery

    The foundation: see every certificate and deploy without agents.

    • Discovery with automatic platform recognition
    • Blast radius map and live health score
    • Agentless deployment over SSH and SFTP, including F5 BIG-IP and FortiGate
    • Connectors for DigiCert, Active Directory Certificate Services and OpenBao PKI
    • Renewal automation and enterprise sign-in (MFA, SSO)
  2. Next

    Phase 2: Predictive AI & Machine Identity Intelligence

    From reacting to expiry to predicting risk.

    • Anomaly detection: unknown issuers, sudden swaps, scan spikes
    • Kubernetes and cloud certificate discovery
    • AI assistant access through the Model Context Protocol
    • Cost and risk insights across your certificate estate
  3. Later

    Phase 3: Autonomous PKI & Post-Quantum Cryptography

    Certificates that manage themselves, ready for quantum.

    • Autonomous issuance and purchasing, within budget guardrails
    • Hybrid post-quantum key exchange and signatures
    • Independent penetration test
    • SOC 2 readiness

Phases are ordered by priority. Scope and timing may change.

Apply for early access.

Join the closed pilot and run Guardian CLM on your own network.

Organization type

We use your details only to reply to this request.