PKI · Identity · Automation

Engineering the future of digital trust

Every outage, breach and failed audit starts the same way: a certificate nobody owned. RootCoreX finds every key and certificate you have, renews them before they expire, and keeps the evidence auditors ask for.

Deploys in your cloud or ours. No agents required.

0 Renewal success rate
0 Median time to issue
0 Native integrations
0 Expiry monitoring

The platform

Six products. One trust fabric.

Compare all products
Certificate lifecycle

RootCoreX CLM

Continuous discovery across networks, clouds and clusters. Every certificate gets an owner, a policy and an automated renewal path.

  • Agentless discovery in minutes
  • ACME, EST and SCEP enrolment
  • Zero-touch renewal and deployment
Next
Crypto-agility reporting for post-quantum migration.
Applied intelligence

RootCoreX AI

Models trained on certificate telemetry that flag the outage three weeks out — the weak key, the drifted config, the renewal that will silently fail.

  • Predictive expiry and failure scoring
  • Anomaly detection on issuance patterns
  • Plain-language remediation steps
Next
Autonomous remediation with human approval gates.
Identity & access

RootCoreX IAM

One policy engine for people, workloads and devices. Machine identities stop being second-class citizens.

  • OIDC, SAML and SCIM out of the box
  • Workload identity for Kubernetes and CI
  • Short-lived credentials by default
Next
Continuous access evaluation across sessions.
Key custody

RootCoreX Vault

Private keys that never leave hardware. FIPS 140-3 modules, quorum approval, and an append-only record of every operation.

  • PKCS#11 and KMIP compatible
  • Quorum-gated signing ceremonies
  • Tamper-evident audit log
Next
Bring-your-own-HSM across multi-cloud regions.
Open tooling

RootCoreX Labs

Free tools we built for ourselves and kept open: chain validators, CT log watchers, and a CLI that does not require remembering OpenSSL flags.

  • Certificate chain and CT inspector
  • TLS posture scanner
  • Open source, MIT licensed
Next
Post-quantum readiness checker.
Education

RootCoreX Academy

PKI is badly taught and widely misunderstood. Academy is the course we wished existed — practical, vendor-neutral, and free.

  • From X.509 basics to CA operations
  • Hands-on labs, no slideware
  • Certification track
Next
Post-quantum cryptography migration track.

Why RootCoreX

Built by the people who got paged at 3am

Certificate management is not a dashboard problem. It is an ownership problem, an automation problem, and an evidence problem. We built for all three.

Discovery that finds the shadow estate

Network scans, cloud APIs, Kubernetes secrets and CT logs, correlated into one inventory. The certificates you did not know about are the ones that take you down.

Automation with a rollback path

Renewal, deployment and reload, orchestrated per workload — with staged rollout and automatic revert when a health check fails.

Crypto-agility as a first-class feature

Inventory by algorithm and key size, model the blast radius of a migration, and move estates to new primitives without a two-year programme.

Evidence auditors accept

Every issuance, approval and revocation written to an append-only log, exportable against SOC 2, ISO 27001, PCI DSS and eIDAS controls.

Runs where your workloads run

SaaS, private cloud or fully air-gapped. Same control plane, same API, no feature asymmetry between deployment models.

API and CLI before UI

Every capability ships as an API first. Terraform provider and CLI are maintained by the same team, versioned with the platform.

Speaks the protocols your estate already runs on

X.509 ACME EST SCEP CMPv2 PKCS#11 KMIP mTLS OIDC SAML SPIFFE Kubernetes Terraform HashiCorp Vault FIPS 140-3 eIDAS

Writing

From the team

All articles

Roadmap

What we are building next

Published because you should be able to check whether we ship what we say. Dates are targets, not contracts.

  1. Q3 2026 · Shipped

    Agentless discovery v2

    Cloud-native scanning across AWS, Azure and GCP with CT log correlation.

  2. Q4 2026

    Crypto-agility reporting

    Algorithm inventory, blast-radius modelling and staged migration plans.

  3. Q1 2027

    Autonomous remediation

    AI-proposed fixes executed behind explicit human approval gates.

  4. Q2 2027

    Post-quantum issuance

    ML-DSA and hybrid certificate profiles, with dual-chain rollout support.

Get started

See your certificate estate in 30 minutes

We will run a read-only discovery against one environment and walk you through what we find. No commitment, no agents.