We maintain the security infrastructure your team owns but nobody owns.

Identity, secrets and certificates — deployed once, then left. Still running. Still nobody’s job.

The engineer who set it up moved on. It works, so it has no owner and no budget line — until a deadline or a security advisory makes it urgent overnight.

Wireframe drawing of a key

Certificate renewals just doubled. In March 2027 they roughly double again.

In April 2025, the CA/Browser Forum passed ballot SC-081v3 — 29 votes in favour, none against, with Apple, Google, Mozilla and Microsoft all voting yes. It steps the maximum lifetime of a publicly trusted TLS certificate down on a published schedule:

15 March 2026 — 200-day maximum certificate lifetime, 200-day domain-validation reuse. In force now.

15 March 2027 — 100-day maximum certificate lifetime, 100-day domain-validation reuse.

15 March 2029 — 47-day maximum certificate lifetime, 10-day domain-validation reuse.

Enforcement is by browsers, not by a standards body’s goodwill. A certificate that exceeds the limit simply stops being trusted.

The arithmetic is the whole story: an organisation that renewed annually now renews twice a year, will renew roughly 3.6 times a year from March 2027, and around eight times a year from 2029. Any process that depends on a person and a calendar reminder is being retired by that schedule whether or not anyone has scheduled its replacement.

Wireframe drawing of a clock

Three lines, one problem

Certificates — PKI and TLS lifecycle. Discovery of everything you actually present publicly, automated issuance and renewal, internal CA infrastructure, and the migration off manual processes before the arithmetic forces it.

Identity — self-hosted Keycloak. Kept current across major versions, with the upgrade paths rehearsed before they touch your environment. Realm configuration, federation, and the advisory cadence that never ends.

Secrets — Vault and OpenBao. Operated, upgraded and hardened. Including Vault to OpenBao migration for organisations re-evaluating after the licence change.

If you run this software on your own infrastructure, you have already decided not to buy a SaaS identity platform — usually for data residency, sovereignty or compliance reasons that are not going away. We work with that decision rather than trying to reverse it.

Wireframe drawing of three keys on a keyring

Start with an assessment

A fixed-scope, fixed-price review. One to two weeks. You get a report covering:

Every certificate your organisation presents publicly — issuer, expiry, key type

Which renew automatically and which depend on a human remembering

What breaks when the 100-day limit lands in March 2027

Your Keycloak, Vault and OpenBao versions, support status, and known upgrade cliffs

A prioritised remediation list, ordered by what actually bites first

It is deliberately small enough to authorise without procurement, and it produces a document you can put in front of your own management. Most of it is built from evidence we can gather before you give us access to anything.

Then we fix what it found — automated issuance and renewal, a stranded Keycloak brought current, a Vault to OpenBao migration, internal CA infrastructure replaced. Fixed scope, priced from findings.

And then, if it suits you, we keep it that way. A monthly retainer per environment, with a named engineer who answers when something breaks. Not a dashboard — a person with the authority to fix it, and a monthly statement your auditors will accept.

Wireframe drawing of a clipboard holding a checklist

Why bring in a third party for this

Because self-attestation is not attestation. When your auditors ask whether your certificate estate is under control, an answer from the team responsible for it is worth less than an answer from an independent party who did the work and signed the statement.

Because it is nobody’s job internally, and that is structural. This work is invisible when it is going well. It does not compete successfully for attention against roadmap commitments — not because your team is careless, but because that is what happens to maintenance everywhere.

Because we have the remediation capacity, not just the finding. Plenty of tools will tell you a certificate is expiring. The scarce thing is somebody who will go and fix the underlying process, and be accountable for it afterwards.

Wireframe drawing of a rubber stamp

Find out what you’re actually running

Most organisations are surprised by their own certificate inventory. The assessment is fixed-price, takes a week or two, and tells you exactly where you stand against the 2027 deadline.

Email contact