ACME handles nginx. It does not handle the FortiGate SSL VPN, the Synology in the closet, the UniFi controller, or the Exchange box. CertMule renews centrally and pushes the result into the hardware — at every client site, without anyone logging in.
Maximum public certificate lifetime, per the CA/Browser Forum schedule (each step lands on 15 March). By 2029 that's eight renewals a year, on every device, at every client.
One agent per client site talks to each device over its own API and restarts whatever needs restarting. Then it checks the device is actually serving the new certificate, and tells you if it isn't.
first wave later, or sooner if you ask
CNAME per client domain. No DNS API keys, no credentials handed over.Private keys are generated inside your client's network and never leave it. We hold signing requests and public certificates — nothing that would matter if we were breached.
Multi-tenant by default: one console, every client separated. Hosted in the EU. Priced per client site so you can put it on the invoice. When a vendor changes their API and a deploy breaks, fixing it is our job, not a ticket in your queue.
It's being scoped right now, and which devices come first depends on who asks. Leave an address and I'll write when there's something to try — and I'll probably ask you two questions about your fleet first.
Noted — thanks. If you left devices, that goes straight into the build order.
That didn't go through. Email hello@certmule.com instead — same two lines.