certmule.

Your clients' certs are about to renew eight times a year.

ACME handles nginx. It does not handle the FortiGate SSL VPN, the Synology in the closet, the UniFi controller, or the Exchange box. CertMule renews centrally and pushes the result into the hardware — at every client site, without anyone logging in.

  1. 2024398 days · 1×/yr
  2. 2026200 days · 2×/yr
  3. 2027100 days · 4×/yr
  4. 202947 days · 8×/yr

Maximum public certificate lifetime, per the CA/Browser Forum schedule (each step lands on 15 March). By 2029 that's eight renewals a year, on every device, at every client.

Where the certs go

One agent per client site talks to each device over its own API and restarts whatever needs restarting. Then it checks the device is actually serving the new certificate, and tells you if it isn't.

first wave later, or sooner if you ask

How it works

  1. Add one CNAME per client domain. No DNS API keys, no credentials handed over.
  2. The agent generates the key on site and sends only the signing request.
  3. We complete the ACME order with Let's Encrypt and return the signed certificate.
  4. The agent installs it on every device that needs it, then verifies what's being served.

Private keys are generated inside your client's network and never leave it. We hold signing requests and public certificates — nothing that would matter if we were breached.

Built for people running other people's networks

Multi-tenant by default: one console, every client separated. Hosted in the EU. Priced per client site so you can put it on the invoice. When a vendor changes their API and a deploy breaks, fixing it is our job, not a ticket in your queue.

This isn't built yet

It's being scoped right now, and which devices come first depends on who asks. Leave an address and I'll write when there's something to try — and I'll probably ask you two questions about your fleet first.

Noted — thanks. If you left devices, that goes straight into the build order.