Discovery & Compliance
Find every certificate on your estate, then audit and score its TLS posture.
Overview
You cannot manage what you cannot see. DuoKey's discovery subsystem finds certificates across your network and endpoints — including ones issued outside the platform — imports them for tracking, and evaluates each one's SSL/TLS posture against recognized compliance baselines.
Discover
Network scanners and installed agents locate TLS endpoints and certificates across the estate.
Import & track
Bring discovered certificates under management to monitor expiry and ownership.
Audit & score
Run a per-certificate SSL/TLS audit and evaluate compliance against Mozilla / NIST / PCI DSS.
Scanning
Scanners can run from the network or via installed agents (a managed fleet with key rotation, revocation and downloadable install bundles). Discovered certificates can be reviewed and imported into the certificate inventory.
SSL/TLS audit and compliance
Each discovered or managed certificate can be run through a per-certificate SSL/TLS audit, with history and re-runs, and evaluated against compliance frameworks (Mozilla configurations, NIST guidance, PCI DSS) or your own tenant policies.
Pair discovery with the enrollment protocols and deployment tooling: find an out-of-policy or expiring certificate, re-issue it from a compliant CA, and deploy the replacement — all from one console.