Custody boundaries
Keep sensitive key material and operations closer to the customer environment.
A SecuriTLS satellite is a customer-side component for key generation, signing, deployment, validation, and other custody-sensitive workflows.
The platform coordinates jobs and records results while sensitive operations can remain closer to the environment that owns the keys and services.
Some organizations want the visibility and workflow benefits of a SaaS platform while keeping private-key operations inside infrastructure they control.
Keep sensitive key material and operations closer to the customer environment.
Use an outbound connection model for environments that should not expose inbound management services.
Coordinate local execution through the same certificate, deployment, validation, and audit workflows.
Generate private keys in the satellite environment and return certificate requests or encrypted results.
Coordinate signing through the satellite that holds or can access the relevant CA key material.
Encrypt deployment credentials for use by the intended satellite.
Write certificate, key, and CA materials to configured paths and run service reload commands.
Explore deployment automation →Inspect deployed certificate and key files in the customer environment.
Test live endpoints from the environment that can reach the target service.
Explore validation →Stores workflow state, certificate records, job status, deployment intent, and audit history.
Performs authorized local operations using customer-controlled access and encrypted material.
Receives certificate deployments and is validated from the appropriate network location.
Start with a private CA and a few certificates, then expand into automation, deployment validation, audit history, and satellite workflows.