Inventory that knows ownership
Every credential points back to an owner, tenant, source, expiry, risk and operational state instead of living as an orphaned blob.
trstctl runs the lifecycle for all of them, self-hosted, with private keys sealed in an isolated signer. For platform and security teams with more certificates than people, for MSPs that hold their customers’, and for estates with no path to the internet: defense, critical infrastructure, sovereign and regulated networks, OT.
The full console in your browser: sample data, no signup, no backend.
A CDN keeps the public edge on short lifetimes automatically. Behind it sit origin certificates, internal services, mTLS clients, SSH trust, secrets, tokens, workload identities and now agents, on the same short-lived trajectory with no one to automate them. That is the part trstctl runs.
One control plane or dedicated deployments, each customer isolated by construction, usage metered per customer as invoice evidence, and managed-service and resale rights in the license. The 47-day schedule multiplies by your whole book of business; trstctl is built to carry that.
Every page in trstctl opens with the answer, then the real next action, then the exact evidence behind it. Missing evidence says unavailable; it is never dressed up as a reassuring zero.
Sources, schedules and runs feed one findings list, with CT watch and policy drift, so every credential gets an owner.
Open Discover in the demo
Inventory, estate health, CRL and CT, and renewal readiness on one list, with the next 90 days of work counted.
Open Certificates in the demo
SPIFFE and attested identities, ephemeral credentials, SSH access and fleet agents, each tied to the machine that holds them.
Open Workloads in the demo
Leaks, overdue rotation, failed delivery and access are visible before anyone opens a value; dynamic sources mint short-lived credentials.
Open Secrets in the demo
Code signing with provenance, keyless flows and the health of the key behind every signature.
Open Software Trust in the demo
What to fix first, incidents with a remediation path, approvals, jobs and queues, and a change history you can replay.
Open Operations in the demo
Every credential points back to an owner, tenant, source, expiry, risk and operational state instead of living as an orphaned blob.
See where a credential is used, what it can reach, which systems depend on it, and what breaks if it expires or is revoked.
Non-human identity goes wrong at the worst time. The answer should already be in the inventory, the graph and the audit trail.
“We’re breached. Which keys and certs can reach that host, and what do we kill first?”
The credential graph shows what each one can reach and what depends on it, so you revoke by blast radius instead of guessing.
“Audit wants every certificate issued last quarter, and who approved each one.”
Every issuance, approval and revocation is an immutable event you can replay. The audit trail is the product state, not a side spreadsheet.
“Can we automate issuance without handing a robot the CA private keys?”
The signer is a separate, isolated process. The control plane orchestrates but never holds the keys. Automation without losing custody.
The lifecycle is explicit: every state change emits an event, every external action goes through an outbox, and every retry is idempotent.
Agents and connectors find certificates, SSH trust, keys, secrets and workload identities.
Profiles, policies, approvals and signer-backed CA custody turn requests into credentials.
Connectors write to the target only after the intent is recorded durably in the outbox.
Policy-driven renewal keeps expiry from becoming an outage, with retry-safe operations.
Revocation, decommission and audit close the loop instead of leaving stale trust behind.
A separate signer process holds them and signs on request. That separation is the product, not a deployment detail.
Issuance, renewal and revocation are immutable events. The audit trail is the product’s own memory, replayable on demand.
PostgreSQL row-level security enforces the tenant line, so a missed check fails a test instead of a customer.
Proof-carrying algorithm succession moves an estate to a new signing algorithm with a verifiable record at every step.
trstctl is not here to replace a great secrets engine or your in-cluster certificate automation. It is the inventory, lifecycle and audit layer across every kind of non-human identity, so the credentials no single tool owns stop falling through the cracks.
A secrets engine is excellent at secrets. trstctl wraps the full lifecycle around all non-human identity, from discovery to audit, and keeps signing in a separate, isolated process rather than in-app.
Commercial CA managers are strong at X.509 at scale. trstctl treats X.509, SSH, secrets, API keys, tokens and SPIFFE as one inventory, self-hosted and source-available, with no per-certificate licensing.
In-cluster tooling is great at in-cluster certificates. trstctl spans clusters and the hybrid estate beyond Kubernetes, with an event-sourced audit trail you can replay and rebuild.
Everything the lifecycle needs runs inside your network. The parts that do not are named here, not hidden.
An egress guard that fails closed. An offline install bundle with checksums. An offline license. Offline-verifiable evidence. Telemetry off, with no collector to send to.
A public certificate authority, cloud DNS for validation, cloud certificate stores, transparency-log monitoring, cloud AI. Each is a destination you configure; nothing leaves otherwise.
Run a local evaluation stack, deploy with Docker or Helm, then connect agents and CA and deployment integrations as your environment grows.
Business Source License 1.1: run it in production free, with no signed license; each release converts to MPL 2.0 four years after it ships. Licensing →
trstctl is pre-1.0 and in active development. The docs keep a standing list of what is served and what is not yet, and the demo runs on sample data. Expect rough edges, and file what you find. Current limitations → · Report an issue →
Start with the demo, then discovery. It is alpha software: expect rough edges, file what you find, and keep going until issuance, rotation, revocation and audit are boring.