Built for certificate visibility without private-key upload.
BamGuard observes public certificate issuance and helps operators manage certificate visibility workflows. Certificate private keys remain on customer infrastructure.
Trust pillars
No certificate private keys uploaded
Root-only local credential storage
CT-based monitoring, accurately stated
Hosted checkout
Checkout and subscription management are hosted by a payment provider. BamGuard does not directly handle card details.
Open-source-friendly client hook
Designed to preserve compatibility with standard public ACME-DNS tooling.
BamGuard Certificate Visibility Flow
Customer Host
Public ACME-DNS Gateway
ACME-DNS / DNS-01
Certificate Authority
Certificate Transparency
BamGuard monitoring and alerts
Local credential storage
BamGuard client configuration should be stored with protected local permissions. Certificate private keys remain outside BamGuard.
Monitoring limitations
What BamGuard can observe
- Public certificate or precertificate observations
- Newer matching certificates
- Issuer and SAN changes
- Approaching expiry based on observed certificate data
What BamGuard does not claim
- ×Certificate deployment
- ×Endpoint health
- ×Failed renewal detection
- ×Private/internal PKI visibility through public CT