Built for certificate visibility without private-key upload.

BamGuard observes public certificate issuance and helps operators manage certificate visibility workflows. Certificate private keys remain on customer infrastructure.

Trust pillars

No certificate private keys uploaded

Root-only local credential storage

CT-based monitoring, accurately stated

Hosted checkout

Checkout and subscription management are hosted by a payment provider. BamGuard does not directly handle card details.

Open-source-friendly client hook

Designed to preserve compatibility with standard public ACME-DNS tooling.

BamGuard Certificate Visibility Flow

Customer Host
Public ACME-DNS Gateway
ACME-DNS / DNS-01
Certificate Authority
Certificate Transparency
BamGuard monitoring and alerts

Local credential storage

BamGuard client configuration should be stored with protected local permissions. Certificate private keys remain outside BamGuard.

Monitoring limitations

What BamGuard can observe

  • Public certificate or precertificate observations
  • Newer matching certificates
  • Issuer and SAN changes
  • Approaching expiry based on observed certificate data

What BamGuard does not claim

  • ×Certificate deployment
  • ×Endpoint health
  • ×Failed renewal detection
  • ×Private/internal PKI visibility through public CT