Skip to content

Cyphers

On-premises certificate lifecycle management for infrastructure teams.

Cyphers monitors, scores, and automates the renewal of the TLS certificates across your fleet — built for the 47-day certificate era (the CA/Browser Forum is stepping maximum certificate lifetimes down to 200 days in Mar 2026, 100 days in Mar 2027, and 47 days in Mar 2029). Everything runs on your own network: no SaaS dependency, no certificates or private keys leaving your infrastructure.

The two halves

Component Runs Role
Hub (Rust) Your server API, dashboard, built-in CA, ACME client, scoring, renewal lifecycle, fleet posture
Scout (Go) Each endpoint The agent on your servers: scans TLS posture, discovers on-disk certificates, and executes the Hub's issuance / delivery / renewal commands

New here?

  • Quick start — Hub, first Scout, first managed endpoint, in about 30 minutes.
  • Product overview — the components, the lifecycle loop, and the operator surface, in one read.

Understand it — Concepts

Do it — How-to guides

Task-shaped, step-by-step, with expected output at every step:

Look it up — Reference

Run it — Operations

Read the maturity markers

These pages are a deliberately honest capability map — the Scout pages note live / partial / stub / dead status and platform gates, so you can tell a shipped feature from an aspiration.

Scope of this wiki

This is the product wiki — what Cyphers does and how to operate it. The engineering references (architecture internals, wire contracts, design plans) live in the repo's top-level docs/ folder.