Certificate authority as a service

Every device on your network, holding a certificate you issued.

ScepNet runs a private certificate authority for your organization and hands certificates to your devices over SCEP. Your laptops and phones authenticate to Wi-Fi and wired networks with 802.1X — no shared password, nothing to type, nothing to leak.

5 devices free for 14 days. No card required to start.

LAPTOP PHONE DESKTOP SCEP ScepNet YOUR PRIVATE CA RADIUS WI-FI / SWITCH 802.1X

Why bother

A Wi-Fi password is one screenshot away from everyone.

Shared network passwords get texted to contractors, saved in personal password managers, and walk out the door with people who leave. Rotating one means touching every device you own.

Certificates fix that. Each device proves itself with its own key, which never leaves it and cannot be read off a screen or forwarded. When someone leaves, you revoke one certificate instead of changing the password for everybody.

  • Nothing to type. The device authenticates itself. Users never see a credential, so they cannot share one.
  • Revoke one device. A lost laptop stops authenticating at the next revocation check. Everyone else is unaffected.
  • Only your devices. A certificate from your CA is the whole admission test — an unmanaged machine has nothing to present.
  • Nothing exposed. You run no certificate authority, no NDES, and open no port to the internet.

How it works

Three steps, and your MDM does the rest.

Get your own CA

Sign up and we generate a root and an intermediate certificate authority that belong only to you. They vouch for your devices and for nothing else on earth.

Point your MDM at it

Add a SCEP payload with the URL and challenge from your dashboard. Jamf, Intune, Mosyle, Kandji, Workspace ONE, or a plain configuration profile — anything that speaks SCEP.

Devices enroll themselves

Each device generates its own key, requests a certificate, and starts authenticating. You watch them appear on the dashboard. Nobody visits a desk.

What you get

Built for the awkward parts.

A root that is yours alone

Every organization gets its own root, not a slice of a shared one. Another customer's CA cannot issue a certificate your network would accept — that isolation is structural, not a policy we promise to enforce.

Any MDM, no lock-in

A standard SCEP endpoint with a static challenge. One URL serves your whole fleet — no per-device setup, no agent, and nothing that only works with one vendor's console.

Revocation that actually works

A revocation list published at a fixed address, regenerated the moment you revoke and refreshed before it can expire. Point NPS, FreeRADIUS or ClearPass at it, or mirror it to an address you control.

Bring your own root

Already have a corporate CA? Sign our intermediate with it and we issue beneath your existing trust anchor. Your root stays offline; nothing of yours faces the internet.

Outages do not knock you offline

Certificates already issued keep authenticating whether or not you can reach us. What needs the service is enrolling a new device or fetching a fresh revocation list — not the daily business of getting onto Wi-Fi.

An audit trail you can hand over

Every issuance, revocation and sign-in recorded in an append-only, hash-chained log. It cannot be edited — by us either — without the chain visibly breaking.

Put a certificate on five devices this afternoon.

The trial is 14 days and 5 devices — enough to enroll a laptop, authenticate it against your own network, revoke it, and watch the revocation list update.

  • No card to start
  • Nothing renews on its own — every period is a separate payment
  • Devices you enrolled keep working after the trial ends
  • Priced in devices, not certificates — re-enrolling costs nothing