One price a year, and nothing per certificate
Start free on a single server. Move to Standard when it is worth having the whole company covered - which for most businesses is where it stops.
Free
One server, to see if this works for you
The whole cycle - issue, install, renew - on one real machine. No payment details.
- 1 certificate, 1 server, 1 domain
- Let's Encrypt, already set up
- Windows certificate store, or NGINX, Apache, any file path on Linux
- Automatic renewal
- Mail alerts
- 7 days of history
Standard
A company running its own servers
Full certificate automation for a company that runs its own infrastructure, at business scale rather than data-centre volumes.
- 150 certificates, 75 servers, 5 domains
- Any certificate authority, public or your own internal CA
- Everywhere a certificate can be installed - IIS bindings, Exchange, ADFS, Remote Desktop, SQL Server, NGINX, Apache, NetScaler, Docker and more
- Groups and policies, so a new server arrives with its certificate already being issued
- All key types, including exportable keys for Windows
- 30 days of history
Pro
A larger estate, or one you already monitor
Standard's capabilities with room to grow, faster reporting, and a way into the monitoring system you already run.
- 1,500 certificates, 1,000 servers, 25 domains
- Agents can report in as often as every minute
- Fleet metrics for CheckMK, Prometheus or Grafana
- Alerts pushed to a webhook, a SIEM over syslog/CEF, or an SNMP trap receiver
- 90 days of history, in the dashboard and on the servers
- Everything in Standard, unchanged
MSP
Selling certificate management as a service
Multi-tenant, with a separate workspace per customer. You buy licences at a wholesale rate and charge your own price.
- 5 Standard-tier customer places included
- A fully separate workspace per customer - never a shared view
- Buy more Standard or Pro places from the dashboard, at a discounted rate
- Assign, reassign and control auto-renew per customer
- Scope each of your staff to the customers they actually look after
- Your own workspace runs at Standard's numbers, with Pro's monitoring integrations and 90 days of history
MSP Plus
Reselling under your own brand
Everything in MSP, plus your customers reach the dashboard on your own domain, under your own name, logo and colours.
- Everything in MSP, unchanged
- Your customers sign in on your own dashboard domain
- Your name, logo, colours and typeface throughout - support details too
- Same containers, same database, same agents underneath
- Set up once: a DNS record and a login, no redeploy
Free plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.
Already have an account? Change plan under Settings › Organization › Billing.
What is true whichever plan you pick
One price, however much it protects
Nothing is charged per certificate or per user. Invite your whole team; the number that matters is how many servers and certificates you have.
Billed once a year
There is no monthly option. Prices exclude applicable taxes, and everything - payment methods, invoices, cancellation - is handled through Stripe's own portal.
Growing does not break anything
Reaching a limit stops you creating the next certificate. It never touches the ones you have: they keep working and keep renewing while you decide.
Downgrading is not destructive either
Nothing is deleted. Whatever exceeds the new limits keeps running - you just cannot add more until you are back under. The exception worth knowing: Free only allows Let's Encrypt and EC-256 keys.
Compare every feature
The complete matrix, including the limits the server actually enforces. Capabilities your plan does not include are never hidden in the product either - they show as disabled controls with an upgrade hint.
| Feature | Free | Standard | Pro | MSP | MSP Plus |
|---|---|---|---|---|---|
| Capacity | |||||
| Certificates | 1 | 150 | 1,500 | 150 per workspace | 150 per workspace |
| AgentsOne per server that needs a certificate. | 1 | 75 | 1,000 | 75 per workspace | 75 per workspace |
| Domains | 1 | 5 | 25 | 5 per workspace | 5 per workspace |
| Team membersInvite by email instead of sharing a login. | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
| Certificate authorities | |||||
| Let's EncryptSeeded on every account – nothing to configure. | Included | Included | Included | Included | Included |
| Public CAs via EAB (External Account Binding)Google Trust Services, ZeroSSL, SSL.com, Actalis. | Not included | Included | Included | Included | Included |
| PSW Group reseller | Not included | Included | Included | Included | Included |
| Self-hosted ACME serverstep-ca and anything else that speaks ACME. | Not included | Included | Included | Included | Included |
| Internal CA over REST | Not included | Included | Included | Included | Included |
| Active Directory Certificate ServicesThrough the CA connector. | Not included | Included | Included | Included | Included |
| Validation | |||||
| HTTP-01 validation | Included | Included | Included | Included | Included |
| DNS-01 validation | Included | Included | Included | Included | Included |
| Wildcard certificatesRequires DNS-01, on any plan. | Included | Included | Included | Included | Included |
| DNS providersCloudflare, Route 53, Azure, Google Cloud, Hetzner and the rest – plus ACME-DNS, a webhook and a custom script. | 217 | 217 | 217 | 217 | 217 |
| Private key types | EC-256 | EC-256/384, RSA-2048/4096 | EC-256/384, RSA-2048/4096 | EC-256/384, RSA-2048/4096 | EC-256/384, RSA-2048/4096 |
| Windows deploy targets | |||||
| Certificate store | Included | Included | Included | Included | Included |
| IISCreates and updates the site's HTTPS binding. | Not included | Included | Included | Included | Included |
| Exchange | Not included | Included | Included | Included | Included |
| ADFS | Not included | Included | Included | Included | Included |
| RDP / RDS listenerFor a standalone RDP/RDS listener, outside a full RDS deployment. | Not included | Included | Included | Included | Included |
| RDS deploymentGateway, Web Access, Connection Broker or Licensing role. | Not included | Included | Included | Included | Included |
| WinRM (HTTPS listener) | Not included | Included | Included | Included | Included |
| SQL Server | Not included | Included | Included | Included | Included |
| Skype for Business / Lync | Not included | Included | Included | Included | Included |
| Hyper-V Replica | Not included | Included | Included | Included | Included |
| Custom scriptScript content is never uploaded – it must already be on the host. | Not included | Included | Included | Included | Included |
| Exportable private keys | Not included | Included | Included | Included | Included |
| Linux deploy targets | |||||
| NGINX | Included | Included | Included | Included | Included |
| Apache | Included | Included | Included | Included | Included |
| Custom | Included | Included | Included | Included | Included |
| Custom scriptScript content is never uploaded – it must already be on the host. | Not included | Included | Included | Included | Included |
| HAProxy | Not included | Included | Included | Included | Included |
| Third-party deploy targets | |||||
| Citrix NetScaler (Nitro API)Uploads via the Nitro API; bind it to a vserver yourself. | Not included | Included | Included | Included | Included |
| Docker container | Not included | Included | Included | Included | Included |
| Fortinet FortiGate | Not included | Included | Included | Included | Included |
| Palo Alto Networks (PAN-OS) | Not included | Included | Included | Included | Included |
| Sophos Firewall | Not included | Included | Included | Included | Included |
| WatchGuard Firebox | Not included | Included | Included | Included | Included |
| Cisco Secure Firewall (FMC) | Not included | Included | Included | Included | Included |
| Kemp / Progress LoadMaster | Not included | Included | Included | Included | Included |
| F5 BIG-IP | Not included | Included | Included | Included | Included |
| VMware vCenter Server | Not included | Included | Included | Included | Included |
| Nutanix Prism | Not included | Included | Included | Included | Included |
| Proxmox VE | Not included | Included | Included | Included | Included |
| VMware Horizon Connection Server | Not included | Included | Included | Included | Included |
| Citrix StoreFront | Not included | Included | Included | Included | Included |
| Kubernetes | Not included | Included | Included | Included | Included |
| Fleet automation | |||||
| Automatic renewal | Included | Included | Included | Included | Included |
| External certificate discoveryAgents inventory certificates already installed on their host. | Included | Included | Included | Included | Included |
| Agent groups | Not included | Included | Included | Included | Included |
| Certificate policiesA standing rule on a group – new servers get their certificate as they join. | Not included | Included | Included | Included | Included |
| Idle check-in intervalA queued job always triggers a check-in within ~10 seconds, on every plan. | 3h, fixed | 1h-3h | 30 min-3h | 1h-3h | 1h-3h |
| Monitoring & audit | |||||
| Event log retention | 7 days | 30 days | 90 days | 90 days | 90 days |
| Agent log retentionLog files on the agent host itself. | 7 days, fixed | 30 days | 90 days | 30 days | 30 days |
| Job history with per-attempt errors | Included | Included | Included | Included | Included |
| Monitoring integrationsPrometheus/CheckMK metrics endpoint, plus webhook, syslog/CEF and SNMP trap push. | Not included | Not included | Included | Included | Included |
| Security & access - Security should be a standard, not a premium feature | |||||
| Mandatory multi-factor authentication | Included | Included | Included | Included | Included |
| Passkeys | Included | Included | Included | Included | Included |
| RolesDeploy targets need admin, because they run commands on your hosts. | Viewer, member, admin, owner | Viewer, member, admin, owner | Viewer, member, admin, owner | Viewer, member, admin, owner | Viewer, member, admin, owner |
| Microsoft Entra single sign-on | Included | Included | Included | Included | Included |
| Private keys never leave your servers | Included | Included | Included | Included | Included |
| Data residency | Germany | Germany | Germany | Germany | Germany |
| Managed service provider | |||||
| Isolated customer workspacesA separate organization each, not a filtered view of one tenant. | Not included | Not included | Not included | Included | Included |
| Included customer slots | Not included | Not included | Not included | 5 × Standard | 5 × Standard |
| Additional slots on demand | Not included | Not included | Not included | MSP rate for Standard or Pro slots | MSP rate for Standard or Pro slots |
| One login across every customer | Not included | Not included | Not included | Included | Included |
| Consolidated invoicing | Not included | Not included | Not included | Included | Included |
| Reassign or release a slot per customer | Not included | Not included | Not included | Included | Included |
| White labeling | |||||
| White-label brandingYour company name, logo, colours and typeface, not aethercert's. | Not included | Not included | Not included | Not included | Included |
| Custom dashboard domainCustomers sign in at dash.yourcompany.com – same product, your hostname. | Not included | Not included | Not included | Not included | Included |
| Support | |||||
| Documentation | Included | Included | Included | Included | Included |
| Bug reports & feature requests | Included | Included | Included | Included | Included |
| First-line support | Through a partner | Through a partner | Through a partner | Direct from aethercert | Direct from aethercert |
Full technical detail: Plans & limits in the documentation.
Frequently asked questions
Choosing a plan
What counts as a certificate?
One certificate is one common name plus its alternative names, however many servers it is installed on. A certificate covering example.com and www.example.com, deployed to twelve servers, counts as one - not twelve.
How do I know which plan I need?
Count the servers that need a certificate and the domains they sit under. Free is one of each, for trying it out. Standard covers 150 certificates across 75 servers and 5 domains, which is more than most single companies ever use, and it has every capability the product has. Pro exists for when those numbers are not enough. MSP is for managing other companies' infrastructure rather than your own.
What is the difference between Standard and Pro?
Scale and monitoring, not core capability. Standard already includes every certificate authority, every place a certificate can be installed, agent groups, certificate policies and exportable keys. Pro raises the ceilings to 1,500 certificates and 1,000 agents, lets agents check in as often as every 30 minutes instead of Standard's 1-hour floor (both still default to 3 hours), keeps 90 days of history instead of 30, and adds the integrations that push fleet metrics and alerts into a monitoring system you already run.
What happens when I reach a limit?
Creating the next certificate, agent or domain is refused with a message naming the limit. Nothing that already exists is affected - it keeps working and keeps renewing. Capabilities your plan does not include are shown as disabled controls with an upgrade hint rather than hidden, so you can always see what a plan would add.
Can I switch plans later?
Yes. Upgrading applies immediately - agents, domains and certificates carry over, nothing is re-created and no agent needs reinstalling. Downgrading deletes nothing either: whatever exceeds the new limits keeps working and keeps renewing, you simply cannot create more until you are back under. The one thing to plan for is Free, which allows only Let's Encrypt and EC-256 keys, so a certificate on another authority will not reissue there.
Do I need a credit card to start on Free?
No, the Free plan requires no payment details at all. It covers one certificate on one server for one domain using Let's Encrypt - enough to run the whole cycle end to end on a real machine before deciding anything. Registration itself is invite-only while we scale, so sign-up starts with a short waitlist.
Billing
Is there a monthly billing option?
No - all paid plans are billed annually. That keeps the price per certificate low and avoids monthly billing overhead on both sides. Prices exclude applicable taxes.
How do I change my payment method or get an invoice?
Through Stripe's customer portal, reachable from Settings › Organization › Billing. Payment methods, invoices, receipts and cancellation are all handled there.
What happens if a payment fails?
Stripe retries on its normal schedule and the failure is recorded in your event log. Certificates already installed keep working throughout - they are files and certificate-store entries on your own servers with no runtime dependency on aethercert.
IT service providers
Can I manage certificates for my own customers?
Yes - that is what the MSP plan is for. Each customer gets a fully separate workspace with its own data and its own access, you work across all of them from one login and one invoice, and you decide independently what to charge each customer.
How does customer licensing work?
The MSP plan includes five Standard-tier customer places. Additional Standard or Pro places are bought from the dashboard at a discounted rate. Each is its own annual subscription with its own renewal date and its own auto-renew switch - assign one to a customer, reassign it to a different one later, or let it lapse when the relationship ends.
Is every customer workspace really separate?
Yes. Each one is its own organization - separate data, separate access - not a shared tenant filtered by a customer ID. Managing ten customers means ten isolated organizations, and there is no query that spans them.
What happens to a customer when I release their licence?
The workspace drops to Free-plan limits rather than being deleted. Nothing is destroyed, certificates already installed keep working, and the data is still there if the customer comes back. The licence can then be assigned to someone else.
What if a customer already pays for their own plan?
They keep it. Their tier, renewal date and invoice stay theirs when you take over managing them, and they do not consume one of your places. If a managed customer buys their own subscription later, that takes over and the licence you had assigned is released back into your pool.
Who supports my customers?
You do - that is what they are paying you for, and a customer workspace's own support screen points its users at your contact details rather than at aethercert. As an MSP you are a direct aethercert customer, so support for you comes from us directly.
The product itself
Does aethercert ever hold my private keys?
No. Every private key is generated on the server that will serve the certificate, by the agent, and never leaves that host. What comes back to us is metadata - serial number, fingerprint, validity window. This is true on every plan, including Free.
What happens to my certificates if aethercert is unavailable?
They keep working. Installed certificates are ordinary files and certificate-store entries on your own servers with no runtime dependency on us. What pauses is scheduling, so renewals resume when the control plane is reachable again - and the default 30-day renewal window is the margin that makes a short outage a non-event.
Where is aethercert hosted?
Storage and processing stay in Germany: the application runs on Hetzner in Nuremberg and the database on Supabase in Frankfurt (eu-central-1). Cloudflare sits in front as a TLS-terminating proxy for DDoS protection - it handles edge traffic, not data storage.
Which DNS providers are supported?
217, on every plan including Free. That covers Cloudflare, Route 53, Azure, Google Cloud, DigitalOcean, Hetzner and every other common provider, and includes ACME-DNS, a generic webhook and a custom script as escape hatches for anything not on the list.
Do you support Kubernetes as a target?
Not today. Certificates can currently be installed into Windows roles (certificate store, IIS, Exchange, ADFS, RDP/RDS listener, RDS deployment, WinRM, SQL Server, Skype for Business/Lync, Hyper-V Replica), Linux services (NGINX, Apache, custom paths with a reload command), Citrix NetScaler/ADC, Docker containers, and custom scripts on either operating system - the full list is in the comparison table above.
Is there a public API?
Not yet. The dashboard and the agents talk over an internal API today, and a documented public API for external integrations is on the roadmap. On Pro and MSP there is a read-only metrics endpoint in Prometheus format, which covers monitoring but not automation. If a public API is a blocker for you, say so - that is what moves it.
Can I export my data?
Your account profile and organization memberships, yes, as JSON from account settings. Self-service export of certificates and the full event log is not built yet - ask if you need it for a specific compliance requirement.
Is there a formal SLA?
Not a tiered SLA today. aethercert is built and supported by one person, so support means a direct reply rather than a ticket queue with a response-time table. Security reports do have committed timelines - three business days to acknowledge, ten to assess.
Still unsure which plan fits?
Start on Free and judge it against your own certificates. Upgrading later keeps everything you have already set up - no agent needs reinstalling.
Free plan, no card required. aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.