Certificate management for MSPs

Build a certificate service you can sell

aethercert is multi-tenant: a separate workspace for every customer you look after, managed from one login. You buy customer licences at a wholesale rate and charge whatever the service is worth - we never invoice your customer, and their support screen carries your name, not ours.

aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.

Your organization

one login, one invoice, your pricing

Customer A

Standard workspace – included place

Customer B

Pro workspace – licence you bought

Customer C

pays for their own plan

Each customer is a separate organization - its own servers, domains and certificates, visible only to you and to them.

The business model

A managed service, not another internal tool

Certificate management is the rare service line where the delivery cost falls to almost nothing after onboarding, because the renewals genuinely run themselves. That gap is the margin.

You buy

A licence per customer, at a wholesale rate

The MSP plan includes five Standard-tier customer places. Beyond that you buy Standard or Pro places from your dashboard as you sign customers - each its own annual subscription, assignable, reassignable, and cancellable on its own.

You deliver

A workspace per customer, running in an afternoon

Create the workspace, install the agent on their servers with one command each, and the certificates already installed on those machines appear with their expiry dates. From then on renewals, installation and service reloads happen without your team.

You charge

Whatever the service is worth to them

You hold the licence, so your price is independent of ours. aethercert never contacts your customer, never invoices them, and their support screen shows your company - not ours.

Who pays whom, and who owns what

The whole commercial arrangement, since this is usually the part that decides whether a platform can carry a service line at all.

What you pay us
€2,190 a year for the MSP plan, five Standard-tier customer places included, plus any further places you buy at a discounted rate.
What you charge them
Entirely your decision. Per server, per certificate, folded into an existing package - we never see it.
Who invoices the customer
You do. One invoice comes to you from us, covering your plan and every licence you hold.
Who supports the customer
You do, and the product says so: their support screen carries your company name and contact details.
Who owns the relationship
You. aethercert has no commercial relationship with your customer at all.
What happens if they churn
Release the licence and give it to the next customer. Their workspace drops to Free limits rather than being deleted.
One console

Your whole book of business in one list

Which tier each customer runs on, when their licence renews, and whether it renews automatically - instead of a folder of contracts and a reminder in someone's calendar.

How customer workspaces work
MSP › Customers - tier, renewal date and auto-renew, per customer.
Multi-tenant certificate management

Built for a book of customers, not one company

The parts that decide whether a platform survives contact with twenty accounts, three engineers and a customer who wants to see their own data.

Multi-tenant in the strict sense

Every customer is a separate organization - own domains, servers, certificates, authorities, members, audit log. Not one tenant filtered by a customer ID. There is no query that spans two of them, so there is nothing for one customer to see about another.

Staff scoped to their own accounts

Assign each engineer the customers they actually look after, at a role chosen per customer. Admin at one, viewer at another, regardless of their role in your own organization - and no separate credentials per customer to keep straight.

Take over a customer who already has an account

A management invitation is a single-use link their owner accepts, choosing whether you get everything operational or full control. Neither side can create the relationship alone, and either side can end it without the other's agreement.

Sub-contract or hand over one account

Share an individual customer workspace with another organization at viewer, member or admin. Owner is never available as a shared role, so billing, the member list and deletion stay with whoever manages that customer.

Customers who pay for themselves

A customer with their own Standard or Pro subscription keeps it when you take over managing them - their tier, their renewal date, their invoice - and does not consume one of your places.

Onboard before they ever sign in

The workspace is live the moment you create it. Add domains, enroll agents and issue certificates before the customer has an account, or without them ever having one.

What you are selling them

The service, from the customer's side

Useful when you are writing the datasheet: this is what changes at a customer once the agents are in.

Certificates stop expiring

Every certificate you issue for them renews on its own, roughly a month before it lapses, and reinstalls itself into the service that serves it. A failed attempt retries automatically before anyone is paged.

An inventory they never had

Each agent reports the certificates already installed on its server - including the ones a predecessor issued and nobody has documented since. That first list is usually the easiest deliverable you will ever bill for.

Windows and Linux, where it actually serves

IIS bindings, Exchange, ADFS, Remote Desktop and RDS, WinRM, SQL Server, Hyper-V Replica; NGINX, Apache or any path with a reload command; Citrix NetScaler and Docker containers.

Nothing opened in their firewall

The agent dials out and accepts no connection. No inbound rule, no VPN, no public address - which is usually what turns a security review into a formality.

Their keys stay on their servers

Private keys are generated on the machine that serves them and never transmitted. You hold no key material for your customers, and neither do we.

A record for the audit

Every issuance, renewal, installation and administrative change is appended to a log that cannot be edited or deleted, kept for 30 or 90 days depending on their tier.

And customers who arrive looking for a provider

Companies that sign up for aethercert on their own and have no provider are pointed at a partner list for support. Listing your organization there is one switch in your settings, plus a short description of what you do - it is off until an owner turns it on, and it shows the company contact details on your account.

It is an in-product directory rather than a public marketplace, and how much it is worth depends on how many unmanaged customers are on the platform at the time. It costs nothing to be in it.

Questions providers ask before committing

Running it as a service

Can I resell aethercert to my own customers?

Yes - that is what the MSP plan is built for. You buy customer licences at a discounted rate, assign them to the customer workspaces you create, and charge your customers whatever you decide. aethercert has no commercial relationship with them: you invoice them, you set the price, and you own the contract.

Is aethercert multi-tenant?

Yes, and in the strict sense. Each customer is a separate organization with its own domains, servers, certificates, authorities, members and audit log - not one shared tenant filtered by a customer ID. There is no query that spans two customers, so there is nothing for one of them to see about another. You switch between them from a single login.

Who provides support to my customers?

You do, and the product is built to say so: a customer workspace's own support screen shows your company name and your contact details rather than ours. As an MSP you are a direct aethercert customer, so your own support comes from us directly.

Can I white-label the dashboard with my own branding?

Not today. The dashboard your customers see - if you give them a login at all - carries aethercert's branding. What is yours is the commercial relationship, the pricing and the support contact shown in their workspace. Many providers run it without giving the customer a login at all, which makes the question moot; if white-labelling would decide it for you, tell us, because that is what moves it up the list.

How do I price it for my customers?

However you want. You hold the licence, so what you charge is independent of what you pay - per server, per certificate, folded into an existing managed-service package, or as a flat line item. aethercert never sees your pricing and never contacts your customer about it.

How many customers can I manage?

There is no cap on customer workspaces. Five Standard-tier places are included with the MSP plan, and you buy additional Standard or Pro places from the dashboard as you sign customers. Each is its own annual subscription with its own renewal date, so capacity follows your book rather than a contract negotiation.

Onboarding and day-to-day

How long does it take to onboard a customer?

Creating the workspace is a form. After that the work is installing the agent on the customer's servers, which is one elevated command per server, and a multi-provision token lets the same command run on every one of them. Their existing certificates show up with expiry dates as soon as the agents check in, which usually makes the first review the thing you can bill for.

Can I take over a customer who already uses aethercert?

Yes, through a management invitation. You send a single-use link, an owner of that organization accepts it and chooses how much the arrangement covers - everything operational, or full control. Neither side can create the relationship alone, and either side can end it later without the other's agreement. Their existing subscription stays theirs and does not consume one of your places.

Can my staff be restricted to their own accounts?

Yes. By default everyone in your organization works in every customer workspace, but each person can instead be assigned specific customers, at a role chosen per customer - admin at one, viewer at another, regardless of their role in your own organization.

Does my customer get their own login?

Only if you want them to. Some providers operate the workspace entirely and the customer never signs in. Others invite the customer as a viewer so they can see their own certificate status without changing anything, or as an admin if they should configure things themselves. Both models are supported by the same role system.

What happens when a customer leaves?

Release their licence and reassign it to someone else. The workspace is not deleted - it drops to Free-plan limits, the certificates already installed on their servers keep working, and their data is still there if they come back. Detaching the workspace ends the relationship itself and hands the workspace back to them.

Do I need certificate expertise to sell this?

Less than you would expect. Let's Encrypt is set up on every workspace and needs no configuration, and the deploy targets are presets - IIS, Exchange, Remote Desktop, NGINX, Apache, a load balancer - rather than something to script per customer. The part that needs your expertise is knowing which of a customer's systems serve TLS at all, which is knowledge you already have about them.

The platform underneath

Which systems can it manage certificates on?

Windows Server and Linux. On Windows it installs into the certificate store and, depending on the target, updates the IIS binding, the Exchange services, ADFS, the Remote Desktop or RDS deployment configuration, the WinRM HTTPS listener, SQL Server, Skype for Business or Hyper-V Replica. On Linux it writes the files and reloads NGINX, Apache or anything else that reads a certificate from disk. It also pushes to Citrix NetScaler over its management API and into running Docker containers.

Does it need inbound access into a customer's network?

No, which is usually the question that decides whether a customer will agree to it. The agent makes outbound HTTPS connections and accepts none - no inbound firewall rule, no VPN, no public IP address, nothing listening. It works unchanged behind NAT.

Where do my customers' private keys live?

On their own servers. Each key is generated by the agent on the machine that will serve the certificate, at every issuance and every renewal, and is never transmitted. aethercert stores metadata only - serial number, fingerprint, validity. Neither you nor we hold a customer's key material, which is a considerably easier conversation than an escrow model.

Can it show me certificates a customer already has?

Yes, and it is often the fastest way to prove the service's value. Each agent inventories the certificates already installed on the server it runs on - whoever put them there, whenever - and reports them with their expiry dates. It reads only that machine and never opens a private key. It cannot renew a certificate it did not issue, but taking one over means creating a certificate for the same names.

Can I plug it into my RMM or monitoring stack?

Into monitoring, yes. Every workspace on Pro exposes fleet metrics in Prometheus format for CheckMK, Grafana or anything that scrapes it, and pushes alert-worthy events to a webhook, a SIEM over syslog/CEF, or an SNMP trap receiver. There is no public API for provisioning yet, so creating workspaces and certificates is done in the dashboard.

Where is it hosted, and does that matter for my customers?

Germany - the application on Hetzner in Nuremberg, the database on Supabase in Frankfurt, with Cloudflare in front as a TLS-terminating proxy that handles traffic rather than storage. For customers who ask where their data goes, storage and processing stay in the country. Their keys and certificates never leave their own machines regardless.

More in the customer-workspace documentation and on the pricing page. Something not answered here decides it for you? Ask - it is one person you will be talking to.

Start with one customer

Subscribe to MSP, create a workspace, and put the agent on one customer's servers this week. Five Standard-tier places are included, so the second and third customers cost you nothing extra.

aethercert is invite-only while it scales - leave your email and you'll hear back from us directly.