Key capabilities
KryptoVault Discovery provides:- Network-based certificate discovery
- Domain-based certificate discovery
- Cloudflare-integrated discovery
- Configurable discovery scopes
- Manual and scheduled execution
- Automatic certificate import
- Certificate-store integration
- Job execution history
- Discovery result analytics
- Blackout-window controls
- Blacklist enforcement
- Retry and timeout management
- Certificate trust and algorithm analysis
Discovery methods
Network Discovery
Network Discovery identifies certificates exposed across configured network locations. The discovery scope can include:- Static IPv4 addresses
- CIDR ranges
- IP address ranges
- Individual ports
- Port ranges
- Web and application servers
- Load balancers
- API gateways
- Network appliances
- Internal services
- Certificate-enabled endpoints
Domain Discovery
Domain Discovery identifies certificates associated with configured domain names. It is designed for certificate visibility across:- Public websites
- Customer-facing applications
- APIs
- Internet-accessible services
- Internal domain-based services
- Multi-domain environments
Cloudflare Discovery
Cloudflare Discovery integrates with Cloudflare through an API endpoint and access token to retrieve certificate and domain-related information. This capability is useful for organizations that use Cloudflare to manage:- Public domains
- DNS zones
- Edge services
- TLS termination
- Cloud-hosted applications
- Internet-facing infrastructure
Discovery processing model
A discovery job defines the environment to be scanned and the operational policy applied during execution. The processing model includes:- Scope definition The organization defines the network, domain, or cloud source to be assessed.
- Port evaluation KryptoVault connects to configured service ports or port ranges.
- Certificate identification Certificates exposed by reachable endpoints are collected and evaluated.
- Result processing Successful and failed discovery results are recorded.
- Certificate onboarding Identified certificates can be added to the managed inventory.
- Lifecycle integration Imported certificates become available for validation, expiry monitoring, risk assessment, tagging, and store association.
Automatic certificate import
KryptoVault can automatically import certificates identified during discovery. When automatic import is enabled, the discovered certificate is associated with a selected certificate store and becomes part of the centralized certificate inventory. Imported certificates can then be used for:- Certificate-chain validation
- Expiration monitoring
- Issuer identification
- Trust-level classification
- Cryptographic algorithm analysis
- Lifecycle tracking
- Risk evaluation
- Certificate-store association
Certificate-store integration
Discovery is integrated with KryptoVault Certificate Stores. A linked certificate store acts as the managed destination for certificates imported from discovery operations. This relationship allows certificates identified outside formal enrollment workflows to be brought into the same governance model as enrolled or generated certificates. A discovered certificate may subsequently be:- Validated
- Tagged
- Assigned to a store
- Monitored for expiration
- Reviewed for security risks
- Associated with lifecycle events
- Prepared for renewal or replacement
Scheduling and automation
KryptoVault supports recurring discovery through configurable schedules. Scheduled discovery helps organizations:- Continuously refresh certificate inventory
- Detect newly deployed certificates
- Identify changes in network or domain environments
- Monitor certificate replacement
- Detect expiring or misconfigured certificates
- Reduce dependence on manual scans
Discovery execution lifecycle
Discovery jobs move through controlled operational states.Created
The job has been configured and is available for execution.Scheduled
The job has been queued for a configured execution time.In Progress
The discovery process is actively scanning the defined scope.Completed
The execution has finished and its results are available for review. KryptoVault preserves execution status and run history to support operational monitoring and traceability.Run history and execution intelligence
Each discovery execution produces a historical record. Run information can include:- Discovery method
- Execution type
- Start and end time
- Duration
- Execution status
- Total scan scope
- Successful results
- Failed results
- Discovered certificate count
- Error information
- State-transition history
Discovery analytics
KryptoVault provides analytics that summarize discovery operations and discovered certificate characteristics. The product can present information such as:- Total configured discovery jobs
- Jobs by discovery method
- Completed jobs
- Scheduled jobs
- Jobs in progress
- Last scan time
- Average runtime
- Successful and failed runs
- Newly discovered certificates
- Total discovered certificates
- Signature algorithm distribution
- Certificate trust distribution
Signature algorithm visibility
KryptoVault classifies discovered certificates according to their signature algorithms. This helps organizations:- Identify legacy cryptographic algorithms
- Assess current signing practices
- Detect weak or non-standard signatures
- Plan cryptographic-policy improvements
- Prepare for algorithm migration
Certificate trust classification
Discovered certificates can be classified by trust level. Supported classifications may include:- Domain Validation
- Organization Validation
- Extended Validation
- Unknown
Blackout windows
KryptoVault supports blackout windows that prevent discovery jobs from running during restricted periods. Blackout windows are useful when scanning must be avoided during:- Business-critical operating hours
- Planned maintenance
- Peak transaction periods
- Infrastructure upgrades
- Sensitive processing windows
Blacklist governance
KryptoVault supports central blacklist policies that exclude defined infrastructure or certificate sources from discovery. Blacklist controls can include:- Domains
- IP addresses
- CIDR ranges
- Ports
- Certificate issuers
- Exclude restricted environments
- Prevent scanning of sensitive infrastructure
- Avoid unsupported endpoints
- Enforce organizational boundaries
- Apply legal or compliance restrictions
- Reduce unnecessary scan traffic
Timeout and retry controls
Discovery jobs support configurable timeout and retry behaviour. Timeout controls prevent a job from waiting indefinitely for an unresponsive endpoint. Retry controls allow KryptoVault to repeat failed connection attempts before classifying an endpoint as unsuccessful. Together, these controls improve discovery reliability across unstable, geographically distributed, or intermittently available environments.Partial-result handling
KryptoVault can support partial discovery results. When partial results are allowed, certificates successfully identified within a discovery scope can be retained even when other targets fail. When partial results are disabled, the platform can prevent incomplete discovery output from being committed. This allows organizations to choose between:- Maximum inventory coverage
- Strict result completeness
Discovery modes and policy control
Discovery methods can be centrally enabled or disabled. This allows administrators to control which discovery technologies are available within the organization. For example:- Network Discovery may be enabled for internal infrastructure
- Domain Discovery may be enabled for public services
- Cloudflare Discovery may be enabled only when an approved integration exists
Security and governance
Discovery operations are governed through role-based access control. Permissions can be applied to capabilities such as:- Creating discovery jobs
- Running discovery jobs
- Modifying job configuration
- Deleting jobs
- Viewing run history
- Managing discovery settings
- Enabling automatic import
- Overriding blackout windows
- Overriding blacklist restrictions
- Accessing discovered certificate inventory
Audit and traceability
KryptoVault records discovery-related activity to provide accountability and operational traceability. Audit information can include:- Job creator
- Creation date and time
- Last modifier
- Modification date and time
- Deletion information
- Execution start and end
- State changes
- Execution outcome
- Error information
Enterprise use cases
KryptoVault Discovery supports use cases such as:Unmanaged certificate identification
Locate certificates deployed outside approved PKI or issuance processes.Certificate outage prevention
Identify certificates approaching expiration before they disrupt services.Certificate inventory reconciliation
Compare expected certificate assets with certificates actually deployed across infrastructure.Cloud certificate visibility
Extend certificate governance into Cloudflare-managed environments.Cryptographic posture assessment
Identify certificate algorithms, trust levels, and weak cryptographic configurations.Merger and acquisition discovery
Assess certificate assets inherited from acquired or integrated environments.Continuous compliance monitoring
Run recurring scans to detect certificates that violate organizational certificate policies.Certificate migration planning
Identify certificates that must be renewed, replaced, consolidated, or migrated to stronger algorithms.Product value
KryptoVault Discovery helps organisations:- Eliminate certificate blind spots
- Build a complete certificate inventory
- Reduce certificate-related outages
- Detect unmanaged infrastructure
- Automate recurring certificate identification
- Improve cryptographic governance
- Centralize multi-environment certificate visibility
- Support compliance and audit requirements
- Connect discovery with certificate lifecycle management
- Prepare for cryptographic and post-quantum migration