Private Key Policy
SSLNexus is designed so certificate private keys remain under the control of the organisation operating the workload.
Customer-controlled key custody
SSLNexus does not require customer certificate private keys to be uploaded to, stored by, or operated from an SSLNexus-hosted SaaS service. Private keys remain within customer-controlled infrastructure, including customer-controlled servers, HSMs, key vaults and cloud accounts.
Vendor Portal
When a vendor creates a certificate request through the Vendor Portal, the browser generates the private key locally. Only the certificate signing request (CSR) is submitted to SSLNexus. The private key is not returned by the Client Server and is not stored by SSLNexus.
Automation and deployment
Certificate lifecycle automation may coordinate issuance, deployment and verification while keeping key custody inside the infrastructure boundary that uses the key. Where an integration uses a customer-controlled vault or HSM, access remains governed by that customer's infrastructure and credentials.
Support and telemetry
Do not send private keys through support tickets, email, chat, telemetry or ordinary diagnostic uploads. SSLNexus support should not request a production private key as part of normal troubleshooting.
Backups
Backups containing key material must remain under customer control and be protected to the same or a stronger standard than the live infrastructure. A storage or service operator should not gain independent ability to decrypt customer private keys.
Why this matters
This policy keeps the authority and custody boundary clear. Certificate automation can be centralised without creating an additional third-party private-key custodian between the organisation, its infrastructure providers and the systems that actually use the key.
For operational guidance, see Security guidance.

