Private keys stay within customer-controlled infrastructure.
Certificate automation should not require transferring private-key custody to the software vendor. SSLNexus is designed around customer-controlled key boundaries.
Private keys are the identity material behind TLS. For many organisations, especially regulated, education and enterprise environments, moving those keys into a vendor-operated SaaS service creates an architectural and assurance burden that is avoidable.
Private keys stay within customer-controlled infrastructure.
Vendor Portal CSR generation happens locally in the browser.
Customer-owned vaults and secret stores can remain part of the lifecycle.
SSLNexus is installed into customer infrastructure and is designed to keep certificate operations, target access and private-key custody under customer control. The platform coordinates lifecycle work without requiring the estate to be rebuilt around a vendor-hosted key store.
No. The product policy explicitly prohibits SSLNexus-operated SaaS custody of customer private keys.
Yes. A customer-controlled vault or secret destination can be part of the customer infrastructure boundary.
The browser generates the key pair locally and submits the CSR. The private key is not returned from the Client Server.