Product
Truvald
PKI Management Platform
Built for the real world of Windows Server ADCS — multi-CA, multi-forest, air-gapped environments and the politics of "who touched the Root CA." Truvald replaces a week of manual PKI health checks with a dashboard you can trust.
Know before it breaks.
Truvald polls every CA in your hierarchy continuously, surfacing health issues before they become 2am incidents. CRL expiry, certificate expiry, service status, key protection, backup recency — all visible at a glance.
- CRL validity monitoring with configurable warning thresholds
- CA certificate expiry tracking with multi-level alerts
- ADCS service state and event log health
- Backup status and last-known-good timestamps
- Full multi-CA, multi-forest hierarchy support
Find the problems before the auditor does.
Truvald runs automated security assessments across your entire ADCS configuration — CA permissions, template vulnerabilities, key protection, and audit settings — against established PKI security baselines derived from Microsoft guidance and real-world incident patterns.
- ESC1–ESC13 template vulnerability detection
- CA ACL and permission analysis
- Private key protection validation (HSM, software)
- Audit logging completeness checks
- Exportable findings with remediation guidance
Documentation that's actually current.
Most PKI documentation is a Word document someone wrote in 2019 that's been 40% wrong ever since. Truvald generates disaster recovery guides from live environment data — the day before you need them, not six months after.
- Live-collected configuration snapshots at generation time
- CA, CEWS, CEPS, and OCSP recovery guides
- Includes certificate chain, gMSA, IIS, and AD configuration details
- PDF export with bilingual (EN/FR) support
- Suitable for audit evidence and DR runbooks
For the CAs nobody can reach.
Air-gapped Root CAs. HSM-protected offline CAs. Servers behind strict network segmentation. The Truvald Offline Collector is a standalone executable that runs on any Windows Server — including Server Core — collects environment data, and packages it for import into Truvald running elsewhere.
- Zero network requirement — runs fully offline
- Single EXE, no installer, runs on Server Core
- Encrypted data package for secure transport
- Schedulable via batch script for recurring collection
| OS | Windows 10 / Windows Server 2016 or later |
| .NET Runtime | .NET 8 (included in installer) |
| RAM | 4 GB minimum, 8 GB recommended |
| Disk | 500 MB for app + database growth |
| Network | LDAP (389/636) + RPC to CA servers |
| Rights | Domain user; CA Audit / Read recommended |
| OS | Windows Server 2012 R2 or later |
| .NET Runtime | Bundled — no pre-install required |
| RAM | 512 MB available |
| Disk | 50 MB for output package |
| Network | None required (air-gap safe) |
| Rights | Local Administrator or CA Manage CA |