See every certificate. Find the risk you did not know you owned.

Vellitas maps public-facing digital certificates and enriches them with network, geospatial, and configuration context, so security teams can discover forgotten assets, anomalies, and domain abuse, then act from a clear remediation report.

Patented digital certificate security
Scroll

Your inventory ends where attackers begin.

Security teams harden, patch, and test servers from the inside. That work is essential, but it begins with systems the organization already knows. Forgotten servers, test systems, weak cipher suites, expired certificates, and lookalike domains can remain outside the picture.

Inside-out

Harden. Patch. Test known systems.

Outside-in

Observe public exposure. Verify external defects.

Vellitas complements internal security by assessing the public attack surface the way an external observer sees it.

Certificate intelligence, built from the outside in.

Vellitas turns public certificate evidence into a focused security assessment and a practical remediation report.

  • Global discovery
  • Contextual enrichment
  • Geospatial analysis
  • Certificate health
  • Name encroachment
  • Historical change

Clear product boundaries

What is available now. What comes next.

Vellitas separates operating capabilities from planned product work so security buyers can evaluate the service on evidence—not promises.

Available now

Outside-in certificate assessment

  • Global certificate discovery from public-facing services
  • DNS, reverse DNS, network, geospatial, and configuration enrichment
  • Certificate health, self-signed certificate, and weak cipher findings
  • Unusual-location, name-encroachment, and historical-change analysis
  • Evidence-based remediation reports and outside-in verification
Product roadmap

Customer workflow and broader exposure intelligence

  • Tenant-scoped customer search and portfolio dashboards
  • Certificate Transparency and event-driven issuance monitoring
  • Attack-surface graph, vendor attribution, and expanded DNS/web posture
  • Ticketing, SIEM, webhook, and ownership integrations
  • Reviewed, versioned remediation scripts with dry-run and approval controls
Read the public roadmap

Methodology

Focused observation. Explainable confidence. Minimal impact.

Vellitas observes the evidence an internet-facing service intentionally presents to a client. The assessment is designed to be narrow, repeatable, and efficient.

01

What we observe

Certificate chain, subject and SANs, issuer, validity, fingerprints, public-key and signature characteristics, TLS versions and cipher support, chain completeness, revocation signals, DNS and reverse DNS, IP/network owner, observed location, and changes across time.

02

Standard cadence

A full baseline at onboarding; daily review of changed or newly discovered endpoints; a weekly portfolio reassessment; monthly reporting; quarterly scope confirmation; and an on-demand retest after remediation. Contracted service levels control notification timing.

03

Confidence scoring

Confirmed findings are reproduced directly. High confidence combines direct evidence with corroborating context. Moderate confidence identifies a real signal with unresolved ownership or attribution. Low-confidence candidates are held for validation rather than presented as remediation work.

04

What we do not access

No credentials, private keys, user accounts, application databases, encrypted payloads, or internal networks are accessed unless a customer separately and explicitly authorizes a defined test. Vellitas does not exploit defects, guess passwords, or perform availability testing.

Responsible scanning

One focused handshake, then back off.

Vellitas makes rate-limited connections, captures only the technical evidence required for the assessment, closes the connection, retries conservatively, and pauses when a service shows signs of stress. It does not collect page content as part of the certificate assessment.

Read data and scanning practices
BlueVellitas assessment
GreenPass
YellowCaution
RedImmediate action

A subscription built around verified closure.

Vellitas is not a one-time report. The service establishes the external baseline, develops the remediation plan, helps complete the work, verifies closure, and keeps watching for changes to the security profile.

Vellitas consultants can perform the remediation or work alongside the customer's security, IT, and technology partners.

View an illustrative report
01

Assess and report

Establish scope, preserve observed evidence, and prioritize confirmed defects.

02

Plan the remediation

Define ownership, corrective work, validation steps, sequencing, and change controls.

03

Fix with the right operating model

Vellitas can execute the plan or collaborate with the client's technology group.

04

Generate safe automation

Roadmap scripts are reviewed, versioned, customer-approved, and dry-run before execution.

05

Verify and continue monitoring

Reobserve the endpoint, document closure, monitor change, and notify the customer with suggested action.

A patented foundation for certificate intelligence.

Vellitas technology links information inside a digital certificate with external network, geospatial, configuration, and historical context. The patent family covers methods for identifying vulnerable certificates across the public internet.

Systems and Methods for Digital Certificate Security

Leadership

Built by technology operators and certificate-security inventors.

Vellitas brings together distributed leadership in security invention, enterprise operations, product architecture, AI, and customer delivery.

CEO · Cofounder

Spencer Shearer

Spencer is a global operations and technology executive with experience building scalable teams and translating complex systems into durable customer and business outcomes. He is an inventor on Vellitas's digital certificate security patents.

LinkedIn profile

COO · Cofounder

Seth Shearer

Seth is a global customer experience and technology leader known for guiding cross-functional teams across sales engineering, product, engineering, and customer operations. He is a co-inventor on Vellitas's certificate security patents.

LinkedIn profile

Chief Product & Technology Officer

Fraser Mackenzie

Fraser is an enterprise technology architect and AI product leader with deep experience in metadata, information governance, and large-scale digital transformation. He has designed platforms and led complex content and data programs for Adobe and Canadian government organizations.

LinkedIn profile

Your unknown certificate risk is already public.

Tell us about the domains or certificate concerns you want to understand. We will respond with a practical next step for an outside-in assessment.

We use these details only to respond to your request. See our privacy notice.