Skip to content

Editions

Which Edition is the right for you?

Let us figure it out together with the license advisor on this page or check the edition matrix below.

License advisor

Set your volume and targets. We’ll highlight the matching edition.

Deployment targets

Linux (SSH)

ADC

Omnissa

Firewall / VPN

Google Cloud / AWS

Azure

Entra

Custom

Features

Web UI / RBAC (browser + permissions)

Tenants (teams / MSP)

Community Edition

Free

Labs and first tests

ACME

  • Certificates2
  • Deployments2

Download

Standard

Small environments, public ACME only

ACME

  • Certificates25
  • Deployments50
  • Deploys per certificate2
  • Deployment targets9
  • Credential stores—
  • Alert targets1
  • Tenants—

Professional

Private & Enterprise CA

ACMEPrivate CAEnterprise CA

  • Certificates100
  • Deployments100
  • Deploys per certificate2
  • Deployment targets23
  • Credential stores2
  • Alert targets4
  • Tenants—

Enterprise

Production with many targets

ACMEPrivate CAEnterprise CA

  • Certificates100
  • Deployments200
  • Deploys per certificate∞
  • Deployment targets31
  • Credential stores5
  • Alert targets5
  • Tenants—

Ultimate

Multi-tenant and large estates

ACMEPrivate CAEnterprise CA

  • Certificates200
  • Deployments400
  • Deploys per certificate∞
  • Deployment targets31
  • Credential stores5
  • Alert targets5
  • Tenants50

Edition comparison

In the comparison table below you see a clear overview of all limits and functions of each edition we offer for TLSPilot:

included not included unlimited

Community Standard Professional Enterprise Ultimate
Caps
Certificates 225100100200
Deployments 250100200400
Deploys/certificate 122∞∞
Tenants ----50
Access & Automation
Management API & PowerShell
AI Assisted Help -
WebUI & RBAC ---
Tenants ----
Issuers
ACME
Private CA --
Enterprise CA --
Alert channels
Mail -
Webhook --
Microsoft Teams --
Slack --
Syslog ---
External credential stores
HashiCorp Vault KV --
Azure Key Vault Secrets --
CyberArk ---
Delinea ---
BeyondTrust ---
Deployment Targets
Windows (all editions)
Certificate store only
IIS
File Path (WinRM)
UNC
Windows (from Standard)
RDS -
Exchange -
AD FS -
SQL Server -
NPS (RADIUS) -
Linux/SSH (from Professional)
Nginx --
Apache --
HAProxy --
Tomcat --
PostgreSQL --
MySQL/MariaDB --
File Path (SSH) --
Application Delivery / ADC (from Professional)
NetScaler --
F5 BIG-IP --
Omnissa (from Professional)
Omnissa UAG --
Firewall / VPN (from Professional)
Palo Alto (PAN-OS / SCM) --
GCP / AWS (from Professional)
GCP Certificate Manager --
AWS ACM --
Azure (from Enterprise)
Azure Key Vault ---
Azure App Service ---
Azure Application Gateway ---
Azure Front Door ---
Azure API Management ---
Entra (from Enterprise)
Entra Application Proxy App ---
Entra App Certificate ---
Custom (from Enterprise)
Custom Deployment ---
Price (year, net, ex VAT) free CHF 490
EUR/USD 590
CHF 1'490
EUR/USD 1'790
CHF 3'490
EUR/USD 4'190
CHF 6'990
EUR/USD 8'390
Add-ons
Add-on: +50 Certificates/+100 Deploys ---CHF 790
EUR/USD 990
CHF 790
EUR/USD 990
Add-on: +10 tenants ----CHF 790
EUR/USD 990

Have you found the right edition?

If you have found the right edition, you can order a license directly on this website by credit card or invoice. Visit our shop. If you need more information or advice, please contact us.

To the shop Contact

What counts as a certificate

Every configured certificate counts - internal or public. The cap is the stock on the host.

What counts as a deploy

Every configured deploy target counts. One certificate can serve several services - each deployment target counts as one.

WebUI & RBAC

So TLSPilot can be managed from wherever you need it, there is also a WebUI reachable in the browser — with authentication via an identity provider (AD or Entra ID). It does not only look like the Management Tool: it behaves the same way:

Role-based access control lets you define precisely and granularly which person or group (including nested groups) gets which access rights. On each certificate or credential, inheritance can also be broken and replaced with explicit permissions:

TLSPilot WebUI in the browser: dashboard like the Management Tool
RBAC: roles and permissions in the manager
RBAC: break inheritance and set explicit permissions

Private CA / Enterprise CA

Public or internal certificate? No problem with TLSPilot: You choose whether the certificate is issued via ACME from an official provider, the internal Enterprise CA or the TLSPilot CA. ACME family (public CAs, e.g. Let's Encrypt and ZeroSSL) in every edition. Private CA and Enterprise CA from Professional.

New Certificate wizard Settings: Enterprise CA enrollment, template, renewal window
Private CA: Running, renew/export, CDP/OCSP

Tenants

Tenants let you group certificates and credentials. That keeps things tidy when you split by team or customer — and lets you limit issuers to certain tenants or apply permissions/roles only to specific tenants:

Deploy catalogue

The certificate is there, but it still has to be bound to the surrounding systems? No problem with TLSPilot: Without agents the certificate is distributed to the target system and bound to the service right away.

Windows

  • Certificate store
  • IIS
  • File Path (WinRM)
  • UNC
  • RDS
  • Exchange
  • AD FS
  • SQL Server
  • NPS (RADIUS)

Linux (SSH)

  • Nginx
  • Apache
  • HAProxy
  • Tomcat
  • PostgreSQL
  • MySQL/MariaDB
  • File Path (SSH)

Application Delivery (ADC)

  • NetScaler
  • F5 BIG-IP

Omnissa

  • UAG (Omnissa)

Firewall / VPN

  • Palo Alto
  • More

Azure

  • Azure Key Vault
  • Azure App Service
  • Azure Front Door
  • Azure Application Gateway
  • Azure API Management
  • More

Entra

  • Entra Application Proxy App
  • Entra App Certificate

Google Cloud

  • Certificate Manager

Amazon Web Services

  • Certificate Manager

Custom

  • Custom script

Management API & PowerShell

Want even more automation? No problem: besides the Management Tool and WebUI, TLSPilot also offers a full API and a PowerShell module so you can call every function directly:

ACME

Anything that follows the ACMEv2 standard can be entered in TLSPilot as a public cert source. From free public cert providers such as Let's Encrypt, ZeroSSL, etc., through to commercial CAs that support ACMEv2. Integration in TLSPilot is modular via JSON definition files that you can also write yourself. Many providers are already included — and only need configuration.

Domain validation uses DNS-01, HTTP-01, or TLS-ALPN-01. Many DNS providers are already included — plus manual DNS configuration and any that work per RFC2136. HTTP-01 can even be terminated on the management host itself with its own listener:

AI Assisted Help

Get 24/7 AI-assisted email support directly from the app. Open a support ticket easily and receive step-by-step solutions and tips in your inbox within minutes. This is not the help quality you know from other vendors: our AI Support Specialist Thomas L. Stevens knows the product in depth and usually delivers precise answers. If he cannot help, he escalates the case automatically.

Enterprise CA

If an Enterprise CA (AD Certificate Services) is already available in the domain, TLSPilot detects it automatically. All templates the management service can access that allow server authentication certificates can then be used directly in TLSPilot — issued and deployed to your targets:

Private CA

TLSPilot Private CA is ideal for certificates that do not need redundancy for CRL checking — for example Entra app registration authentication. TLSPilot Private CA offers various key algorithms (including ECC) and also allows CRL checking via OCSP: