Stop managing certificates and secrets. Start automating them.
Zaita is the world-leading platform for X.509 certificate lifecycle management, private PKI, and secrets management. Discover every certificate, run your own CA hierarchy, automatically renew and deploy to your servers, and store and deliver secrets to every workload — all with data sovereignty in your chosen region.
30 days free · Full enterprise limits · No credit card required
The Platform
Three deeply integrated products. One platform.
Zaita covers the full security automation lifecycle — from discovering certificates you didn't know existed, to rotating every secret across every workload, with a private CA hierarchy protecting it all.
Certificate Lifecycle Management
Discover every certificate across your estate, automate renewal before expiry, and deploy directly to Windows and Linux servers. Built for the 47-day mandate and post-quantum crypto agility.
- Certificate discovery & inventory
- Automated renewal & deployment
- Policy & compliance engine
- Post-quantum readiness
Private PKI
Build a complete root and intermediate CA hierarchy — fully managed, with private keys protected in a dedicated, isolated signing system that never touches the internet.
- Root & intermediate CA hierarchy
- Isolated signing system architecture
- Private ACME server
- SSO, RBAC & machine accounts
Secrets Management
Store, update, and deliver secrets to every workload automatically. Secret Lockers keep credentials, API keys, and tokens organised, versioned, and delivered without human involvement.
- Secret Lockers — named, versioned vaults
- API-driven rotation & delivery
- Version history & audit trail
- Full audit trail & SIEM integration
The Mandate
Certificate lifespans are shrinking — fast
Global standards bodies are mandating shorter and shorter certificate lifespans. Manual renewal processes that barely hold together today will completely collapse within years — and the timeline is accelerating.
Source: CA/Browser Forum Ballot SC-081 — Short-Lived Certificates
The next cryptographic crisis is already underway
Quantum computers will break RSA and ECC — the algorithms protecting every certificate in your estate. Adversaries are harvesting encrypted traffic now to decrypt it later. Zaita's centralised CLM gives you crypto agility: update the algorithm policy once and Zaita re-issues and redeploys your entire estate in hours.
Algorithm migration across thousands of certificates takes months of manual coordination — with high risk of incomplete migration leaving vulnerable certs in production.
Update the algorithm policy once. Zaita re-issues and redeploys every affected certificate automatically — across every server, every environment, in hours.
Hardcoded secrets and manual rotation are your next breach
Credentials committed to repos, API keys shared via email, rotation deferred until after the audit — secrets sprawl is the rule, not the exception. Zaita's Secret Lockers give every application, pipeline, and workload exactly the secrets it needs, encrypted end-to-end, updated and delivered automatically, with every access recorded.
Secrets live in config files, environment variables, and wikis. Rotation means finding every system that uses a credential, updating it manually, and hoping nothing breaks at 2am. One leaked key can cascade across your entire estate.
Every application pulls its Locker via Bridge, Courier, or Workload API — encrypted end-to-end, with zero plaintext on the wire. Rotate a secret once; Zaita delivers the new value everywhere, automatically, with a full audit trail.
Hosting
Deployed wherever your compliance requirements demand
Fully managed shared hosting or your own dedicated infrastructure — across globally distributed regions to meet data residency requirements anywhere in the world.
Multi-Tenant SaaS
Fully managed cloud hosting with strong isolation between customers. Available across multiple regions with offline backups for peace of mind.
Single-Tenant
Your own dedicated infrastructure — complete isolation for regulated industries and the strictest compliance requirements. EU specialist providers available.
HSM Integration
Already have a Hardware Security Module? Connect it to Zaita for the ultimate in key protection and compliance assurance.
Pricing
Start free. Grow at your pace.
There are no hidden fees or surprise overage charges. Our pricing is transparent and predictable, so you can focus on building your PKI and managing your secrets — not on managing your bill.
Everything you need to build and run a personal private PKI for the price of a coffee.
- One user account
- 1 Root CA + 2 Intermediate CA certificates
- 5 leaf certificates per month
- CT log scanning for 1 domain (24-hr monitoring)
- Web portal + 1 private ACME server
- Courier agent (direct SaaS connection, cron-scheduled)
- 10 secret lockers
No credit card required · start trial today
More certificates and more domains for active users. Perfect for home-lab use.
- One user account
- 20 leaf certificates per month
- CT log scanning for up to 2 domains
- 2 private ACME servers
- Courier agent (direct SaaS connection)
- Email support
- 20 secret lockers
Monthly billing · cancel anytime
For small teams ready to automate. SSO, Bridges, and target system deployment.
- Single Sign-On (SAML) with one identity provider (IdP) - Maximum 5 users
- 1 Root CA + 4 Intermediate CA certificates
- 50 leaf certificates per month
- CT log scanning for up to 2 domains + HTTPS endpoint scanning
- Web Portal + 2 private ACME servers
- Courier agent (direct SaaS connection)
- Credential-less machine auth (SPIFFE, Azure, AWS IAM OIDC)
- Email support
- 50 secret lockers
Monthly billing · cancel anytime
For growing teams that need higher certificate volumes, more automation, and a formal uptime guarantee with recovery SLAs.
- Single Sign-On (SAML) with one identity provider (IdP) - Maximum 20 users
- 100 leaf certificates per month
- 1 Bridge Deployment — on-prem 'push' deployment
- Automated deployment to Windows (WinRM) and Linux (SSH) servers
- Service accounts for DevOps / CI-CD pipelines
- 99.9% uptime guarantee (SLA-backed)
- 4-hour RTO / RPO recovery objectives
- Priority email support
- 100 secret lockers
Monthly billing · cancel anytime
Built to fit your environment. Whether you've outgrown the business plans or have specific requirements around data residency, key custody, or compliance, our enterprise offering is designed around your needs — not the other way around.
Frequently asked questions
Common questions from security and infrastructure teams evaluating Zaita.
Does Zaita ever have access to my private keys?
What is a Bridge and why does it need no inbound firewall rules?
How does Zaita handle the 47-day certificate mandate?
Is Zaita prepared for post-quantum cryptography?
What authentication methods do Courier agents support?
Which target systems can Zaita deploy certificates to automatically?
What is a Secret Locker and how is it different from a generic secrets vault?
How are secrets encrypted in transit and at rest?
Security expertise,
homegrown in Aotearoa
Simply Cyber Security Limited was founded in June 2021 with a clear mandate: bring world-class, independent security consulting and tooling to organisations across New Zealand and beyond — built entirely by New Zealanders, for the world.
We believe security should be practical, not performative. Our team focuses on genuine risk reduction — not checkbox compliance or boilerplate reports. When you work with us, you're working with specialists who've done this across government, finance, healthcare, and critical infrastructure.
Every line of Zaita's code is written, reviewed, and supported right here in New Zealand. No offshore handoffs, no outsourced support queues — just a team that's accountable, reachable, and deeply invested in the product.
Simply Cyber Security Limited
New Zealand Registered Business — NZBN: 9429049397420
Compliance & Standards Expertise
Deep practitioner experience across all major frameworks — from initial gap analysis through to certification and ongoing assurance.
100% New Zealand Team
Every engineer, consultant, and support agent is based in New Zealand. No outsourcing, no exceptions.
Certificates expiring. Secrets sprawling. Zaita solves both.
Automate your entire certificate lifecycle, run your own private CA, and deliver secrets to every workload — all from one platform. Start a 30-day free trial with full enterprise features and no credit card required.
30 days · Full enterprise limits · No credit card required