Stop managing certificates and secrets. Start automating them.
Zaita is the world-leading platform for X.509 certificate lifecycle management, private PKI, and secrets management. Discover every certificate, run your own CA hierarchy, automatically renew and deploy to your servers, and store and rotate secrets to every workload — all with data sovereignty in your chosen region.
30 days free · Full enterprise limits · No credit card required
The Platform
Three deeply integrated products. One platform.
Zaita covers the full security automation lifecycle — from discovering certificates you didn't know existed, to rotating every secret across every workload, with a private CA hierarchy protecting it all.
Certificate Lifecycle Management
Discover every certificate across your estate, automate renewal before expiry, and deploy directly to Windows and Linux servers. Built for the 47-day mandate and post-quantum crypto agility.
- Certificate discovery & inventory
- Automated renewal & deployment
- Policy & compliance engine
- Post-quantum readiness
Private PKI
Build a complete root and intermediate CA hierarchy — fully managed, with private keys protected in a dedicated, isolated signing system that never touches the internet.
- Root & intermediate CA hierarchy
- Isolated signing system architecture
- Private ACME server
- SSO, RBAC & machine accounts
Secrets Management
Store, rotate, and deliver secrets to every workload automatically. Secret Lockers keep credentials, API keys, and tokens organised, versioned, and delivered without human involvement.
- Secret Lockers — named, versioned vaults
- Automated rotation & delivery
- Version history & instant rollback
- Full audit trail & SIEM integration
The Mandate
Certificate lifespans are shrinking — fast
Global standards bodies are mandating shorter and shorter certificate lifespans. Manual renewal processes that barely hold together today will completely collapse within years — and the timeline is accelerating.
Source: CA/Browser Forum Ballot SC-081 — Short-Lived Certificates
The next cryptographic crisis is already underway
Quantum computers will break RSA and ECC — the algorithms protecting every certificate in your estate. Adversaries are harvesting encrypted traffic now to decrypt it later. Zaita's centralised CLM gives you crypto agility: update the algorithm policy once and Zaita re-issues and redeploys your entire estate in hours.
Algorithm migration across thousands of certificates takes months of manual coordination — with high risk of incomplete migration leaving vulnerable certs in production.
Update the algorithm policy once. Zaita re-issues and redeploys every affected certificate automatically — across every server, every environment, in hours.
Hosting
Deployed wherever your compliance requirements demand
Fully managed shared hosting or your own dedicated infrastructure — across globally distributed regions to meet data residency requirements anywhere in the world.
Multi-Tenant SaaS
Fully managed cloud hosting with strong isolation between customers. Available across multiple regions with offline backups for peace of mind.
Single-Tenant
Your own dedicated infrastructure — complete isolation for regulated industries and the strictest compliance requirements. EU specialist providers available.
HSM Integration
Already have a Hardware Security Module? Connect it to Zaita for the ultimate in key protection and compliance assurance.
Pricing
Start free. Grow at your pace.
There are no hidden fees or surprise overage charges. Our pricing is transparent and predictable, so you can focus on building your PKI and managing your secrets — not on managing your bill.
Everything you need to build and run a personal private PKI for the price of a coffee.
- One user account
- 1 Root CA + 2 Intermediate CA certificates
- 5 leaf certificates per month
- CT log scanning for 1 domain (24-hr monitoring)
- Web portal + 1 private ACME server
- Courier agent (direct SaaS connection, cron-scheduled)
- 10 secret lockers
No credit card required · start trial today
More certificates and more domains for active users. Perfect for home-lab use.
- One user account
- 20 leaf certificates per month
- CT log scanning for up to 2 domains
- 2 private ACME servers
- Courier agent (direct SaaS connection)
- Email support
- 20 secret lockers
Monthly billing · cancel anytime
For small teams ready to automate. SSO, Bridges, and target system deployment.
- Single Sign-On (SAML) with one identity provider (IdP) — Maximum 5 users
- 1 Root CA + 4 Intermediate CA certificates
- 50 leaf certificates per month
- CT log scanning for up to 2 domains + HTTPS endpoint scanning
- Web Portal + 2 private ACME servers
- Courier agent (direct SaaS connection)
- Credential-less machine auth (SPIFFE, Azure, AWS IAM OIDC)
- Email support
- 50 secret lockers
Monthly billing · cancel anytime
For growing teams that need higher certificate volumes, more automation, and a formal uptime guarantee with recovery SLAs.
- Single Sign-On (SAML) with one identity provider (IdP) — Maximum 20 users
- 100 leaf certificates per month
- 1 Bridge Deployment — on-prem 'push' deployment
- Automated deployment to Windows (WinRM) and Linux (SSH) servers
- Service accounts for DevOps / CI-CD pipelines
- 99.9% uptime guarantee (SLA-backed)
- 4-hour RTO / RPO recovery objectives
- Priority email support
- 100 secret lockers
Monthly billing · cancel anytime
Built to fit your environment. Whether you've outgrown the business plans or have specific requirements around data residency, key custody, or compliance, our enterprise offering is designed around your needs — not the other way around.
Frequently asked questions
Common questions from security and infrastructure teams evaluating Zaita.
Does Zaita ever have access to my private keys?
What is a Bridge and why does it need no inbound firewall rules?
How does Zaita handle the 47-day certificate mandate?
Is Zaita prepared for post-quantum cryptography?
What authentication methods do Courier agents support?
Which target systems can Zaita deploy certificates to automatically?
Security expertise,
homegrown in Aotearoa
Simply Cyber Security Limited was founded in June 2021 with a clear mandate: bring world-class, independent security consulting and tooling to organisations across New Zealand and beyond — built entirely by New Zealanders, for the world.
We believe security should be practical, not performative. Our team focuses on genuine risk reduction — not checkbox compliance or boilerplate reports. When you work with us, you're working with specialists who've done this across government, finance, healthcare, and critical infrastructure.
Every line of Zaita's code is written, reviewed, and supported right here in New Zealand. No offshore handoffs, no outsourced support queues — just a team that's accountable, reachable, and deeply invested in the product.
Simply Cyber Security Limited
New Zealand Registered Business — NZBN: 9429049397420
Compliance & Standards Expertise
Deep practitioner experience across all major frameworks — from initial gap analysis through to certification and ongoing assurance.
100% New Zealand Team
Every engineer, consultant, and support agent is based in New Zealand. No outsourcing, no exceptions.
The certificate crisis is coming. Zaita is ready. Are you?
Get started with a 30-day free trial — no credit card needed, full enterprise features from day one.
30 days · Full enterprise limits · No credit card required