Internal Certificate Authority
HexTrust
Internal certificate authority and digital trust layer.
- Deployment
- Private Cloud · On-Prem · Air-Gapped
Overview
Functional · Root CA + SSL
The digital trust layer that verifies systems and services.
HexTrust runs on HexCluster runtime, built on HexCloud infrastructure.
HexTrust manages internal certificates, SSL/TLS lifecycle, service identity, and secure trust chains so systems can verify and communicate inside controlled infrastructure.
HexTrust gives your ecosystem a controlled certificate authority and TLS lifecycle layer.
Core capabilities
Automated rotation
Trust chain management
mTLS for services
Device certificates
Revocation control
Depends on
HexCloud
Learn moreHexCluster
Learn moreEnabled
HexDNS
HexShield
HexIdentity
HexPulse
VYRA
DARSHAN
The problem
Unverified Internal Services
Private systems need trusted service identity.
Manual Certificate Management
Certificates need lifecycle control, renewal, and governance.
Weak Machine Trust
Service-to-service communication needs verifiable trust chains.
Security Without Structure
Secure environments need internal CA and TLS discipline.
Capabilities
Internal CA
SSL/TLS lifecycle
Certificate issuance
Service trust
Encryption readiness
Trust chain governance
Machine identity
Secure renewal control
The system at work
HexCluster Runtime
Internal Root CA
Certificate Issuance
TLS Lifecycle
Service Identity
Trust Validation
Renewal Controls
Secure Communication
Built for
Internal services
Private cloud environments
On-prem applications
Air-gapped systems
Service-to-service security
Identity-enabled platforms
Secure API layers
Enterprise trust governance
Frequently asked questions
What is HexTrust?
HexTrust is Hexmon’s internal certificate authority and SSL/TLS lifecycle management layer.
Why is HexTrust needed?
It gives private services verifiable identity and encrypted trust chains.
Does HexTrust work in restricted environments?
Yes. It is designed for private, on-prem, and air-gapped infrastructure.
Hex Trust Architecture
Start / Trust Boundary
Define the private trust perimeter for internal systems, services, and machines.
HexCloud & HexCluster Foundation
Use private infrastructure and runtime layers as the base for trust services. Connection: HexCloud · HexCluster Private compute foundation and runtime layer hosting HexTrust certificate authority services.
Root CA Initialization
Establish the internal root certificate authority for the controlled environment.
Intermediate CA Layer
Create delegated signing layers for safer certificate operations.
Certificate Policy Definition
Define certificate templates, validity periods, usage rules, and approval policies. Connection: HexVault Stores certificate records, trust artifacts, audit evidence, and backup material securely.
Service Identity Registration
Register internal services, machines, domains, and workloads for trusted identity. Connection: HexIdentity Connects user roles, service access, and certificate-backed trust for identity governance.
Certificate Issuance
Generate and issue certificates for applications, APIs, devices, and internal services.
TLS Binding & Trust Distribution
Bind certificates to services and distribute trust chains across the ecosystem. Connection: HexDNS · HexShield Private DNS discovery and encrypted overlay fabric consume trusted service certificates.
Renewal, Rotation & Revocation
Manage expiry, renewal, key rotation, and certificate revocation workflows.
Audit, Expiry & Compliance Monitoring
Track certificate health, expiration, issuance history, and compliance events. Connection: HexPulse Monitors certificate health, expiry, issuance events, audit logs, and trust-layer signals.
Ecosystem Trust Consumers
Enable trusted communication for DNS, identity, monitoring, VYRA, and DARSHAN. Connection: VYRA · DARSHAN AI intelligence and digital signage services rely on trusted certificates for secure communication.
Secure Communication Lifecycle
Maintain trusted service identity and encrypted communication over time.