Skip to content Book a PKI health check Get incident support

The engagement

Evidence in. Risk out.

A controlled five-step process from scope to verification. You know what access is needed, what is collected and what your engineers will receive before work begins.

How a health check runs

Five steps. Two weeks.
No changes to production.

scoping — call notes
PS> Get-CAHierarchy -Summary

Forest            : corp.example.com
Enterprise CAs    : 3
  ROOT-CA-01      Offline  SHA256  RSA4096  exp 2039
  ISSUING-CA-01   Online   SHA256  RSA2048  exp 2031
  ISSUING-CA-02   Online   SHA1    RSA2048  exp 2029
Published templates : 41
Endpoints (est.)    : 5,000 – 15,000

# scope agreed. no credentials exchanged.

Representative output. Collection scripts are supplied for your review before anything runs.

Access

Read-only is usually enough.

The collection method is supplied for review. Your team can run it, or we can run it while they watch. An assessment does not need service restarts, certificate enrolment or configuration changes.

Account
Low-privilege domain account in most estates
Host
Domain-joined administrative workstation
Writes
None during assessment collection
Review
Collection script available before execution

Data handling

Evidence is handled like evidence.

The final retention period and approved transfer route are agreed in the statement of work, so data handling is explicit rather than assumed.

  • Read-only access preferred and sufficient for assessment
  • NDA by default, signed before evidence collection
  • Evidence encrypted at rest, deleted on a stated retention schedule
  • Collection scripts supplied for review before they are run

Exact hosting, transfer and deletion controls are documented per engagement and adjusted to client policy where required.

The handover

A report your engineers can operate from.

Findings are ranked by risk and paired with specific remediation and verification. The walkthrough transfers context, not just a PDF.

Scope an engagement