Data as of Aug 25, 2026 · Based on 367 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
If you need broad enterprise discovery and certificate lifecycle orchestration, choose Keyfactor. If you need hardware-backed, BYOK-capable hybrid/multi-cloud control with strong compliance logging, choose
Fortanix DSM. DevOps teams may prefer
HashiCorp Vault for dynamic secrets.
Brands AI recommends here
Named in 72% of answers
Best when you require enterprise-wide discovery, certificate orchestration, and IoT/DevOps support; Keyfactor emphasizes automated inventory and orchestration, though its strength skews toward certificates over cloud KMS features.
Named in 50% of answers
Named in 49% of answers
Named in 45% of answers
If your goal is **“discover every cryptographic asset we have, understand where it is used, assess risk, and then manage/rotate it”**, I’d put **[keyfactor.com](https://www.keyfactor.com?utm_source=chatgpt.com)** at the top of the shortlist. The important distinction is that traditional **key-management systems…
If your goal is “discover every cryptographic asset we have, understand where it is used, assess risk, and then manage/rotate it”, I’d put keyfactor.com at the top of the shortlist.
The important distinction is that traditional key-management systems (KMS/HSMs) manage keys inside the systems they control. What you’re describing sounds broader: enterprise cryptographic discovery + crypto-agility + lifecycle management.
| Platform | Best fit | Why I’d consider it |
|---|---|---|
| keyfactor.com | Best overall for crypto-agility | Broad cryptographic discovery across endpoints, servers, cloud, code and networks; inventory includes keys, certificates, algorithms, protocols and crypto libraries. Strong focus on PQC migration and remediation. Keyfactor Keyfactor |
| digicert.com Trust Lifecycle Manager | Best if certificates/PKI are the center of gravity | Strong CA-agnostic certificate/key discovery, centralized inventory, policy enforcement and lifecycle automation. It explicitly supports crypto-agility and PQC migration workflows. DigiCert DigiCert |
| appviewx.com AVX Platform | Best for automation-heavy enterprises | Combines CLM, PKI, cryptographic discovery and automation; also has SSH-key management. Particularly interesting if you want discovery to trigger automated remediation workflows. AppViewX AppViewX |
Keyfactor's current AgileSec capability is specifically aimed at the problem you're describing. It can discover TLS certificates, SSH keys, tokens, algorithms, protocols and cryptographic libraries across file systems, networks, infrastructure, cloud environments and code repositories, then build a centralized inventory with ownership, dependencies and risk context.
That's materially different from simply deploying something like AWS KMS, Azure Key Vault, HashiCorp Vault or an HSM. Those are excellent at protecting and operating keys, but they don't necessarily tell you what cryptography exists throughout your entire organization.
Keyfactor also positions the platform around a complete loop:
discover → inventory → assess risk → prioritize → remediate → continuously monitor
and explicitly connects discovery with certificate lifecycle management and automated remediation.
I'd make the evaluation criteria very explicit. Ask each vendor to demonstrate discovery of:
Then ask them to show how an identified weak/quantum-vulnerable key actually gets remediated, rather than merely appearing on a dashboard.
For a large enterprise starting a crypto-inventory + post-quantum readiness program, my initial bake-off would therefore be Keyfactor vs. AppViewX vs. DigiCert, with the winner determined by how much of your non-certificate cryptography each platform can actually discover and operationalize.
If you tell me roughly your environment (AWS/Azure/GCP, on-prem, Kubernetes, number of applications/endpoints, and whether you already use a CA/KMS/HSM), I can narrow this to the best 1–2 options and give you a vendor evaluation/RFP checklist.
That's materially different from simply deploying something like AWS KMS, Azure Key Vault, HashiCorp Vault or an HSM. Those are excellent at protecting and operating keys, but they don't necessarily tell you what cryptography exists throughout your entire organization.
Keyfactor also positions the platform around a complete loop:
discover → inventory → assess risk → prioritize → remediate → continuously monitor
and explicitly connects discovery with certificate lifecycle management and automated remediation.
Discovering and managing cryptographic keys across an entire organization—especially with the looming pressure of Post-Quantum Cryptography (PQC) migration—requires moving beyond traditional siloed key vaults into unified **Crypto-Agility and Certificate/Key Posture Management**…
Discovering and managing cryptographic keys across an entire organization—especially with the looming pressure of Post-Quantum Cryptography (PQC) migration—requires moving beyond traditional siloed key vaults into unified Crypto-Agility and Certificate/Key Posture Management platforms.
The "best" platform depends on whether you are prioritizing certificate lifecycle automation (CLM), data-at-rest encryption key management (KMS) , or broad cryptographic asset visibility.
Top Enterprise Platforms for Crypto-Agility & Key Discovery
- **Best For:** CA-agnostic certificate lifecycle management (CLM) and deep cryptographic discovery paired with an open-source PKI core.
- **Strengths:** Excellent at scanning network endpoints, code, and cloud environments to discover hidden keys and certificates. It provides robust automation workflows and strong posture management to prepare organizations for quantum-safe algorithm transitions.
- **Learn more:** Explore capabilities on the Keyfactor Crypto-Agility Platform.[[1]](https://guptadeepak.com/tools/top-5-pki-certificate-lifecycle-management-tools-2026/)[[2]](https://thequantuminsider.com/2026/03/25/25-companies-building-the-quantum-cryptography-communications-markets/)[[3]](https://startupstash.com/top-crypto-agility-management-platforms/)
- **Best For:** Deepest machine-identity governance and enterprise-scale orchestration.
- **Strengths:** Venafi is an industry heavyweight for discovering and orchestrating machine identities (SSH keys, TLS/SSL certificates, code-signing keys). Now integrated into CyberArk, it specializes in locking down how machine identities are used and automatically remediating weak or expired crypto assets.
- **Learn more:** Check out platform integrations via CyberArk Venafi.[[1]](https://guptadeepak.com/tools/top-5-pki-certificate-lifecycle-management-tools-2026/)
- **Best For:** Data-centric Enterprise Key Posture Management (EKPM) across hybrid and multi-cloud infrastructure.
- **Strengths:** Unlike standard CLM tools that focus heavily on certificates, Fortanix excels at discovering raw encryption keys, assessing key utilization, mapping relationships to cloud services (AWS, Azure, GCP), and flagging weak algorithms or unrotated keys across disparate data stores.
- **Learn more:** Review features on Fortanix Enterprise Key Management.[](https://support.fortanix.com/docs/fortanix-key-insight-overview) [[1]](https://support.fortanix.com/docs/fortanix-key-insight-overview)[[2]](https://www.fortanix.com/faq/key-management-system/enterprise-key-management)
- **Best For:** Unified public key infrastructure (PKI) combined with strict certificate policy enforcement and discovery.
- **Strengths:** Great if you want a tightly integrated digital trust ecosystem where discovery, issuance, and automated renewal happen seamlessly under one roof—especially if you leverage DigiCert as a primary CA.
- **Learn more:** Evaluate options via DigiCert Trust Lifecycle Manager.[[1]](https://guptadeepak.com/tools/top-5-pki-certificate-lifecycle-management-tools-2026/)[[2]](https://www.google.com/search?q=product&prds=pvt:hg,productid:11968401470109059221&ibp=oshop)
Key Capabilities to Look For
When evaluating these options for true crypto-agility , ensure the platform supports:
To help narrow down the ideal platform, tell me:
Discovering and managing an enterprise's entire cryptographic inventory—especially with looming mandates for Post-Quantum Cryptography (PQC)—requires moving beyond traditional secrets management into dedicated **Cryptographic Discovery & Crypto-Agility…
Discovering and managing an enterprise's entire cryptographic inventory—especially with looming mandates for Post-Quantum Cryptography (PQC)—requires moving beyond traditional secrets management into dedicated Cryptographic Discovery & Crypto-Agility Platforms.
While tools like HashiCorp Vault or AWS KMS are great for managing application secrets and runtime keys, they function as vaults/CAs rather than complete, cross-environment discovery engines.
The leading platforms specializing in deep discovery, cryptographic Bill of Materials (CBOM) generation, and crypto-agility are organized below by their strengths:
How to choose the right approach
To help narrow down the best fit, could you tell me:
If your goal is specifically **“discover every cryptographic key and asset we have, understand the risk, and then become crypto-agile,”** my current first choice would be **[keyfactor.com](https://www.keyfactor.com/?utm_source=chatgpt.com)**. ### My shortlist Platform | Best fit | Why I'd consider it
If your goal is specifically “discover every cryptographic key and asset we have, understand the risk, and then become crypto-agile,” my current first choice would be keyfactor.com.
| Platform | Best fit | Why I'd consider it |
|---|---|---|
| Keyfactor | Best overall for crypto-agility | Continuous discovery/inventory of cryptographic assets, policy/risk analysis, certificate/key lifecycle automation, PKI, and explicit post-quantum/crypto-agility capabilities. Keyfactor Keyfactor |
| CyberArk Venafi | Mature enterprise certificate/key management | Strong discovery, monitoring, provisioning and lifecycle management across heterogeneous CAs and environments. Venafi Docs Venafi Docs |
| AppViewX | Automation-heavy CLM/PKI | Strong workflow automation, integrations, cryptographic discovery, CBOM/PQC readiness and certificate lifecycle management. AppViewX AppViewX |
Why Keyfactor gets my nod: its newer platform is explicitly organized around cryptographic posture management, not just certificates. It says it can inventory cryptographic objects, assess them against organizational policies, discover cryptography throughout the ecosystem, and automate remediation. Keyfactor Keyfactor In June 2026, Keyfactor also launched its Trust Control Plane, combining cryptographic assets and machine identities under a unified operating model.
One important distinction: a traditional KMS/HSM isn't the same thing as enterprise crypto discovery. AWS KMS, Azure Key Vault, Google Cloud KMS, Thales, etc. are excellent for protecting and operating keys, but they don't necessarily give you a complete inventory of cryptography scattered across applications, certificates, SSH, databases, appliances, legacy systems, embedded devices, and code.
Don't let vendors win the POC merely by showing a pretty certificate dashboard. I'd test whether the platform can:
If you're starting a serious enterprise crypto-agility / post-quantum readiness program, I'd run a bake-off between Keyfactor, CyberArk Venafi, and AppViewX, with Keyfactor as the baseline.
If you tell me roughly how big your environment is (e.g. 10K vs. 1M+ keys/certs), cloud/on-prem mix, and whether you need actual private-key custody or primarily discovery/governance, I can narrow this to the best 1–2 options and give you a vendor evaluation scorecard.
Don't let vendors win the POC merely by showing a pretty certificate dashboard. I'd test whether the platform can:
If you're starting a serious enterprise crypto-agility / post-quantum readiness program, I'd run a bake-off between Keyfactor, CyberArk Venafi, and AppViewX, with Keyfactor as the baseline.
If you tell me roughly how big your environment is (e.g. 10K vs. 1M+ keys/certs), cloud/on-prem mix, and whether you need actual private-key custody or primarily discovery/governance, I can narrow this to the best 1–2 options and give you a vendor evaluation scorecard.
Here are top web results for exploring this topic: [](https://www.keyfactor.com/products/cryptographic-posture-management/)  Keyfactor·https://www.keyfactor.com**Cryptographic** Posture **Management** - Keyfactor Manage Cryptographic Posture…
Here are top web results for exploring this topic:
Keyfactor·https://www.keyfactor.com**Cryptographic** Posture Management - Keyfactor Manage Cryptographic Posture · Cryptography Posture. Inventory all cryptographic objects and benchmark them against best practices and your organization's policy.
Startup Stash·https://startupstash.com Top Crypto-Agility Management Platforms In 2026 - Startup Stash ... specific points: mass TLS rotation across Kubernetes ingress controllers, inconsistent ACME enrollments across multi-cloud, and slow swaps from RSA or ECDSA to NIST's new ML-KEM or ML-DSA in code
Encryption Consulting·https://www.encryptionconsulting.com Top Cryptographic Inventory Vendors and Methodologies Cryptographic sprawl — most enterprises have tens of thousands of keys and certificates scattered across cloud, on-prem, HSMs, databases, secrets vaults, and source code, with no authoritative invento
www.futurex.com·https://www.futurex.com/blog/which-key-management-solution-is-best Which Key Management Solution is Best for Me? - Futurex 6. Which Key Management Solution Is Best for Securing IoT Devices? This solution manages the cryptographic keys required for IoT devices. It enables secure key injection and lifecycle management, whic
Cryptomathic·https://www.cryptomathic.com**Encryption Key Management Software** - Cryptomathic Safeguard sensitive customer data and comply with security standards with CKMS and CSG – our powerful and intuitive encryption key management software.
Gartner·https://www.gartner.com**What** is Multicloud Key Management as a Service (KMaaS)? - Gartner Fortanix Data Security Manager is a software designed to provide centralized management and protection of encryption keys, secrets, and tokens. The software enables organizations to secure sensitive d
emudhra.com·https://emudhra.com/en/blog/finding-the-best-key-management-system-from-the-rest**Finding** the Best Key Management System from the Rest - eMudhra A good key management system provides centralized control over all your encryption keys. You may be managing a few keys or thousands. Consistency, ease of use, and better control are ensured through c
Fortanix·https://www.fortanix.com**How** to Future Proof Your Encryption with Crypto-Agility and Next ...Why encryption strategies are shifting toward crypto agility; What “next-gen key management” actually means; How organizations can best manage encryption keys across clouds and AI workloads; What mode LinkedIn·https://www.linkedin.com The Best Guide to Choosing the Right Key Management Solution What really keeps things safe is how you manage the cryptographic keys behind the encryption. That's where the right key management solution comes in, and for small and medium-sized businesses, it's a Google Cloud Security Community·https://security.googlecloudcommunity.com From Inventory to Agility : A CISO's Guide to Robust Key Management We have linked the ability to seamlessly transition to new cryptographic algorithms – keyword “cryptographic agility” – tightly to robust key management practices, particularly key rotation as describ
No sources cited
If your goal is **“discover every cryptographic key/algorithm/certificate we have, understand where it’s used, and then manage migration and rotation,”** I’d put **Keyfactor** at the top of the shortlist. ### My shortlist | Platform | Best fit | Why I’d consider it |
If your goal is “discover every cryptographic key/algorithm/certificate we have, understand where it’s used, and then manage migration and rotation,” I’d put Keyfactor at the top of the shortlist.
| Platform | Best fit | Why I’d consider it |
|---|---|---|
| Keyfactor | Broad crypto-agility / enterprise crypto inventory | Its AgileSec product discovers keys, certificates, algorithms, crypto libraries and protocols across servers, endpoints, cloud, networks and code; it then provides risk scoring, policy and remediation workflows. www.keyfactor.com |
| Venafi / CyberArk | Huge certificate/key + machine-identity estates | Particularly strong for TLS certificates, SSH keys and machine identities, with discovery, monitoring, policy enforcement and lifecycle automation across heterogeneous environments. docs.venafi.com |
| HashiCorp Vault | Cloud-native secrets, PKI and key operations | Excellent when your primary problem is securely storing/using secrets and issuing short-lived credentials, rather than discovering every piece of cryptography embedded throughout the enterprise. |
| DigiCert | Certificate lifecycle / PKI | Strong choice if certificates and public/private PKI are the dominant problem, but I'd look beyond it if your objective is comprehensive cryptographic discovery and PQC migration. |
The important distinction is key management vs. cryptographic discovery.
A traditional KMS/HSM/secret manager answers:
“Where do we securely store and use the keys we already know about?”
Crypto-agility requires answering:
“Where is cryptography being used across the entire organization, including things we don't know about?”
Keyfactor's current AgileSec capability specifically inventories keys, certificates, algorithms, protocols and cryptographic libraries, including assets in file systems, networks, infrastructure, cloud and code repositories. It can also identify deprecated algorithms, exposed/improperly protected keys and quantum-vulnerable cryptography.
That's much closer to an enterprise cryptographic asset-management / crypto-posture-management platform than a conventional KMS.
It also connects discovery to remediation: Keyfactor describes integrations with CLM, GRC, ITSM and CMDB systems and workflows such as key rotation and certificate renewal.
I wouldn't expect one product to literally replace every KMS/HSM/secrets system.
A mature architecture often looks more like:
Crypto inventory / discovery → Keyfactor AgileSec
Certificate & PKI lifecycle → Keyfactor Command / EJBCA, or Venafi/CyberArk
Application secrets / dynamic credentials → HashiCorp Vault or cloud-native equivalents
High-assurance key protection → HSM/KMS infrastructure
Code signing → Keyfactor Signum/SignServer or another dedicated signing platform
Keyfactor itself now positions its platform around visibility, trust/identity and lifecycle automation rather than simply being a key vault.
Don't let vendors win based on a pretty certificate dashboard. Give them a concrete discovery challenge and ask:
On those criteria, Keyfactor would be my first vendor evaluation, with Venafi/CyberArk as the strongest alternative, particularly if your environment is dominated by machine identities and certificates. Independent 2026 comparisons similarly place Keyfactor and Venafi among the leading enterprise machine-identity platforms, while positioning Vault/Smallstep more toward cloud-native credential issuance.
If you tell me roughly your environment (AWS/Azure/GCP/on-prem), number of applications/servers, and whether the main concern is PQC migration, certificates, encryption keys, secrets, or all of them, I can narrow this to a 3-vendor recommendation with a feature-by-feature scorecard.
If your goal is specifically **“discover every cryptographic asset we have, understand where/how it’s used, and then manage the lifecycle so we can become crypto-agile,”** I’d put **Keyfactor** at the top of the shortlist today. ### My shortlist | Platform | Best fit | Why I’d consider it |
If your goal is specifically “discover every cryptographic asset we have, understand where/how it’s used, and then manage the lifecycle so we can become crypto-agile,” I’d put Keyfactor at the top of the shortlist today.
| Platform | Best fit | Why I’d consider it |
|---|---|---|
| Keyfactor | Broad crypto discovery + crypto-agility | Its AgileSec platform is explicitly built for cryptographic discovery/inventory, scanning hosts, networks, source code, CI/CD, containers, etc. It can find certificates, keys, keystores, crypto libraries and tokens. docs.keyfactor.comdocs.keyfactor.com |
| CyberArk / Venafi | Large-enterprise machine identity & certificate/key lifecycle | Very mature discovery and lifecycle management across certificates, private keys and SSH, with strong provisioning/renewal automation and heterogeneous CA support. docs.venafi.com |
| DigiCert ONE | PKI/certificate-centric organizations + PQC transition | Strong certificate/key discovery and lifecycle automation, and notably has Quantum Central, introduced in July 2026, for cryptographic inventory and post-quantum migration planning. www.digicert.com |
The important distinction is crypto inventory vs. certificate inventory.
If by “all cryptographic keys” you literally mean all uses of cryptography throughout the enterprise—keys buried in source code, keystores, hosts, containers, network protocols, CI/CD, certificates, etc.—Keyfactor's AgileSec is particularly interesting. Its sensors are designed to discover cryptographic information from files, network connections, source code and more, and its Git sensor can identify keys, certificates, Java keystores, JWT/JWE tokens and crypto libraries.
Then Keyfactor Command handles the more traditional certificate/key lifecycle side. Keyfactor describes its platform as providing visibility and control over digital keys and certificates plus automated discovery, management and renewal.
Choose CyberArk/Venafi if your primary problem is enterprise machine identity management—TLS certificates, SSH keys, private keys, provisioning, renewal and policy enforcement across a huge heterogeneous estate. Venafi's current platform supports symmetric/asymmetric/SSH encryption and multiple CAs and deployment environments.
Choose DigiCert if you're already heavily invested in DigiCert/PKI and your main objective is certificate lifecycle + crypto-agility + post-quantum readiness. Its newly introduced Quantum Central is particularly relevant if PQC migration is driving the project.
No platform is going to magically produce a perfect inventory of every secret key in an organization. I'd evaluate vendors on whether they can discover:
If you're starting from scratch, my recommendation would be to run a proof-of-concept with Keyfactor AgileSec and CyberArk/Venafi, with DigiCert as the third contender. Don't make the decision based on certificate-management demos alone; make each vendor prove how much of your actual cryptographic estate it can discover.
If you tell me roughly your environment (AWS/Azure/GCP, Kubernetes, on-prem, number of certs/keys, HSM/KMS vendors, and whether PQC is a priority), I can narrow this to a winner and give you a vendor evaluation scorecard.
Discovering and managing all cryptographic assets—and building true crypto-agility (especially in the era of post-quantum cryptography (PQC) and strict compliance mandates)—requires a combination of **discovery/CBOM (Cryptographic Bill of Materials) tools**, **Certificate Lifecycle Management (CLM)** , and…
Discovering and managing all cryptographic assets—and building true crypto-agility (especially in the era of post-quantum cryptography (PQC) and strict compliance mandates)—requires a combination of discovery/CBOM (Cryptographic Bill of Materials) tools, Certificate Lifecycle Management (CLM) , and Enterprise Key Management (EKM).
There is no single "magic bullet" platform that handles code scanning, hardware security, cloud secrets, and network ciphers natively out-of-the-box without integration, but a few market leaders lead the pack depending on your primary objective:
To help narrow down the ideal platform or combination for your environment, tell me:
Discovering and managing enterprise cryptographic assets—ranging from symmetric keys and SSH keys to X.509 certificates and hardware security module (HSM) contents—requires looking at **Certificate Lifecycle Management (CLM)**, **Public Key Infrastructure (PKI)** , and emerging **Crypto-Agility / Post-Quantum…
Discovering and managing enterprise cryptographic assets—ranging from symmetric keys and SSH keys to X.509 certificates and hardware security module (HSM) contents—requires looking at Certificate Lifecycle Management (CLM), Public Key Infrastructure (PKI) , and emerging Crypto-Agility / Post-Quantum Cryptography (PQC) readiness platforms.
With shrinking TLS lifetimes (heading toward a 47-day maximum validity standard) and looming NIST post-quantum migration deadlines, manual spreadsheets are no longer viable.
Leading enterprise platforms approach cryptographic discovery and management with distinct strengths:
To help narrow down the ideal platform for your organization, tell me:
If your goal is specifically **“discover every cryptographic key/asset we have, understand what uses it, assess risk, and then manage/rotate/migrate it,”** I’d shortlist **Keyfactor and Fortanix**, with AppViewX as another strong option if certificates/PKI are the dominant problem. ### My ranking | Platform | Best fit…
If your goal is specifically “discover every cryptographic key/asset we have, understand what uses it, assess risk, and then manage/rotate/migrate it,” I’d shortlist Keyfactor and Fortanix, with AppViewX as another strong option if certificates/PKI are the dominant problem.
| Platform | Best fit | Why |
|---|---|---|
| Keyfactor | Best overall for enterprise crypto-agility | Strongest emphasis on broad cryptographic discovery/inventory: keys, certificates, algorithms, protocols and libraries, plus risk prioritization and remediation workflows. www.keyfactor.com |
| Fortanix | Best if you also need centralized key management/KMS | Combines cryptographic discovery/posture assessment with enterprise encryption key management, automated rotation/revocation, HSM capabilities and multicloud key control. www.fortanix.com |
| AppViewX | Best for PKI/certificate-heavy environments | Excellent certificate discovery and lifecycle automation, plus crypto inventory/CBOM and PQC-readiness capabilities. www.appviewx.com |
I'd avoid treating “key management” and “cryptographic inventory” as the same problem.
A traditional KMS tells you how to generate, store, authorize, rotate and destroy keys under its control. That doesn't necessarily tell you where all the cryptography in your organization is.
For crypto-agility, you want an inventory that can uncover things such as:
Keyfactor is particularly compelling here: its AgileSec product describes continuous discovery across code, servers, endpoints, cloud workloads and network traffic, then correlates assets with ownership, dependencies and risk.
Fortanix takes a somewhat different approach: Key Insight discovers encryption keys and maps them to the data services using them across on-premises and hybrid/multicloud environments, while its broader platform provides the actual centralized key-management capabilities.
If you're starting from “we don't know where all our cryptography is”: choose Keyfactor.
If you're starting from “we need one enterprise KMS/HSM/key-control platform across AWS/Azure/GCP/on-prem”: choose Fortanix.
If your biggest operational pain is certificates, PKI and machine identities: choose AppViewX.
For a large enterprise, I would actually evaluate Keyfactor + your existing KMS/HSM infrastructure versus Fortanix as a more consolidated platform, rather than assuming you need to replace every existing key-management system.
One particularly important requirement for 2026 is PQC readiness. Don't just ask vendors whether they are “post-quantum ready”; ask them to demonstrate that they can produce a continuously updated cryptographic inventory/CBOM, map cryptographic dependencies, identify quantum-vulnerable assets, and show exactly how you'd migrate a selected application from today's algorithms to the replacement algorithms. That's the practical test of crypto-agility.
If you tell me roughly your environment (AWS/Azure/GCP/on-prem), number of endpoints/apps, whether you already use a KMS/HSM, and whether PKI/certificates are in scope, I can give you a much more concrete Keyfactor vs. Fortanix vs. AppViewX comparison and a recommended architecture.