What is our primary use case?
My main use case for AppViewX CERT+ includes three business cases that I can explain. For internal websites that we have in the company, we share with the business and provide because we need to be completely secure with this environment. Each business owner and developers request internal certificates. We now have a workflow that they can request from our management tool. They request the certificate and then the certificate team, with AppViewX CERT+, generates the certificate for them and pushes them directly to the server where it's deployed without requiring anything on their side.
The second case is for public certificates, all the websites and SaaS environment that we use, which we provide to the business and external clients. This workflow differs because it involves public certificates approved by our public authority. This process is closely tied to the business as they need to ensure certificate validity, especially when planning to move URLs or stop services within six to eight months, due to associated costs. The process is similar to internal websites but requires change management for production. The process varies depending on whether the SaaS application is in our cloud environment or managed by a provider. In both cases, we create the certificate with AppViewX CERT+, generate it, verify DNS entries for public authority validation, and then either push it ourselves if we manage the backend or coordinate with the provider to implement it.
The third business case involves application and mobile application coding. We have specific workflows and certificate possibilities that are highly integrated with the automation process, especially for APIs. Our developers create numerous APIs for clients, ranging from two or three per month to sometimes more than 100. We have created an automation process that generates certificates for varying periods depending on API requirements.
What is most valuable?
We have been using AppViewX CERT+ for more than a year and are really happy with the solution, including their business services and the development of our company workflows. It has helped reduce latency in certificate requests from business and application owners while providing numerous security solutions.
AppViewX CERT+ offers many possibilities, including the ability to send notifications when certificates are approaching expiration to app owners. The solution also provides extensive integration capabilities with various components and device types, such as pushing certificates directly to NetScaler or creating certificates in Azure automatically. These features significantly reduce our workload in certificate management.
The automation is the best feature, along with their business-focused development. Compared to other solutions we tested, AppViewX CERT+ stands out. Though not a public authority itself, it works with them, offering similar capabilities to DigiCert, our new public authority. AppViewX CERT+ excels not only in managing and generating certificates but also in creating workflows and offering multiple workflow options for different business cases.
What needs improvement?
We have discussed with them the need for better integration with APIs, including specific definitions and business cases. We would benefit from templates for specific APIs that need to connect with external vendors or integrate directly with our backend. This feature is currently in their development pipeline.
Another improvement area is the integration with automation, specifically simplifying the ACME services they offer to work without an agent. Currently, every backend machine requires an agent for ACME services. This improvement will become crucial in the next two years when public certificates must be reduced from one year to 47 days, which presents a significant challenge for us.
For how long have I used the solution?
We use AppViewX CERT+ for more than a year.
What do I think about the stability of the solution?
AppViewX CERT+ is completely stable because we use their cloud solution and they are everywhere. The scalability extends to the agents we have on our backend, and we have these agents on multiple data centers, making it available and scalable everywhere.
What do I think about the scalability of the solution?
AppViewX CERT+ is completely stable because we use their cloud solution and they are everywhere. The scalability extends to the agents we have on our backend, and we have these agents on multiple data centers, making it available and scalable everywhere.
How are customer service and support?
On a scale of one to 10, I would give AppViewX CERT+ customer support a nine.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before choosing AppViewX CERT+, we did not use a solution. While I evaluated other options, I cannot recall the specific solution we considered. It was somewhat similar but was completely cloud-based, which is not permitted in financial markets.
How was the initial setup?
My experience with pricing, setup cost, and licensing was really good. It was defined as a project and all the mandatory dates were expected and followed correctly. We had no issues with them and the discussion was really productive.
What about the implementation team?
We have sufficient engineers in this company to help us with deployment and troubleshooting if something goes wrong with the flow that needs to be opened on our side.
What was our ROI?
We have seen a return on investment with AppViewX CERT+ through reduced costs in human resources. The time spent on certificate services and deploying new certificates was significantly reduced due to automation. This has benefited the business as we are only a few people managing numerous certificate requests, including nighttime requests.
The current process is much simpler compared to our previous complex process that required connecting to different environments. With full backend integration, users simply follow the workflow and the certificate is deployed correctly. This efficiency saves time and money, which is particularly important in a financial company where time directly correlates to costs.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was really good. It was defined as a project and all the mandatory dates were expected and followed correctly. We had no issues with them and the discussion was really productive.
Which other solutions did I evaluate?
I evaluated other options before choosing AppViewX CERT+, but I cannot recall the specific solution we considered. It was somewhat similar but was completely cloud-based, which is not permitted in financial markets.
What other advice do I have?
I recommend AppViewX CERT+ for organizations needing a solution that can create workflows to provide more control and management. The tool is easy to understand for anyone with minimal knowledge of certificates. The management capabilities, including permission controls for business users to approve or request certificates, make it highly recommendable for those seeking a solution to manage workflows while maintaining certificate control. Based on my experience, I rate AppViewX CERT+ a 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other