Security
Your credentials, kept to a minimum and encrypted
LapseZero only asks for what a feature actually uses. Certificate monitoring needs nothing. DNS validation can run on a one-time CNAME instead of DNS keys. Everything you do provide is encrypted with AES-256-GCM.
Only what each feature needs
| Feature | What you provide | Alternative |
|---|---|---|
| Certificate monitoring | Nothing | — |
| DNS validation | A one-time CNAME record, or an API token for your DNS provider | Pick whichever you prefer |
| Deploying to cloud products | A cloud access key with the permissions listed for each target | Deploy over SSH, or download the certificate |
| Deploying to servers | SSH login (password or private key) | Download the certificate and install it yourself |
Validate domains without DNS keys
- Add one CNAME such as
_acme-challenge.example.com→<random>.acme.lapsezero.com. After that, every issuance and renewal runs on its own, with no DNS changes and no DNS credentials. - The CNAME is used only for certificate validation. Your other DNS records are never touched.
- Delete the CNAME whenever you want to stop.
Or use your DNS provider's API
- LapseZero adds a TXT record at
_acme-challenge.<domain>for each validation and removes it right after. - A sub-account or token limited to DNS for the zones you need is enough.
Deployment credentials
- Cloud deployment uses an Alibaba Cloud, Tencent Cloud or AWS access key. The exact actions each target uses are listed on integrations, so you can grant just those.
- SSH deployment uses an account on your host that can write the certificate files and, if you set one, run your reload command.
How credentials are protected
- DNS and cloud credentials, SSH passwords and keys, certificates and private keys are all encrypted with AES-256-GCM before they are stored.
- Credentials are checked when you save them, so mistakes surface right away instead of at renewal time.
- Once saved, credentials are never shown again. The console and API return only names and other metadata.
- Certificates and private keys can be downloaded only by their owner.
- Deleting a provider or SSH host deletes its stored credentials.
Your data, your call
- Email
[email protected]from your account address to delete your account. All domains, certificates, credentials and logs are removed within 30 days. See the Privacy Policy for details.