Security

Your credentials, kept to a minimum and encrypted

LapseZero only asks for what a feature actually uses. Certificate monitoring needs nothing. DNS validation can run on a one-time CNAME instead of DNS keys. Everything you do provide is encrypted with AES-256-GCM.

Only what each feature needs

FeatureWhat you provideAlternative
Certificate monitoringNothing—
DNS validationA one-time CNAME record, or an API token for your DNS providerPick whichever you prefer
Deploying to cloud productsA cloud access key with the permissions listed for each targetDeploy over SSH, or download the certificate
Deploying to serversSSH login (password or private key)Download the certificate and install it yourself

Validate domains without DNS keys

  • Add one CNAME such as _acme-challenge.example.com → <random>.acme.lapsezero.com. After that, every issuance and renewal runs on its own, with no DNS changes and no DNS credentials.
  • The CNAME is used only for certificate validation. Your other DNS records are never touched.
  • Delete the CNAME whenever you want to stop.

Or use your DNS provider's API

  • LapseZero adds a TXT record at _acme-challenge.<domain> for each validation and removes it right after.
  • A sub-account or token limited to DNS for the zones you need is enough.

Deployment credentials

  • Cloud deployment uses an Alibaba Cloud, Tencent Cloud or AWS access key. The exact actions each target uses are listed on integrations, so you can grant just those.
  • SSH deployment uses an account on your host that can write the certificate files and, if you set one, run your reload command.

How credentials are protected

  • DNS and cloud credentials, SSH passwords and keys, certificates and private keys are all encrypted with AES-256-GCM before they are stored.
  • Credentials are checked when you save them, so mistakes surface right away instead of at renewal time.
  • Once saved, credentials are never shown again. The console and API return only names and other metadata.
  • Certificates and private keys can be downloaded only by their owner.
  • Deleting a provider or SSH host deletes its stored credentials.

Your data, your call

  • Email [email protected] from your account address to delete your account. All domains, certificates, credentials and logs are removed within 30 days. See the Privacy Policy for details.