Product
Truvald™
Canadian-built. No cloud. No nonsense.
Built for the real world of Windows Server ADCS — multi-CA, multi-forest, air-gapped environments and the politics of "who touched the Root CA." Truvald™ replaces a week of manual PKI health checks with a dashboard you can trust. Runs entirely in your environment — no telemetry, no SaaS portal, no cloud sync. $1,499 CAD/year or $499 CAD for a one-time 30-day license — straight from the Stripe checkout, no sales call.
Know before it breaks.
Truvald™ polls every CA in your hierarchy continuously, surfacing health issues before they become 2am incidents. CRL expiry, certificate expiry, service status, key protection, backup recency — all visible at a glance.
- CRL validity monitoring with configurable warning thresholds
- CA certificate expiry tracking with multi-level alerts
- ADCS service state and event log health
- Backup status and last-known-good timestamps
- Full multi-CA, multi-forest hierarchy support
Find the problems before the auditor does.
Truvald™ runs automated security assessments across your entire ADCS configuration — CA permissions, template vulnerabilities, key protection, and audit settings — against established PKI security baselines derived from Microsoft guidance and real-world incident patterns.
- ESC1–ESC13 template vulnerability detection
- CA ACL and permission analysis
- Private key protection validation (HSM, software)
- Audit logging completeness checks
- Exportable findings with remediation guidance
Documentation that's actually current.
Most PKI documentation is a Word document someone wrote in 2019 that's been 40% wrong ever since. Truvald™ generates disaster recovery guides from live environment data — the day before you need them, not six months after.
- Live-collected configuration snapshots at generation time
- CA, CEWS, CEPS, and OCSP recovery guides
- Includes certificate chain, gMSA, IIS, and AD configuration details
- PDF export with bilingual (EN/FR) support
- Suitable for audit evidence and DR runbooks
For the CAs nobody can reach.
Air-gapped Root CAs. HSM-protected offline CAs. Servers behind strict network segmentation. The Truvald™ Offline Collector is a standalone executable that runs on any Windows Server — including Server Core — collects environment data, and packages it for import into Truvald™ running elsewhere.
- Zero network requirement — runs fully offline
- Single EXE, no installer, runs on Server Core
- Encrypted data package for secure transport
- Schedulable via batch script for recurring collection
| OS | Windows 10 / Windows Server 2016 or later |
| .NET Runtime | .NET 8 (included in installer) |
| RAM | 4 GB minimum, 8 GB recommended |
| Disk | 500 MB for app + database growth |
| Network | LDAP (389/636) + RPC to CA servers |
| Rights | Domain user; CA Audit / Read recommended |
| OS | Windows Server 2012 R2 or later |
| .NET Runtime | Bundled — no pre-install required |
| RAM | 512 MB available |
| Disk | 50 MB for output package |
| Network | None required (air-gap safe) |
| Rights | Local Administrator or CA Manage CA |
