
AppViewX AVX ONE CLM
Automated certificate lifecycle has reduced audits and improved compliance across platforms
What is our primary use case?
My main use case for AppViewX CERT+ is certificate life cycle management. We use AppViewX CERT+ to integrate with various platforms to rotate certificates on a periodic manner to ensure that the processes related to certificates are met.
What is most valuable?
The best features that AppViewX CERT+ offers include a wide variety of integrations with various tech stacks such as firewalls and its simplicity and straightforward nature of use.
I love the integrations with the firewall platforms and the HSMs, as they integrate well with third-party HSMs such as Fortanix, which makes it easier to adhere to all the FIPS regulations.
AppViewX CERT+ has positively impacted our organization by helping us to remediate many audits in a better manner. In a recent audit, we were lacking in CLM capabilities, and introducing AppViewX CERT+ helped us adhere to the majority of the audit findings and seamlessly rotate certificates, renew certificates, and meet all the requirements on time.
What needs improvement?
Sometimes the new features need to be amplified more, as I feel they are underplayed, and I think there should be more integrations that need to be done first of its kind for the tool.
For how long have I used the solution?
I have been using AppViewX CERT+ for over seven years.
What do I think about the stability of the solution?
AppViewX CERT+ is stable.
What do I think about the scalability of the solution?
AppViewX CERT+ is scalable, and it can be done in a very fast manner, as the team is effective in what they do.
How are customer service and support?
The customer support is impressive; I work with all stakeholders, including the CEO, and it is a very responsive team. I would rate the customer support as a nine out of ten.
What was our ROI?
We have seen a return on investment, as we had reduced our team strength, which significantly improved our ROI.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it depends on negotiation, and we negotiated effectively, feeling that the pricing fits within our budget compared to other vendors such as Thales.
Which other solutions did I evaluate?
Before choosing AppViewX CERT+, I evaluated other options, such as Venafi.
What other advice do I have?
I would rate AppViewX CERT+ as a solid ten out of ten. I chose ten because the team is effective in what they do, and the full scope of improvement is pretty niche, but they excel in their offerings.
Regarding AppViewX CERT+'s AI capabilities, they adhere to all the basic AI-related requirements, and they integrate in such a way with HSMs that not everything is compromised if something goes wrong, ensuring proper segregation of duty. In terms of accuracy and reliability of output, AppViewX CERT+ is accurate in whatever basic offering it provides, which we can consider to be sufficient for the current state of AI adoption.
My advice to others looking into using AppViewX CERT+ is to leverage the solution more and ensure that all the respective tech stacks are integrated with it, as it can help reduce the number of man-hours needed for certificate life cycle management. My overall rating for AppViewX CERT+ is ten.
Certificate lifecycle automation has reduced expiry incidents and now supports self-service requests
What is our primary use case?
My main use case for AppViewX CERT+ is certificates lifecycle management. A specific example of how I use AppViewX CERT+ in my daily operations is for certificate signing, both internal and public certificates, and also for notifying certificates expirations to business owners and the IT team.
What is most valuable?
The best features AppViewX CERT+ offers, in my opinion, are the easy way of implementing it and the stability that the solution has. It is also very flexible. When we need to change something in the process, it is quite flexible for that adjustment as well.
AppViewX CERT+ has positively impacted our organization by helping us significantly with certificate expirations. Before AppViewX CERT+, we had many issues with not renewing certificates in time. With AppViewX CERT+, we receive expiration notifications in advance, so the process of certificate expiration is now much more reliable. It also helped us make the process of requesting new certificates much more reliable and easy for users; they can request certificates directly through AppViewX CERT+ interface and it is quite fast. It is a self-request for the users; they can do it themselves.
What needs improvement?
The main area that could be improved about AppViewX CERT+ is the support; support could be better and the engagement of the commercial team. They could improve on being more close to the customer to understand the needs of the customer, what the customer can improve or if the customer has things licensed that are not being used. On the support side, having local support in our case will be much better, to have someone that helps us solve issues faster. Currently we are having a couple of issues with the solution and those resolutions are being very slow, so that could be improved.
I mostly wish improvements related to support. They also lack the possibility of signing public certificates by their own, so you depend on other public certificate authorities; that is one thing that could be improved in the product.
For how long have I used the solution?
What do I think about the stability of the solution?
A time when I needed to make changes or adjustments and how AppViewX CERT+ handled it smoothly was when we needed to create flows for internal people so they could request certificates by themselves, and we needed to customize those flows, which was quite easy to do with the solution.
What do I think about the scalability of the solution?
AppViewX CERT+ scalability can handle our growing needs easily.
How are customer service and support?
Regarding customer support, I would say that customer support is not good; they have a ticketing system with people that take your tickets and solve your issues, but it takes a lot of time and it is not personalized for the customers.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before AppViewX CERT+.
What was our ROI?
I do not have specific metrics regarding return on investment, but I would say that it helped us achieve approximately 50% cost reduction on people and systems broken because of expired certificates.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for AppViewX CERT+ was good; the costs are acceptable and the licensing is quite clear.
Which other solutions did I evaluate?
Before choosing AppViewX CERT+, I evaluated Keyfactor.
What other advice do I have?
I would advise others looking into using AppViewX CERT+ to go direct to the cloud, to the software-as-a-service architecture, and also to have a local partner for support. I would rate this solution an 8 out of 10.
AppViewX CLM tool
Automation has transformed certificate lifecycle tasks and saves significant operational time
What is our primary use case?
The main use case of using AppViewX CERT+ is for the automation of certificate lifecycle management for my application.
What is most valuable?
I have integrated AppViewX CERT+ with different public certificate providers as well as my private PKI internal infrastructure. AppViewX CERT+ automatically fetches new certificates from the respective public CA or private CA and pushes that certificate to the target endpoint. It also provides real-time notifications based on email, so whenever the certificate is updated or the certificate update job fails, it alerts me via email with the status. This makes it very easy to track down.
AppViewX CERT+ has a wide variety of integration support for different public CAs as well as internal PKI environments. It supports all types of notifications based on the requirement, such as notifications based on certificate status or job status via email. It also supports integration with external ticketing tools. If you are using ServiceNow or any remedy tool for ticketing, you can integrate that with AppViewX CERT+ portal or platform. Whatever changes happen through the automation jobs, the portal or platform sends a request to the ticketing tool to create the ticket against it. Therefore, administration or operations becomes much easier to track changes.
The best feature I appreciate is that AppViewX CERT+ supports different endpoints where the application or certificates need to be updated, such as Windows, Linux, different firewall vendors, cloud platforms such as Akamai and Salesforce, and load balancers such as F5 and Citrix. AppViewX CERT+ supports the majority of all the endpoints for integration, which is one of the best features. You do not need to depend on different platforms for managing various vendors. AppViewX CERT+ becomes centralized for all kinds of endpoints for certificate lifecycle management.
The best outcome is that it is saving human hours. My engineers' time is saved, allowing them to use that time for other proactive work. Human error is minimized, so there are very few chances of impact due to misconfiguration or misapplying the certificate. As my human hours are saved, it also positively impacts the overall efficiency of my team and operations. It is very easy to track down. You can fetch the report of the past month to see how many certificates were updated and their status, making auditing much easier.
I have almost more than 100 applications where I need to update certificates. If you consider one certificate, generating it and applying it on the endpoint takes a minimum of 45 minutes to one hour. If you calculate that multiplied by 100 or more, that much time is consumed for updating all those certificates. During manual updates, if any impact or issue occurs due to human error, additional troubleshooting time is required. You can sense how much time we are saving by using AppViewX CERT+ for automation with no human intervention required.
What needs improvement?
Recently, every customer must have seen that AWS has added their feature or support for public CA signed certificates, allowing you to use AWS signed certificates for your applications hosted on the internet. Earlier that support was not there, and when we compare the cost of the AWS provided certificates with other vendors, they are very much cheaper, almost 20% to 25% of the costs of others. Many customers have started moving to AWS provided public certificates. However, I do not see that AppViewX CERT+ currently supports AWS public CA for certificate integration and automation, which is something they can add. I believe their engineering team is already working on it, and I am still waiting for their update.
For how long have I used the solution?
I have been using AppViewX CERT+ for more than three years now.
What do I think about the stability of the solution?
Overall, I am very satisfied with the platform and how it works. There is no downtime on the platform, and even when there are vulnerabilities or patch updates, it is very straightforward, less time-consuming, and highly reliable. I am very satisfied with the platform.
What do I think about the scalability of the solution?
The overall features and the way it works make AppViewX CERT+ a very reliable platform with fewer issues. The jobs function and the implementation happen as per the configuration done and the plan, leading to fewer issues. I have never seen any kind of problems with the platform. It runs very smoothly, and overall, I am very satisfied with the platform.
What other advice do I have?
I have almost more than 100 applications where I need to update certificates. If you consider one certificate, generating it and applying it on the endpoint takes a minimum of 45 minutes to one hour. If you calculate that multiplied by 100 or more, that much time is consumed for updating all those certificates. During manual updates, if any impact or issue occurs due to human error, additional troubleshooting time is required. You can sense how much time we are saving by using AppViewX CERT+ for automation with no human intervention required.
The only thing I hope for is that whenever a new CA comes into the market, AppViewX CERT+ will release support for that new CA very soon.
I would recommend that if you have multiple applications requiring SSL certificates updated every month, and you observe human errors that could create significant impacts on your organization's applications, you should definitely consider an automation tool. AppViewX CERT+ is one of the great tools based on my usage over the last three years. It is going to definitely increase your team's operational efficiency, and you should consider this product for evaluation.
I gave this review a rating of 10. Overall, it is very good with relevant questions. One suggestion is to add a few more questions in future reviews regarding platform deployment strategies followed by other customers. If that is included in the review, it would be very useful for other customers evaluating the product.
Automated Certificate Management Made Easy
Automation has streamlined certificate workflows and reduced human errors significantly
What is our primary use case?
My main use case for AppViewX CERT+ includes three business cases that I can explain. For internal websites that we have in the company, we share with the business and provide because we need to be completely secure with this environment. Each business owner and developers request internal certificates. We now have a workflow that they can request from our management tool. They request the certificate and then the certificate team, with AppViewX CERT+, generates the certificate for them and pushes them directly to the server where it's deployed without requiring anything on their side.
The second case is for public certificates, all the websites and SaaS environment that we use, which we provide to the business and external clients. This workflow differs because it involves public certificates approved by our public authority. This process is closely tied to the business as they need to ensure certificate validity, especially when planning to move URLs or stop services within six to eight months, due to associated costs. The process is similar to internal websites but requires change management for production. The process varies depending on whether the SaaS application is in our cloud environment or managed by a provider. In both cases, we create the certificate with AppViewX CERT+, generate it, verify DNS entries for public authority validation, and then either push it ourselves if we manage the backend or coordinate with the provider to implement it.
The third business case involves application and mobile application coding. We have specific workflows and certificate possibilities that are highly integrated with the automation process, especially for APIs. Our developers create numerous APIs for clients, ranging from two or three per month to sometimes more than 100. We have created an automation process that generates certificates for varying periods depending on API requirements.
What is most valuable?
We have been using AppViewX CERT+ for more than a year and are really happy with the solution, including their business services and the development of our company workflows. It has helped reduce latency in certificate requests from business and application owners while providing numerous security solutions.
AppViewX CERT+ offers many possibilities, including the ability to send notifications when certificates are approaching expiration to app owners. The solution also provides extensive integration capabilities with various components and device types, such as pushing certificates directly to NetScaler or creating certificates in Azure automatically. These features significantly reduce our workload in certificate management.
The automation is the best feature, along with their business-focused development. Compared to other solutions we tested, AppViewX CERT+ stands out. Though not a public authority itself, it works with them, offering similar capabilities to DigiCert, our new public authority. AppViewX CERT+ excels not only in managing and generating certificates but also in creating workflows and offering multiple workflow options for different business cases.
What needs improvement?
We have discussed with them the need for better integration with APIs, including specific definitions and business cases. We would benefit from templates for specific APIs that need to connect with external vendors or integrate directly with our backend. This feature is currently in their development pipeline.
Another improvement area is the integration with automation, specifically simplifying the ACME services they offer to work without an agent. Currently, every backend machine requires an agent for ACME services. This improvement will become crucial in the next two years when public certificates must be reduced from one year to 47 days, which presents a significant challenge for us.
For how long have I used the solution?
We use AppViewX CERT+ for more than a year.
What do I think about the stability of the solution?
AppViewX CERT+ is completely stable because we use their cloud solution and they are everywhere. The scalability extends to the agents we have on our backend, and we have these agents on multiple data centers, making it available and scalable everywhere.
What do I think about the scalability of the solution?
AppViewX CERT+ is completely stable because we use their cloud solution and they are everywhere. The scalability extends to the agents we have on our backend, and we have these agents on multiple data centers, making it available and scalable everywhere.
How are customer service and support?
On a scale of one to 10, I would give AppViewX CERT+ customer support a nine.
Which solution did I use previously and why did I switch?
Before choosing AppViewX CERT+, we did not use a solution. While I evaluated other options, I cannot recall the specific solution we considered. It was somewhat similar but was completely cloud-based, which is not permitted in financial markets.
How was the initial setup?
My experience with pricing, setup cost, and licensing was really good. It was defined as a project and all the mandatory dates were expected and followed correctly. We had no issues with them and the discussion was really productive.
What about the implementation team?
We have sufficient engineers in this company to help us with deployment and troubleshooting if something goes wrong with the flow that needs to be opened on our side.
What was our ROI?
We have seen a return on investment with AppViewX CERT+ through reduced costs in human resources. The time spent on certificate services and deploying new certificates was significantly reduced due to automation. This has benefited the business as we are only a few people managing numerous certificate requests, including nighttime requests.
The current process is much simpler compared to our previous complex process that required connecting to different environments. With full backend integration, users simply follow the workflow and the certificate is deployed correctly. This efficiency saves time and money, which is particularly important in a financial company where time directly correlates to costs.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was really good. It was defined as a project and all the mandatory dates were expected and followed correctly. We had no issues with them and the discussion was really productive.
Which other solutions did I evaluate?
I evaluated other options before choosing AppViewX CERT+, but I cannot recall the specific solution we considered. It was somewhat similar but was completely cloud-based, which is not permitted in financial markets.
What other advice do I have?
I recommend AppViewX CERT+ for organizations needing a solution that can create workflows to provide more control and management. The tool is easy to understand for anyone with minimal knowledge of certificates. The management capabilities, including permission controls for business users to approve or request certificates, make it highly recommendable for those seeking a solution to manage workflows while maintaining certificate control. Based on my experience, I rate AppViewX CERT+ a 9 out of 10.
Communications with Appviewx team
Real time saver!
The possibility to see and manage my companys external certificates in one place.
Quick turnaround and easy to get support
AppviewX Platform Boosts Our Infrastructure as Code Strategy
The user portal is remarkably responsive, providing a seamless experience whether you are navigating through its various features or managing certificates. The interface is well-designed, ensuring that even those with minimal technical knowledge can easily find their way around.
Moreover, AppViewX Cert+ excels in proactive alerting and historical reporting. The platform constantly monitors for any issues and promptly alerts users, helping to prevent potential disruptions before they occur. Additionally, its comprehensive historical reporting features give users a detailed view of past activities and trends, enabling better planning and decision-making.
Overall, AppViewX Cert+ is an exceptional tool for anyone looking to streamline their certificate management processes, backed by an efficient setup, a responsive user experience, and proactive alerting and historical reporting capabilities.