Skip to content

Create your account

Signing up takes a work email address, and every new organization starts on a 14-day Business trial.

Go to app.nocert.io and select Create an account.

Tick the consent box, which covers the terms, the privacy policy, the data processing agreement, business use, and your authority to scan your company’s assets.

Enter the 6-digit code that arrives by email. It expires after 20 minutes.

Your organization is named after your email domain. Rename it in Settings → Organization.

NoCert only accepts work addresses at signup. Consumer webmail and disposable domains are refused, which covers Gmail, Outlook, Yahoo, iCloud, Proton, Fastmail, and large national ISPs like free.fr, orange.fr and web.de.

Your first scan is built from the domain in your email address, so a shared webmail domain would point NoCert at a zone you don’t own.

If your company genuinely uses a blocked domain, contact us rather than signing up with a personal address.

No. Accounts are created without one, and you sign in with a fresh code each time.

You can set a password later in Settings → Profile, which asks for a new code to confirm. Do that first if you want two-factor authentication: NoCert refuses to enable 2FA on an account with no password. Neither is mandatory, but both sit on the owner’s setup checklist.

Your organization starts on the Business trial. NoCert adds the domain from your email address, leaves it unverified, and runs one discovery pass over it: the apex, a list of common subdomain names, and what public hostname datasets know about it. The first certificates land in Certificates on their own.

You also get an email notification target addressed to you, and a set of notification rules attached to it:

  • Default Rule, at 7 days before expiry. It cannot be deleted or disabled.
  • Three examples you can delete: CA certificate expiry (90 days), Staging certificates (30 days) and Wildcard certificates (10 days).

Those three are enabled and will mail you. Delete the ones that don’t match how you work.

A compliance policy set is chosen from the country you signed up from, always including the Mozilla baseline.

That first pass finds what is reachable today, and NoCert keeps those endpoints refreshed afterwards. What verification adds is going back for more: repeat subdomain enumeration, hostnames a DNS connector found, and endpoints you add by hand. Monitor your first domain covers it.

Sending them to the signup page puts them in a separate organization, even on the same company domain, and the two will not see each other’s certificates.

An owner adds them instead, from Settings → Local Users.

Every Business feature is live during the trial, within the plan’s usage limits, including single sign-on and the compliance workspace. The days remaining show in a strip at the top of the app.

When the trial ends, NoCert stops monitoring and the organization goes read-only. You can still read and export your certificates, but changes are refused: no new domains, no scans, no discovery, no alerts. Your own account settings and Settings → Billing keep working, and the compliance evidence export stops with the rest of the Business features.

Read-only lasts 30 days. After that the organization and its data are deleted.

Activating a plan from Settings → Billing starts billing immediately and ends the trial.