Automated Single Sign-On (SSO) certificate rotation. Self-hosted. Zero data egress.

Mārama runs as a scheduled job in your Azure tenant. It rotates SSO certificates before they expire and verifies each rotation before anything breaks.

The problem

SSO certificates are the backbone of any modern enterprise. They expire and need to be rotated in what any IT admin can only describe as a truly painful experience.

A lapsed certificate could result in locking your entire user base out of a critical application, while your IT Team chases support channels that are becoming increasingly harder to reach. This manual process built on email reminders and a constant state of fear is truly overdue for automation.

The solution

Mārama runs as a scheduled job inside your own Azure tenant. It watches certificate expiry across your identity provider, rotates certificates automatically ahead of expiry, and verifies the rotation actually took effect before anything breaks.

Why self-hosted, zero-egress

How it works

  1. Deploy: Use our fully-templated BICEP files to deploy the Azure infrastructure needed to run Mārama
  2. Configure: Declare your SSO-integrated platforms in a version-controlled config file.
  3. Rotate: Mārama checks certificate expiry on a configurable schedule and rotates automatically on your parameters.
  4. Verify: Each rotation is confirmed end-to-end before it's considered complete, and you're notified either way.

Get in touch about the Founder's license.

Contact us