Hexure incident
FireLight Staging Certificate Renewal
Hexure experienced a minor incident on October 2, 2026, lasting —. The incident has been resolved; the full update timeline is below.
Update timeline
- monitoring Sep 22, 2026, 12:55 PM UTC
**FireLight Staging Certificate Will Expire Friday, October 2, 2026** This is a reminder that the FireLight staging certificate will expire Friday, October 2, 2026. The FireLight staging certificate is used to secure communication between the browser and FireLight servers. If and how this affects you will depend on how you use the certificate. Please work with your internal network team to determine how your organization is using the certificate, which will determine what steps your organization needs to take. **Certificate Usage** The certificate is used to secure the connection between FireLight and the client’s browser. The certificate is used by some of our clients to encrypt the payload of the SSO request into FireLight. The certificate is used to secure the connection between FireLight and the client’s back-office systems. **Questions to Ask Internal Network Team** Are we encrypting the SSO payload into FireLight with FireLight’s certificate? They can use the certificate information listed below in their investigation. Do our servers receive requests from FireLight through a web service, or do our servers send information to FireLight? If so, do our servers require the domain’s certificate to be loaded on the server? **Steps to Take Based on Usage** We are not encrypting SSO payload with the certificate and no requirement to have the certificate on servers. No action is needed. Your server(s) and your advisor’s workstations will automatically use the new certificate without any intervention. Encrypting SSO payload with the certificate. Work with your internal network team to install the public key certificate on all servers generating the encrypted payload for FireLight. Transition over to using the new certificate before October 2, 2026. Using FireLight web services or receiving FireLight data through a web service AND your servers require the domain certificate to be installed on the servers. Work with your internal network team to install the public key on all servers communicating with FireLight. Transition over to using the new certificate before October 2, 2026. **Key Dates** September 15 - Hexure purchased the certificate. September 24– The certificate will be available for use. October 1, 2026 – Transition to the new certificate for SSL encryption. October 2, 2026 – Transition to the new certificate must be completed. November 2, 2026 – The old certificate will be removed from servers by Hexure. **Public Key** The public key for this certificate is now available. [Public Key](https://uat.firelighteapp.com/EGAdmin/SecureDocument/GetDocument?docname=2.48%2Fstaging-firelighteapp-com-202609-202703%201.zip) **Summary of Certificates** For information about the existing certificate please reference the FireLight Certificate Usage and Summary of Certificates document. [FireLight Certificate Usage Summary](https://uat.firelighteapp.com/EGAdmin/SecureDocument/GetDocument?docname=2.48%2FFireLight%20Certificate%20Usage%20%20Summary_Oct2026.pdf) If you have any questions regarding this certificate renewal, please submit a Jira Support ticket, and a Hexure team member will assist you.
- monitoring Oct 01, 2026, 09:40 PM UTC
**FireLight Staging Certificate Will Expire Tomorrow, Friday, October 2, 2026 ** This is a reminder that the FireLight staging certificate will expire tomorrow, Friday, October 2, 2026. The FireLight staging certificate is used to secure communication between the browser and FireLight servers. If and how this affects you will depend on how you use the certificate. Please work with your internal network team to determine how your organization is using the certificate, which will determine what steps your organization needs to take. **Certificate Usage** The certificate is used to secure the connection between FireLight and the client’s browser. The certificate is used by some of our clients to encrypt the payload of the SSO request into FireLight. The certificate is used to secure the connection between FireLight and the client’s back-office systems. **Key Dates** **September 15, 2026** - Hexure purchased the certificate. **September 24, 2026**– The certificate will be available for use. **October 1, 2026** – Transition to the new certificate for SSL encryption. **October 2, 2026 ** – Transition to the new certificate must be completed. **November 2, 2026** – The old certificate will be removed from servers by Hexure. **Public Key** The public key for this certificate is now available. [Public Key](https://uat.firelighteapp.com/EGAdmin/SecureDocument/GetDocument?docname=2.48%2Fstaging-firelighteapp-com-202609-202703%201.zip) **Summary of Certificates** For information about the existing certificate please reference the FireLight Certificate Usage and Summary of Certificates document. [FireLight Certificate Usage Summary](https://uat.firelighteapp.com/EGAdmin/SecureDocument/GetDocument?docname=2.48%2FFireLight%20Certificate%20Usage%20%20Summary_Oct2026.pdf) If you have any questions regarding this certificate renewal, please submit a Jira Support ticket, and a Hexure team member will assist you.
- monitoring Oct 02, 2026, 06:00 AM UTC
**FireLight Staging Certificate Will Expire Friday, October 2, 2026.** The FireLight staging certificate is used to secure communication between the browser and FireLight servers. Some organizations may also use the certificate to secure the SSO request into the environment, or to establish a secure communication between FireLight servers and back-office systems, or front-office systems into FireLight web service endpoints. If and how this affects you will depend on how you are using the certificate. Please work with your internal network team to determine how your organization is using the certificate, which will determine what steps your organization needs to take. To help, we have documented questions to ask your internal network team and the potential steps to take based on your usage of the certificate. **Certificate Usage** The certificate is used to secure the connection between FireLight and the client’s browser. The certificate is used by some of our clients to encrypt the payload of the SSO request into FireLight. The certificate is used to secure the connection between FireLight and the client’s back-office systems. **Questions to Ask Internal Network Team** Are we encrypting the SSO payload into FireLight with FireLight’s certificate? They can use the certificate information listed below in their investigation. Do our servers receive requests from FireLight through a web service, or do our servers send information to FireLight? If so, do our servers require the domain’s certificate to be loaded on the server? **Steps to Take Based on Usage** We are not encrypting SSO payload with the certificate and no requirement to have the certificate on servers. No action is needed. Your server(s) and your advisor’s workstations will automatically use the new certificate without any intervention. Encrypting SSO payload with the certificate. Work with your internal network team to install the public key certificate on all servers generating the encrypted payload for FireLight. Transition over to using the new certificate before October 2, 2026. Using FireLight web services or receiving FireLight data through a web service AND your servers require the domain certificate to be installed on the servers. Work with your internal network team to install the public key on all servers communicating with FireLight. Transition over to using the new certificate before October 2, 2026. **Timeline** The new staging certificate was purchased by Hexure on September 15, 2026 and will be available for use on staging on September 17, 2026. Clients can use the new or old certificate for encryption of the SSO payload (usage 2). We will continue to use the old certificate for usages 1 and 3 until the old certificate **expires on October 2, 2026.** **Key Dates** September 15, 2026 - Hexure purchased the certificate. [September 24, 2026 – The certificate will be available for use. October 1, 2026 – Transition to the new certificate for SSL encryption. October 2, 2026 – Transition to the new certificate must be completed. November 2, 2026 – The old certificate will be removed from servers by Hexure. **Public Key** The public key for this certificate is now available. [Public Key](https://uat.firelighteapp.com/EGAdmin/SecureDocument/GetDocument?docname=2.48%2Fstaging-firelighteapp-com-202609-202703%201.zip) **Summary of Certificates** For information about the existing certificate please reference the FireLight Certificate Usage and Summary of Certificates document. [FireLight Certificate Usage Summary](https://uat.firelighteapp.com/EGAdmin/SecureDocument/GetDocument?docname=2.48%2FFireLight%20Certificate%20Usage%20%20Summary_Oct2026.pdf) If you have any questions regarding this certificate renewal, please submit a Jira Support ticket, and a Hexure team member will assist you.