Build PKI you can trust for years.
Production-grade PKI designed around security, resilience and automation.
PKI is easy to deploy. Getting it right is harder.
A certificate authority becomes critical infrastructure the moment your applications, devices, identities and services depend on it.
Poor architecture creates long-term problems: exposed keys, unreliable revocation, difficult renewals, operational dependencies and costly migrations.
We design the trust infrastructure before those problems become yours.
The approach
From trust architecture to production
Rather than dropping in a CA and walking away, we take the entire lifecycle into account.
Architecture
We define the CA hierarchy, trust model, cryptography, revocation strategy and operational boundaries before any keys are generated.
Implementation
We build the root and issuing infrastructure, integrate the required services, and establish secure key management with HSM backing.
Automation
We connect issuance, renewal, deployment and revocation to the systems that depend on certificates via ACME and REST.
Handover
You receive the documentation, runbooks and operational knowledge needed to run the environment confidently.
Your PKI should not become the next legacy system you have to replace. Designed for production. Built for long-term operation.
What you get
A PKI foundation your infrastructure can depend on
Secure CA architecture
Offline roots and controlled issuing infrastructure designed around your risk profile.
Reliable certificate validation
OCSP, CRL and AIA services designed for dependable certificate lifecycle operations.
Protected keys
Modern cryptography (ECDSA P-384 / SHA-512) and HSM integration where required.
Operational readiness
Automation, documentation, runbooks and a clear path into production.
Process
Five steps from architecture to operation
Assess
Map trust anchors, certificate profiles and consuming services.
Design
Define hierarchy, cryptography, revocation and operational boundaries.
Build
Deploy root and issuing CA with HSM-backed keys and OCSP.
Integrate
Wire ACME, REST, Salt and Vault into your existing systems.
Operate
Hand over runbooks, quarterly health checks and ongoing support.
Technology
The stack we deploy
Every component runs in our own production lab and has been validated against real workloads, not just product brochures.
Certificate Authority
EJBCA cluster (active/active behind HAProxy) with MariaDB Galera. Sub-second OCSP. Stable for years.
Cryptography
ECDSA P-384 with SHA-512 signatures as the modern baseline. RSA only when legacy clients require it.
Hardware security
HSM integration for tiers where keys must never be extractable. SoftHSM2 for development.
Validation authority
OCSP responder co-located or peered. CRL published over HTTP per RFC 5280. AIA paths verified.
Enrolment protocols
ACME for web-server certificates, REST for service accounts, CMP/SCEP for legacy clients.
Compliance & audit
Audit-ready logging, retention policy and evidence collection. NIS2 Article 21 from day one.
Ready to build PKI properly?
Starting from scratch, replacing legacy infrastructure, or strengthening an existing environment: we can help.