Your PKI, operated and supported.
Keep your certificate infrastructure secure and operational without carrying it alone.
Running a PKI is not a one-off project. Certificates expire, CRLs need publishing, OCSP responders need monitoring, and someone needs to answer the 02:00 page when a CA service goes down. We provide ongoing operations and support for your PKI, whether we built it or inherited it, so your team can focus on everything else.
What we handle
The day-to-day work that keeps a PKI healthy, and the 02:00 calls that nobody volunteers for.
Continuous monitoring
CA availability, OCSP responder health, CRL freshness and certificate expiry horizons, monitored 24/7 with alerts before things break.
Certificate lifecycle
Renewal automation, revocation handling, new issuance for services and accounts. The full lifecycle managed so nothing expires silently.
Incident response
When a CA service goes down or a certificate is compromised, we respond with the runbook, the access and the experience to resolve it fast.
Key ceremony & rotation
Planned root or intermediate key rotations executed under controlled conditions. Full ceremony documentation for audit.
Compliance evidence
NIS2, eIDAS and CA/B BR evidence collected continuously. Your auditor gets a query result, not a three-week waiting period.
Quarterly health checks
A structured review every quarter: cryptographic posture, certificate inventory, trust hierarchy and operational metrics, documented and delivered.
Infrastructure maintenance
Patching, upgrades and configuration drift correction for EJBCA, OCSP responders, HSMs and the surrounding stack.
Architecture evolution
As your environment grows, we advise on trust hierarchy changes, new enrolment protocols and post-quantum readiness before they become urgent.
Stop carrying your PKI alone
Whether you need full managed operations or just a safety net for your internal team, we tailor the engagement to your needs. You keep visibility and control. We handle the repetitive work, the 02:00 calls and the audit evidence.