ambord.tech

PKI work, done by the person who knows it

Four services, one approach: understand what you run today, fix what matters most, and leave your team able to operate it without us.

PKI architecture and operations

For organisations that run their own certificate authorities, or are about to.

Typical work

  • Assessment of an existing PKI: architecture, processes, key protection and documentation
  • Design of new CA hierarchies, including HSM integration and key ceremonies
  • Certificate policies and practice statements (CP/CPS)
  • Hands-on operations support and incident help

What you get

  • A clear picture of your risks, ranked by impact
  • Architecture and policy documents your auditors can follow
  • Runbooks your operations team can actually use

Certificate automation and crypto-agility

For teams facing 100-day certificates in 2027 and a post-quantum roadmap.

Typical work

  • Inventory of certificates, keys and algorithms across your systems
  • Automated issuance and renewal with ACME, EST or cert-manager
  • Crypto-agility review: where changing an algorithm would hurt
  • Post-quantum readiness assessment and migration roadmap

What you get

  • A complete inventory, kept current by automation rather than spreadsheets
  • Renewal processes sized for 100- and 47-day lifetimes
  • A post-quantum roadmap you can present to your supervisor

Kubernetes and DevSecOps security

For platform teams on Kubernetes or OpenShift.

Typical work

  • cert-manager setup and hardening, including private CAs
  • Service mesh and workload identity with mutual TLS
  • CI/CD pipeline security and software supply chain
  • Secrets and key management in GitOps workflows

What you get

  • Security built into how you ship, not a gate at the end
  • Configurations reviewed in Git like the rest of your platform
  • Knowledge transfer to your own engineers

OpenPKI implementation and support

For organisations adopting OpenPKI, the open-core certificate governance layer we build.

Typical work

  • Pilot and production rollout on your clusters
  • Policy and approval workflow design
  • Integration with your existing CAs, HSMs and audit processes

What you get

  • A working deployment, tailored to your policies
  • Support directly from the people who build it
  • Access to the commercial tier for regulated operations

How an engagement works

  1. Call

    A free first conversation about where your PKI hurts and what you need.

  2. Proposal

    A written scope with a fixed price or a clear daily rate, and no surprises.

  3. Delivery

    Hands-on work with your team, with regular check-ins and shared documents.

  4. Handover

    Documentation and knowledge transfer, with ongoing support if you want it.

Tell us where your PKI hurts.

A short call is usually enough to see whether we're the right fit.