PKI work, done by the person who knows it
Four services, one approach: understand what you run today, fix what matters most, and leave your team able to operate it without us.
PKI architecture and operations
For organisations that run their own certificate authorities, or are about to.
Typical work
- Assessment of an existing PKI: architecture, processes, key protection and documentation
- Design of new CA hierarchies, including HSM integration and key ceremonies
- Certificate policies and practice statements (CP/CPS)
- Hands-on operations support and incident help
What you get
- A clear picture of your risks, ranked by impact
- Architecture and policy documents your auditors can follow
- Runbooks your operations team can actually use
Certificate automation and crypto-agility
For teams facing 100-day certificates in 2027 and a post-quantum roadmap.
Typical work
- Inventory of certificates, keys and algorithms across your systems
- Automated issuance and renewal with ACME, EST or cert-manager
- Crypto-agility review: where changing an algorithm would hurt
- Post-quantum readiness assessment and migration roadmap
What you get
- A complete inventory, kept current by automation rather than spreadsheets
- Renewal processes sized for 100- and 47-day lifetimes
- A post-quantum roadmap you can present to your supervisor
Kubernetes and DevSecOps security
For platform teams on Kubernetes or OpenShift.
Typical work
- cert-manager setup and hardening, including private CAs
- Service mesh and workload identity with mutual TLS
- CI/CD pipeline security and software supply chain
- Secrets and key management in GitOps workflows
What you get
- Security built into how you ship, not a gate at the end
- Configurations reviewed in Git like the rest of your platform
- Knowledge transfer to your own engineers
OpenPKI implementation and support
For organisations adopting OpenPKI, the open-core certificate governance layer we build.
Typical work
- Pilot and production rollout on your clusters
- Policy and approval workflow design
- Integration with your existing CAs, HSMs and audit processes
What you get
- A working deployment, tailored to your policies
- Support directly from the people who build it
- Access to the commercial tier for regulated operations
How an engagement works
Call
A free first conversation about where your PKI hurts and what you need.
Proposal
A written scope with a fixed price or a clear daily rate, and no surprises.
Delivery
Hands-on work with your team, with regular check-ins and shared documents.
Handover
Documentation and knowledge transfer, with ongoing support if you want it.
Tell us where your PKI hurts.
A short call is usually enough to see whether we're the right fit.