PKISecOPS

The Cryptographic Trust Convergence Platform.

The first platform in the category. You declare the trust state. PKISecOPS keeps every service in it, and proves it.

How it works

One loop, three jobs,
running all the time.

01 · Declare

Write down what must be true.

One short rulebook per type of service. Security writes it.

  • Issuers, key custody, lifetimes, quantum-safe date
  • Versioned, reviewed like any policy
  • Every service inherits it
Trust declarationcustomer-facing APIsv14 · Declared
Applies to312 services
IssuersInternal Root G2 · DigiCert
EncryptionECDSA P-256 now · hybrid ML-KEM from Q2 2027
Key custodyHSM required · no exportable keys
Lifetime30 days · rotate at 20
Quantum-safe byQ4 2027
OwnerSecurity architecture · approved 3 Aug 2026

02 · Converge

Find the gap. Close it.

Compare reality with the rulebook. Fix the difference. Check again.

  • Gaps found in seconds
  • Routine fixes, automatic
  • Anything unusual waits for a person
Convergencecustomer-facing APIs · 312Running
98.4%converged
  • payments-apiConverged · 4 s ago
  • edge-gateway-euRotating key
  • checkout-webChain changed · converging
  • core-ledgerIssuer change · waiting for approval
  • mobile-bffConverged · 11 s ago

03 · Prove

Record what each service is really doing.

Each service is checked from the outside, the way a customer sees it. The record cannot be quietly changed.

  • Audits become queries
  • Migrations proven, service by service
  • Incident reviews replay what was true
Proof of Servingpayments-api · 443Matches declared state
Observed2026-08-30 12:04:31 UTC · 3 vantage points
Presented chainleaf → Issuing CA 2 → Internal Root G2
NegotiatedTLS 1.3 · ECDSA P-256 · X25519
Key custodyHSM-held · attested
Recordsha256:9f2c…e41b · append-only · signed

Guardrails

Routine work, it does on its own.
Anything that matters, it asks first.

You draw the line. It lives in the rulebook.

Does on its own

  • Renews certificates on schedule
  • Installs certificates that were issued but never put to use
  • Replaces keys, inside the storage you approved
  • Repairs a broken certificate chain

Routine, reversible and inside the rules.

Waits for a person

  • Changing who issues your certificates
  • Switching off an encryption method still in use
  • Anything you tag as regulated or critical
  • Anything it cannot verify
  • Anything outside the rules

The person sees the problem, the proposed fix and the evidence.

Never does

  • Hold keys it was not told to hold
  • Act on a service it cannot see
  • Change a record after it is written
  • Give itself more access

These are built in. They cannot be switched off.

Post-quantum

Quantum-safe encryption
becomes a date you set.

  1. Today

    Classical

    Today's encryption (RSA, ECDSA, X25519)

  2. From a date you set

    Hybrid

    Old and new together (ML-KEM, ML-DSA), so nothing breaks

  3. Deadline you set

    Quantum-safe

    Only the new methods. The old ones switched off by rule.

Set the standardper type of service, with a date
Move one area at a timepausing anything a customer's system cannot yet handle
Show where you standwhich services are quantum-safe today

NIST IR 8547 (draft): deprecated after 2030, disallowed after 2035. UK and EU timelines end the same year. Subject to change.

What is inside today

Twelve capabilities. One loop.

Certificate lifecycle and post-quantum migration, converged.

  • DiscoveryEvery certificate, key and service you have.
  • Certificate lifecycleIssue, renew, install, revoke. By the rules.
  • Trust chainsEvery chain back to a root the world trusts.
  • Quantum-readiness inventoryWhich services a quantum computer could break, and where.
  • Key custodyKeys in your vault, replaced on schedule.
  • MonitoringAnything that no longer matches the rules.
  • Private CAInternal certificates, issued by the same rules.
  • Post-quantum migrationQuantum-safe by the date you set.
  • Proof of ServingTamper-proof record of what was really served.
  • Approvals and holdsImportant changes wait for a person.
  • ReportingAnswers for boards, regulators and auditors.
  • IntegrationsThe CAs, clouds, key vaults and ticketing you already run.

Architecture

Sits on what you have.
Replaces nothing.

You set the rules

RulebooksApprovalsQuantum-safe dates

PKISecOPS checks, fixes and proves

DiscoveryCheckingFixingGuardrailsProof of ServingReporting

Your infrastructure, as it is

Public CAsPrivate CAsHSMs and cloud KMSLoad balancersAWS · Azure · Google CloudKubernetesSecrets managersCI/CDDevice fleetsITSMSIEM and SOAR

Cloud, your data center or fully offline. Data stays inside your borders. Usually nothing to install.

Roadmap

What is live, and what is next.

  1. Certificate lifecycle

    Every public and private certificate, kept inside your rules.

    Live now
  2. Post-quantum migration

    Every service moved on schedule, through the same loop.

    Live now
  3. Machine identity and cryptographic posture

    The next two parts of the category, on the same platform.

    In build
  4. Advanced security

    Extra safeguards around how certificates and keys are handled.

    Q3 2026
  5. Reporting for leaders

    Risk and readiness in plain terms, for operators and executives.

    Q4 2026
  6. Ask it questions

    Plain-English questions about your trust state, and actions on the answer.

    Q1 2027

Questions buyers ask

The four we hear first.

Is this just another certificate management tool?

Certificate lifecycle is one part of the category. Convergence also covers machine identity, cryptographic posture and post-quantum migration.

Do we need a separate post-quantum project?

No. Quantum-safe is a date in the same rulebook. Each service gets there through its normal lifecycle.

What happens to the certificate authorities we already use?

They stay. PKISecOPS works with the ones you already trust, public and private.

How is the evidence stored?

Where you run the platform. Signed, tamper-proof, exportable in open formats, verifiable without us.

See it run on your own systems.

One type of service. Declared, converged, proven.