PKISecOPS
The Cryptographic Trust Convergence Platform.
The first platform in the category. You declare the trust state. PKISecOPS keeps every service in it, and proves it.
How it works
One loop, three jobs,
running all the time.
01 · Declare
Write down what must be true.
One short rulebook per type of service. Security writes it.
- Issuers, key custody, lifetimes, quantum-safe date
- Versioned, reviewed like any policy
- Every service inherits it
02 · Converge
Find the gap. Close it.
Compare reality with the rulebook. Fix the difference. Check again.
- Gaps found in seconds
- Routine fixes, automatic
- Anything unusual waits for a person
- payments-apiConverged · 4 s ago
- edge-gateway-euRotating key
- checkout-webChain changed · converging
- core-ledgerIssuer change · waiting for approval
- mobile-bffConverged · 11 s ago
03 · Prove
Record what each service is really doing.
Each service is checked from the outside, the way a customer sees it. The record cannot be quietly changed.
- Audits become queries
- Migrations proven, service by service
- Incident reviews replay what was true
Guardrails
Routine work, it does on its own.
Anything that matters, it asks first.
You draw the line. It lives in the rulebook.
Does on its own
- Renews certificates on schedule
- Installs certificates that were issued but never put to use
- Replaces keys, inside the storage you approved
- Repairs a broken certificate chain
Routine, reversible and inside the rules.
Waits for a person
- Changing who issues your certificates
- Switching off an encryption method still in use
- Anything you tag as regulated or critical
- Anything it cannot verify
- Anything outside the rules
The person sees the problem, the proposed fix and the evidence.
Never does
- Hold keys it was not told to hold
- Act on a service it cannot see
- Change a record after it is written
- Give itself more access
These are built in. They cannot be switched off.
Post-quantum
Quantum-safe encryption
becomes a date you set.
Today
Classical
Today's encryption (RSA, ECDSA, X25519)
From a date you set
Hybrid
Old and new together (ML-KEM, ML-DSA), so nothing breaks
Deadline you set
Quantum-safe
Only the new methods. The old ones switched off by rule.
NIST IR 8547 (draft): deprecated after 2030, disallowed after 2035. UK and EU timelines end the same year. Subject to change.
What is inside today
Twelve capabilities. One loop.
Certificate lifecycle and post-quantum migration, converged.
- DiscoveryEvery certificate, key and service you have.
- Certificate lifecycleIssue, renew, install, revoke. By the rules.
- Trust chainsEvery chain back to a root the world trusts.
- Quantum-readiness inventoryWhich services a quantum computer could break, and where.
- Key custodyKeys in your vault, replaced on schedule.
- MonitoringAnything that no longer matches the rules.
- Private CAInternal certificates, issued by the same rules.
- Post-quantum migrationQuantum-safe by the date you set.
- Proof of ServingTamper-proof record of what was really served.
- Approvals and holdsImportant changes wait for a person.
- ReportingAnswers for boards, regulators and auditors.
- IntegrationsThe CAs, clouds, key vaults and ticketing you already run.
Architecture
Sits on what you have.
Replaces nothing.
You set the rules
PKISecOPS checks, fixes and proves
Your infrastructure, as it is
Cloud, your data center or fully offline. Data stays inside your borders. Usually nothing to install.
Roadmap
What is live, and what is next.
- Certificate lifecycle
Every public and private certificate, kept inside your rules.
Live now - Post-quantum migration
Every service moved on schedule, through the same loop.
Live now - Machine identity and cryptographic posture
The next two parts of the category, on the same platform.
In build - Advanced security
Extra safeguards around how certificates and keys are handled.
Q3 2026 - Reporting for leaders
Risk and readiness in plain terms, for operators and executives.
Q4 2026 - Ask it questions
Plain-English questions about your trust state, and actions on the answer.
Q1 2027
Questions buyers ask
The four we hear first.
Is this just another certificate management tool?
Certificate lifecycle is one part of the category. Convergence also covers machine identity, cryptographic posture and post-quantum migration.
Do we need a separate post-quantum project?
No. Quantum-safe is a date in the same rulebook. Each service gets there through its normal lifecycle.
What happens to the certificate authorities we already use?
They stay. PKISecOPS works with the ones you already trust, public and private.
How is the evidence stored?
Where you run the platform. Signed, tamper-proof, exportable in open formats, verifiable without us.
See it run on your own systems.
One type of service. Declared, converged, proven.