Public key infrastructure for institutions that issue trust.
Certificate authorities, certificate lifecycle, key custody in hardware security modules and digital signature services, designed and operated to NIST, FIPS, FedRAMP and Mexican NOM requirements. Our oldest practice.
The problem
Issuing a certificate is easy. Running a certificate authority that an auditor, a regulator or a court will trust is not. Key ceremonies, HSM custody, policy documents, revocation, timestamping and the operational discipline around them are where most internal PKI projects stall.
Cybernip began in this work. We design the hierarchy, write the certificate policy and practice statement, run the key ceremony, operate or hand over the CA, and apply the same identity discipline to the newer problem of giving AI agents and workloads credentials that can be attributed and revoked.
What we deliver
- CA hierarchy design: root, intermediates, issuing CAs, offline and online
- Certificate policy (CP) and certification practice statement (CPS)
- Key ceremonies and key custody in FIPS 140-2 and 140-3 validated HSMs, on premises or AWS CloudHSM
- Certificate lifecycle: enrolment, renewal, revocation, OCSP and CRL
- Digital signature and timestamping services aligned to NOM-151 and eIDAS-style requirements
- Agent and workload identity: certificates and mTLS for AI tools and services
How we work
Assess
Trust requirements, applicable standards, existing keys and systems. A gap analysis against the controls you must meet.
Design
Hierarchy, policies, HSM architecture, roles and separation of duties. Reviewed with your security and legal teams.
Build
HSM provisioning, key ceremony with witnesses and minutes, CA deployment, integration with your directories and applications.
Operate or hand over
We run it under a monthly engagement or train your team and hand over the runbooks. Audit evidence is produced either way.
What backs it
Common questions
Can you run a CA for a government entity?
Yes. That is where the practice started. Public-sector work follows the entity's own normative framework and procurement rules, and we have run offline root ceremonies with government witnesses.
Do we have to buy HSMs?
Not necessarily. AWS CloudHSM provides FIPS 140-2 Level 3 modules on demand; for sovereign or air-gapped requirements we specify and install on-premises modules.
What does this have to do with AI?
Agents call tools and systems on your behalf. Each one needs an identity, a credential that can be revoked and a signed record of what it did. That is a PKI problem, and we treat it as one.
Related services
Talk to an engineer about this
Thirty minutes, no slides. Bring the workload and we will tell you what we would do and what it would cost.