Pricing

Priced for the volume that actually matters.

Every tier ships the full platform — discovery, private CA, attestation, and code signing. Tiers differ on inventory scale, support velocity, and deployment shape. No feature paywalls between them.

In production
Annual billing. Multi-year discounts on request. Air-gapped deployments quoted separately.
Three tiers, one platform

Pick the shape of the deployment. Not the shape of the feature list.

Every tier includes the same platform. Choose the deployment model, the inventory cap, and the support tier that matches your program.

01 · Tier

Team

For a single platform team modernising one PKI surface.

$1.9k
per month · billed annually
  • Up to 25,000 certificates under management
  • Managed SaaS control plane
  • Discovery agents for AWS, Azure, GCP, K8s
  • Public CA + private CA (managed)
  • Business-hours support · 8h SLA
02 · Tier
Most adopted

Enterprise

For estates spanning multiple business units and clouds.

$8.4k
per month · billed annually
  • Up to 500,000 certificates under management
  • SaaS, hybrid, or self-hosted deployment
  • Everything in Team
  • TPM 2.0 attestation for up to 50k devices
  • Code signing pipelines + HSM binding
  • 24×7 support · 1h SLA · named CSM
  • SSO, SCIM, and audit exports
03 · Tier

Sovereign

For regulated, air-gapped, or classified environments.

Bespoke
quoted per program
  • Unlimited certificates and attested devices
  • Air-gapped, on-prem, or dedicated tenant deployment
  • Everything in Enterprise
  • FIPS 140-3 Level 3 HSM binding (your hardware)
  • CNSA 2.0 post-quantum profile
  • Dedicated crypto-officer engagement
  • Program-level SLAs · joint incident response
In every tier

Platform baseline, priced in.

  • Discovery across cloud + K8s + on-prem + IoT
  • Public + private CA issuance
  • Zero-downtime rotation with rollback
  • Machine-readable audit trails
  • REST + gRPC + ACMEv2 + CMPv2 APIs
  • Native cert-manager Issuer CRD
  • Compliance mapping tables
  • SIEM-ready audit exports
  • RBAC with Crypto Officer role
How you actually adopt this

From MSA to first attested cert in under two weeks.A concrete adoption path so you know what a rollout looks like before you sign anything.

  1. 01

    Working demo against your infra

    A 30-minute walkthrough where we point discovery at one of your cloud accounts and surface the certificates you already have. Nothing gets written; nothing gets deployed.

    → Day 0 · 30 min · Read-only
  2. 02

    Managed workspace provisioned

    Once the paper is done, your workspace is live within the day. Discovery agents deploy as a single binary or container per environment.

    → Day 1 · MSA + first agents
  3. 03

    Discovery complete across first cloud

    Full certificate inventory for your first cloud account and Kubernetes cluster. Owners assigned, expiries dashboarded, alerts routed to your channels.

    → Day 3-5 · Inventory + alerting
  4. 04

    Automation policies in production

    Your first renewal policy runs end-to-end. Backup CAs configured. Deployment adapters test-run against a canary workload.

    → Day 7-10 · Auto-renewal live
  5. 05

    Attestation & signing programs online

    For enterprise + sovereign tiers, TPM attestation and code-signing pipelines are live for their first target workloads. Auditor evidence exports scheduled.

    → Day 10-14 · Full-stack live

“We priced against three competitors. TigerTrust was the only one that didn’t make us pay extra for the feature we actually bought them for.”

—Sam IwujiDirector of Information Security, Northlark Motors
Pricing questions

What buyers actually want to know.

Unique X.509 certificates with unique public keys that we have observed at least once in the last 30 days. Rotated pairs count as one; ephemeral in-mesh certs (shorter than 24h) count once per parent workload, not per rotation.
A device that has been through TPM Credential Activation and is receiving PCR-gated LDevIDs. Devices in trial or staging cohorts do not count.
Not today — this platform is priced for programs where an outage would cost more than the seat. If you are running <5k certificates and using only ACME + discovery, cert-manager plus TigerTrust Cloud (a hosted CT + inventory-only tier) is likely enough.
Yes. Enterprise + Sovereign tiers support Thales Luna, Entrust nShield, AWS CloudHSM, and Google Cloud HSM. We drive them over PKCS#11; you retain root-of-trust.
Two phases. Phase 1: TigerTrust reads your existing CA (Vault, Microsoft AD CS, DigiCert, ejbca) as a discovery source and starts inventorying. Phase 2: cross-signed intermediate lets you rotate workloads to TigerTrust-issued certs at your own pace, without touching endpoint trust stores.
See it priced against your program

Get a bill of materials for your rollout.

Bring a rough certificate count, a target date, and a compliance requirement. We'll come back with a scoped quote and a two-week adoption plan.

No credit card · Annual billing · Multi-year discounts