Public and private certificate authorities delivered as a managed service. HSM-backed key material, a 99.99% SLA, and native issuance APIs your platform teams can integrate in an afternoon.
The traditional path — buy a pair of Thales or Entrust HSMs, rack them in a colocation cage, hire a Crypto Officer, script a root-signing ceremony, then build the middleware around it — takes six to nine months and roughly $1.4M in year-one costs. Most teams that walk that path end up with a CA that never rotates, an audit trail nobody trusts, and one person who understands the whole system.
PKI as a Service inverts the model. TigerTrust operates the hardware, the ceremony, the OCSP responders, and the CRL distribution. You get an API that mints certificates against policies you write, a signed audit trail streamed to your SIEM, and a Crypto Officer role in your workspace that performs quorum-approved sensitive operations.
The result: a private CA in production the same week you sign the MSA. Full support for cross-signing, path-length constraints, name constraints, custom extensions, and the new-in-2027 short-lived issuance profiles.
Offline-style roots signed once in a witnessed ceremony, issuing intermediates you can scope by business unit, environment, or CI pipeline. Name-constrained sub-CAs stop a compromised issuer from minting Google.com.

Your workloads request certificates the way they already know how. First-class ACME support means cert-manager, Traefik, and every ingress controller in the CNCF just work. Old-line CMPv2 clients get the same treatment.

A distributed OCSP responder with sub-second stapling latency. CRLs published every 5 minutes to a global edge. Optional Certificate Transparency logging for browser-trusted issuance.

Ceremony-signed roots, name-constrained sub-CAs, cross-signing.
Keys never leave FIPS 140-3 boundary.
Every issuance protocol worth speaking.
Reusable issuance policies with SAN / EKU / validity limits.
Multi-party approval on sensitive operations.
Signed audit events over syslog / JSON.
“Our previous private CA needed a Wednesday-afternoon change window to rotate a cert. TigerTrust rotates ours during deploys and I stop hearing about it.”
Bring a CSR, an ACME client, or just a curl session. We'll walk through hierarchy design and mint a live intermediate against a scratch workspace.