Product · PKI as a Service

A private CA without the rack of HSMs.

Public and private certificate authorities delivered as a managed service. HSM-backed key material, a 99.99% SLA, and native issuance APIs your platform teams can integrate in an afternoon.

In production
FIPS 140-3 Level 3 modules. Root ceremonies recorded. Every issuance replicated to your logging bucket.
Why we built this

Running a private CA the old way costs seven figures before your first certificate ships.

The traditional path — buy a pair of Thales or Entrust HSMs, rack them in a colocation cage, hire a Crypto Officer, script a root-signing ceremony, then build the middleware around it — takes six to nine months and roughly $1.4M in year-one costs. Most teams that walk that path end up with a CA that never rotates, an audit trail nobody trusts, and one person who understands the whole system.

PKI as a Service inverts the model. TigerTrust operates the hardware, the ceremony, the OCSP responders, and the CRL distribution. You get an API that mints certificates against policies you write, a signed audit trail streamed to your SIEM, and a Crypto Officer role in your workspace that performs quorum-approved sensitive operations.

The result: a private CA in production the same week you sign the MSA. Full support for cross-signing, path-length constraints, name constraints, custom extensions, and the new-in-2027 short-lived issuance profiles.

01
Hosted root · Hosted intermediates

Hierarchy design that respects compartmentalisation.

Offline-style roots signed once in a witnessed ceremony, issuing intermediates you can scope by business unit, environment, or CI pipeline. Name-constrained sub-CAs stop a compromised issuer from minting Google.com.

  • Offline-style root: activation quorum + video-recorded ceremony
  • Per-workspace intermediates with cryptographic name constraints
  • Cross-signing to a public trust anchor for browser-trusted issuance
  • Path-length + policy OIDs, editable through the console or API
See hierarchy design
PKI hierarchy
02
Issuance API

REST, gRPC, ACME, and CMPv2 — pick one.

Your workloads request certificates the way they already know how. First-class ACME support means cert-manager, Traefik, and every ingress controller in the CNCF just work. Old-line CMPv2 clients get the same treatment.

  • ACMEv2 for cert-manager, Traefik, Caddy, K8s ingress
  • CMPv2 for OT / industrial control gear
  • REST + gRPC with Go, Python, Node.js, and Java SDKs
  • Native cert-manager Issuer CRD
Read the API guide
Issuance API
03
OCSP · CRL · CT logs

Revocation that actually propagates.

A distributed OCSP responder with sub-second stapling latency. CRLs published every 5 minutes to a global edge. Optional Certificate Transparency logging for browser-trusted issuance.

  • Global anycast OCSP with 99.999% availability
  • Delta + full CRLs published on a 5-minute cadence
  • Optional CT log submission for public trust roots
  • Machine-readable revocation reason codes
See revocation flows
Revocation infrastructure
Operational envelope
01 · OCSP uptime
99.999%
Global anycast, sub-second stapling.
02 · CRL cadence
5min
Delta + full CRL republishing.
03 · FIPS
140-3L3
Thales Luna Network HSM modules.
04 · Time to prod
48h
From MSA signature to first issuance.
What's in the box

Everything a private CA has to have.

Trust

Root & intermediate hierarchy

Ceremony-signed roots, name-constrained sub-CAs, cross-signing.

Keys

HSM-backed

Keys never leave FIPS 140-3 boundary.

API

ACME · CMPv2 · REST

Every issuance protocol worth speaking.

Policies

Named profiles

Reusable issuance policies with SAN / EKU / validity limits.

Approvals

Quorum operations

Multi-party approval on sensitive operations.

Export

Audit stream

Signed audit events over syslog / JSON.

“Our previous private CA needed a Wednesday-afternoon change window to rotate a cert. TigerTrust rotates ours during deploys and I stop hearing about it.”

—Adaora NwosuHead of Platform Engineering, Kraftwerk Payments
Half an hour, your workloads

Issue your first cert this week.

Bring a CSR, an ACME client, or just a curl session. We'll walk through hierarchy design and mint a live intermediate against a scratch workspace.

No credit card · Runs on your infra