About
Multi-stakeholder trust, by design
Confium is an open-source framework for threshold-native cryptography. No single party holds the signing key; a configurable quorum must participate.
Sponsored by
Funded by the European Commission through NGI Zero PET, administered by NLnet. More about funding →
What Confium is
Confium is a configurable engine for threshold cryptography. Organizations deploy it with their own parameters — their own algorithms, their own quorum policy, their own certificate formats. The same relationship a TLS library has to transport security.
Three deployment modes ship today: peer-to-peer threshold crypto, PKI drop-in (PKCS#11 / OpenSSL / JCE adapters), and Sovereign PKI for institutional certificate infrastructure.
Governance
Confium is developed in the open at
github.com/confium.
All changes land via pull request on main;
releases are automated via release-plz and published to
crates.io, RubyGems, and npm.
The project operates under the BSD-2-Clause license. There is no contributor license agreement (CLA); contributors retain their copyright while granting the standard distribution rights under the BSD-2-Clause terms.
Contributor ladder
- Contributor — anyone who opens a PR.
- Maintainer — review rights on one or more crates. Earned by sustained review and design contributions.
- Release manager — runs the release workflow, cuts release tags. Two-factor required.
See Contribute for how to get started.
Code of conduct
The project follows the
Contributor Covenant 2.1.
Reports go to conduct@confium.org.
Reference deployments
Confium's Mode 3 (Sovereign PKI) is the right shape for institutional certificate infrastructure: calibration registries, pharma regulator approvals, academic accreditation, supply-chain provenance, treaty organizations, and the CNML (certified measuring instruments list).
CNML is one reference deployment among many — it appears here as an example, not as the project's defining use case.