About

Multi-stakeholder trust, by design

Confium is an open-source framework for threshold-native cryptography. No single party holds the signing key; a configurable quorum must participate.


Sponsored by

Funded by the European Commission through NGI Zero PET, administered by NLnet. More about funding →

What Confium is

Confium is a configurable engine for threshold cryptography. Organizations deploy it with their own parameters — their own algorithms, their own quorum policy, their own certificate formats. The same relationship a TLS library has to transport security.

Three deployment modes ship today: peer-to-peer threshold crypto, PKI drop-in (PKCS#11 / OpenSSL / JCE adapters), and Sovereign PKI for institutional certificate infrastructure.

Governance

Confium is developed in the open at github.com/confium. All changes land via pull request on main; releases are automated via release-plz and published to crates.io, RubyGems, and npm.

The project operates under the BSD-2-Clause license. There is no contributor license agreement (CLA); contributors retain their copyright while granting the standard distribution rights under the BSD-2-Clause terms.

Contributor ladder

  • Contributor — anyone who opens a PR.
  • Maintainer — review rights on one or more crates. Earned by sustained review and design contributions.
  • Release manager — runs the release workflow, cuts release tags. Two-factor required.

See Contribute for how to get started.

Code of conduct

The project follows the Contributor Covenant 2.1. Reports go to conduct@confium.org.

Reference deployments

Confium's Mode 3 (Sovereign PKI) is the right shape for institutional certificate infrastructure: calibration registries, pharma regulator approvals, academic accreditation, supply-chain provenance, treaty organizations, and the CNML (certified measuring instruments list).

CNML is one reference deployment among many — it appears here as an example, not as the project's defining use case.