← All Products
Confium PKI
Run a CA without a single trusted key.
CA OperatorsEnterprise PKI TeamsInstitutional PKI
Use cases
PKI patterns enabled by threshold signing:
Threshold CA Signing
Operate a certificate authority where the root key is split across multiple parties. Issue certifies requires T-of-N quorum.
Products: Confium Threshold Confium PKI
Sovereign PKI
Operate a national or industry PKI where the root of trust is held by a quorum of institutional parties rather than a single operator.
Products: Confium Threshold Confium PKI
Policy Enforcement
Define attribute-based policies that signing sessions must satisfy (geography, role, time-of-day).
Products: Confium Threshold Confium PKI
Certificate Transparency
Run an RFC 6962 transparency log for your CA. Every issued cert is appended; mis-issuance is detectable.
Products: Confium Transparency Confium PKI
OCSP / CRL from Threshold Keys
Operate OCSP responders and CRL signing from threshold keys. No single party can revoke or attest alone.
Products: Confium PKI Confium Threshold
ACME Automation
Integrate ACME protocol with threshold-backed certificate issuance. Drop-in for certbot-style automation.
Products: Confium PKI