Threshold backing
A keyless system concentrates trust in its CA. Confium backs that CA with the Threshold product: the identity key is a T-of-N threshold key shared by independent directors (maintainers, foundation, partner organizations). Forging a countersignature requires corrupting a quorum — a compromise of any single operator, including the CI provider account, is not enough.
This is the same machinery as the PKI product; keyless is the opinionated deployment of it for release signing.