ServicesPKI and digital identity

Public key infrastructure for institutions that issue trust.

Certificate authorities, certificate lifecycle, key custody in hardware security modules and digital signature services, designed and operated to NIST, FIPS, FedRAMP and Mexican NOM requirements. Our oldest practice.

Who it is forGovernment agencies that issue certificates to citizens, companies or officials; banks and regulated firms running internal CAs; providers of electronic signature and timestamping; and AI teams that need identities for agents and tools.

The problem

Issuing a certificate is easy. Running a certificate authority that an auditor, a regulator or a court will trust is not. Key ceremonies, HSM custody, policy documents, revocation, timestamping and the operational discipline around them are where most internal PKI projects stall.

Cybernip began in this work. We design the hierarchy, write the certificate policy and practice statement, run the key ceremony, operate or hand over the CA, and apply the same identity discipline to the newer problem of giving AI agents and workloads credentials that can be attributed and revoked.

What we deliver

  • CA hierarchy design: root, intermediates, issuing CAs, offline and online
  • Certificate policy (CP) and certification practice statement (CPS)
  • Key ceremonies and key custody in FIPS 140-2 and 140-3 validated HSMs, on premises or AWS CloudHSM
  • Certificate lifecycle: enrolment, renewal, revocation, OCSP and CRL
  • Digital signature and timestamping services aligned to NOM-151 and eIDAS-style requirements
  • Agent and workload identity: certificates and mTLS for AI tools and services

How we work

Assess

Trust requirements, applicable standards, existing keys and systems. A gap analysis against the controls you must meet.

Design

Hierarchy, policies, HSM architecture, roles and separation of duties. Reviewed with your security and legal teams.

Build

HSM provisioning, key ceremony with witnesses and minutes, CA deployment, integration with your directories and applications.

Operate or hand over

We run it under a monthly engagement or train your team and hand over the runbooks. Audit evidence is produced either way.

What backs it

We design and operate to NIST SP 800-57 key management guidance, FIPS 140-2 and 140-3 for cryptographic modules, FedRAMP Moderate and High control baselines, and Mexican NOM standards including NOM-151 for data message conservation. We do not publish client references in this practice; our clients prefer it that way, and so do we.

Common questions

Can you run a CA for a government entity?

Yes. That is where the practice started. Public-sector work follows the entity's own normative framework and procurement rules, and we have run offline root ceremonies with government witnesses.

Do we have to buy HSMs?

Not necessarily. AWS CloudHSM provides FIPS 140-2 Level 3 modules on demand; for sovereign or air-gapped requirements we specify and install on-premises modules.

What does this have to do with AI?

Agents call tools and systems on your behalf. Each one needs an identity, a credential that can be revoked and a signed record of what it did. That is a PKI problem, and we treat it as one.

Talk to an engineer about this

Thirty minutes, no slides. Bring the workload and we will tell you what we would do and what it would cost.

Talk to us[email protected]