Enterprise PKI Management

Run your own internal Certificate Authority.

Build multi-tier CA hierarchies, HSM-back your keys, define certificate templates, and enforce policy — all from a single management plane. Eliminate per-cert fees to public CAs.

CA hierarchy

Hierarchical CA management

Build and operate multi-tier CA trees with offline roots and online issuing CAs. Maintain complete control over your trust chain and migrate between CAs without disruption.

How it works
  • Offline root CA support
  • Multiple online issuing CAs
  • Cross-certification workflows
  • CA migration tools
Multi-tier certificate authority hierarchy
Hardware key protection

HSM integration for CA private keys

Protect CA private keys with FIPS 140-2 Level 3 hardware security modules — on-premise or cloud. Keys generate and sign inside the HSM and never leave.

How it works
  • FIPS 140-2 Level 3 HSMs
  • AWS CloudHSM and Azure Dedicated HSM
  • Thales Luna support
  • Key ceremony automation
Hardware security module rack
Templates & policy

Reusable templates and policy enforcement

Pre-configured templates for TLS servers, code signing, user auth, and device certs. Extensions, key usage, and validity periods enforced consistently at issuance time.

How it works
  • TLS server, code signing, user auth templates
  • Custom extension support
  • CP/CPS policy documentation
  • Policy OID management
Certificate templates management
Enterprise PKI capabilities

Everything a Certificate Authority needs. In one platform.

The full toolkit for running a defensible, compliant internal PKI.

CA hierarchy management
Create and manage root and intermediate CAs with cross-certification support.
  • Root CA creation
  • Subordinate CA provisioning
  • Cross-certification
Certificate issuance
Automated and manual issuance workflows with self-service portals.
  • CSR validation & approval
  • Bulk issuance
  • Self-service portals
CRL & OCSP
Certificate revocation infrastructure for real-time validation.
  • Automated CRL generation
  • OCSP responder setup
  • Distribution point management
Policy management
Define and enforce CP/CPS documentation and compliance requirements.
  • CP/CPS docs
  • Policy OID management
  • Compliance enforcement
Multi-tenant support
Manage certificates for multiple teams, departments, or clients with isolation.
  • Tenant isolation
  • Per-tenant policies
  • Delegated administration
Approval workflows
Role-based multi-level approvals with full audit trail logging.
  • Role-based approvals
  • Multi-level workflows
  • Audit trail logging

From production deployments

5M+
Certificates issued
99.99%
CA availability
< 100ms
Issuance latency
Case study
Federal · Government

Consolidated 7 legacy CAs into a single HSM-backed hierarchy — with zero downtime.

We had ADCS, EJBCA, and five OpenSSL scripts nobody would touch. TigerTrust cross-certified everything, then migrated us CA-by-CA. Auditors were speechless.
Chief Information Security Officer
7
Legacy CAs consolidated
0
Minutes of downtime during migration
100%
FIPS 140-2 Level 3 coverage
Integrations

Works with every tool in your stack

Pluggable HSMs, identity providers, and orchestrators for the CA you actually run.

Thales Luna
HSM
YubiHSM
HSM
AWS CloudHSM
HSM
Azure Dedicated HSM
HSM
Entrust nShield
HSM
Okta
Identity
Azure AD
Identity
Active Directory
Identity
HashiCorp Vault
Secrets
Kubernetes
K8s
ServiceNow
ITSM
Terraform
IaC
FAQ

Frequently asked questions

Yes. TigerTrust speaks PKCS#11 to any FIPS 140-2 Level 3 HSM — Thales Luna, Entrust nShield, YubiHSM, AWS CloudHSM, Azure Dedicated HSM, and Utimaco are all validated in production. Key material generates and signs inside the HSM and never leaves. You can partition HSM slots per CA, per policy, or per tenant. If you're on a cloud KMS instead, we support AWS KMS and GCP Cloud KMS with the same key-never-exports guarantee.
Yes, and it's the most common starting point. TigerTrust supports cross-certification with Microsoft ADCS, EJBCA, OpenSSL-based CAs, and legacy Symantec/DigiCert internal roots. We issue a fresh root inside your new HSM, cross-sign against your existing chain so trust never breaks, migrate templates and issued certificates over a defined window, then decommission the old CA. Typical timeline is 60-90 days for a mid-size estate.
HSM keys back up as M-of-N wrapped shards using the HSM vendor's native ceremony (Thales SKS, nShield ACS, etc.). TigerTrust automates the operator prompts, records the ceremony to the audit log, and stores the wrapped shards where you specify — including offline media for offline root CAs. Recovery is documented per HSM vendor and tested during onboarding. We never hold the recovery quorum.
Full X.509 v3 with any extension you can express — TLS server, TLS client, code signing, S/MIME, user auth, smart card logon, device certificates, and custom OID-based extensions. Templates enforce key algorithms (RSA, ECDSA P-256/P-384, Ed25519), key sizes, validity periods, EKU sets, and name constraints. Custom policy OIDs and CP/CPS references are managed through the same UI. RFC 5280 conformance is validated at issuance.
The TigerTrust platform is SOC 2 Type II certified. For customers building a publicly-trusted CA hierarchy, we support the operational controls required for WebTrust for CAs and ETSI EN 319 411 — including offline root storage, key ceremony recording, dual-control enforcement, and audit trail integrity. We do not perform the WebTrust audit itself; that's done by your accredited auditor against the platform we operate.
Yes. TigerTrust PKI Core deploys as a Kubernetes application or bare-metal binaries. Fully air-gapped deployments are supported with signed offline update bundles and offline root ceremonies. The control plane can be self-hosted; the offline root can live in a physically isolated environment and only come online for signing intermediate CA renewals. A hybrid model — SaaS control plane, on-prem HSMs — is also common.

Take control of your Certificate Authority.