What's New

Stay up to date with the latest features, improvements, and updates to TigerTrust

Version 4.0.0
Latest

Released on August 28, 2026

Highlights

New Feature

TPM 2.0 Remote Attestation

Cryptographically gate every certificate issuance on hardware-rooted proof of device state. TigerTrust now verifies TPM2_Quote over PCRs, confirms Credential Activation against the manufacturer EK, and binds the CSR public key to the TPM via TPM2_Certify — closing every gap that shared secrets left open.

New Feature

IEEE 802.1AR DevID Provisioning

Two-tier device identity for industrial IoT: chain manufacturer-issued IDevIDs to short-lived LDevIDs issued by your workspace CA. Ship a million gateways with hardware-rooted identity — no manual keying, no shared bootstrap secrets.

New Feature

Confidential Computing Attestation

Extend attestation-gated issuance beyond TPMs. TigerTrust now verifies AMD SEV-SNP and Intel TDX quotes alongside TPM 2.0, so workloads inside encrypted VMs can prove their launch measurement before they get a certificate.

New Feature

AK X.509 Certificate Issuance

After successful Credential Activation, TigerTrust signs an X.509 certificate to the enrolled Attestation Key with the TCG-KP-AIK EKU. Downstream services validate AK identity via standard cert-path validation — no runtime dependency on our enrollment API.

Improvements

  • Multi-bank PCR attestation — require SHA-256 and SHA-384 concurrently for CNSA 2.0 and FIPS 140-3 profiles
  • TCG event log replay with UEFI + IMA (PCR10) parsing — express policy as "any kernel signed by Ubuntu" instead of exact hashes
  • Runtime re-attestation worker with auto-quarantine — compromised devices get their certs revoked within a minute
  • Sealed keys via TPM2_Seal / TPM2_Unseal — bind arbitrary secrets to specific PCR states
  • TPM2_PolicyPCR sessions — the TPM itself refuses to sign outside sanctioned firmware state
  • Renewal worker gates on attestation freshness — stale devices defer their renewal instead of silently reissuing
  • New dashboard section: IoT & TPM with device inventory, enrolled AKs, attestation policies, and manufacturer trust store
  • Curated manufacturer trust bundle for Intel PTT, Infineon, STMicro, Nuvoton, AMD fTPM, IBM, Microsoft

Bug Fixes

  • Fixed workspaceId-required error on IoT device onboarding and OTA firmware update endpoints
  • Fixed nonce table growth by adding a 15-minute reaper worker for expired attestation challenges
  • Fixed ECC Attestation Key signature verification path in the go verifier
  • Fixed CSR-swap attack window by cross-checking bound public key against TPM2B_PUBLIC contents
Version 3.7.0
Stable

Released on July 15, 2026

Highlights

New Feature

Documentation Site at docs.tigertrust.io

Mintlify-powered developer docs covering every product and every API. 60+ pages organised by feature area, with structured schemas for Product, Solution, Guide, and Glossary types — ready for AI agents to index.

New Feature

Long-form Guides System

Deep-dive technical guides at tigertrust.io/guides — starting with a 5,000-word Complete Guide to TPM 2.0 Certificate Attestation. Editorial writing paired with concrete implementation details and executable examples.

New Feature

PKI & TPM Glossary

Plain-language reference at /glossary covering every term in the machine-identity space: PKI, TPM 2.0, Remote Attestation, PCR, Endorsement Key, Credential Activation, DevID, PQC, SPIFFE / SPIRE, and more.

New Feature

5 New Competitor Comparison Pages

Fair, side-by-side comparisons vs HashiCorp Vault, AWS Private CA, Azure Key Vault, Smallstep, and Google Certificate Manager — each with capability tables, migration steps, and integration deltas.

Improvements

  • New compliance framework landing pages for IEC 62443, FIPS 140-3, and CNSA 2.0 with control-to-capability mapping tables
  • TPM 2.0 PKI product page and TPM-Attested IoT solution page live on tigertrust.io
  • Three in-depth TPM blog posts published: Remote Attestation for IoT, Credential Activation Explained, and the End-to-End Issuance Flow
  • Website design system rebuilt with reusable marketing components: SectionHeader, FeatureCard, SplitFeature, TabbedShowcase, ComparePainSolution, CaseStudyCallout, IntegrationStrip, FAQSection
  • Site-wide font size and radius refinements for improved readability and modern feel
  • Product, solution, and alternative pages migrated to a single-template + data-file pattern — adding a new page is now 150 lines of content

Bug Fixes

  • Added IoT & TPM section to the dashboard sidebar so the pages are actually reachable
  • Fixed oversized text on the pricing page enterprise contact section
  • Fixed React Server Components serialisation error when passing icon references through tabbed showcases
  • Removed inconsistent trust bar treatments across pages ahead of a unified logo asset drop
Version 3.6.0

Released on February 6, 2026

Highlights

New Feature

PKI as a Service

Launch your own private Certificate Authority in minutes. Full PKI infrastructure with Root and Intermediate CAs, CRL/OCSP responders, and HSM support—all managed through our intuitive dashboard or API.

New Feature

On-Premise Deployment

Deploy TigerTrust in your own data center with full air-gapped support. Complete feature parity with cloud offering, including Kubernetes operators and Docker Compose configurations.

New Feature

Code Signing Certificate Management

Comprehensive code signing workflow with secure key storage, timestamping integration, and automated signing pipelines for Windows Authenticode, macOS, JAR, and container images.

Security

Enhanced Agent Security

New agent architecture with mutual TLS authentication, certificate pinning, and secure task queuing via NATS JetStream. Agents now support offline operation with local task caching.

Improvements

  • Unified dashboard with onboarding checklist for faster setup
  • New SSH key discovery and lifecycle management capabilities
  • Multi-cloud certificate synchronization with AWS, Azure, and GCP
  • Performance improvements: 75% faster certificate inventory loading
  • Enhanced compliance reporting with SOC 2 and ISO 27001 templates

Bug Fixes

  • Fixed certificate chain validation for cross-signed intermediates
  • Resolved webhook retry logic for transient network failures
  • Fixed ACME challenge validation timeout on slow DNS propagation
  • Corrected certificate count discrepancies in dashboard widgets
Version 3.5.0
Stable

Released on November 15, 2025

Highlights

New Feature

AI-Powered Certificate Analytics

Introducing our new AI engine that analyzes certificate usage patterns and provides intelligent recommendations for optimization. Get insights on certificate lifecycle trends, anomaly detection, and predictive expiration alerts.

New Feature

Quantum-Safe Cryptography Support

Full support for post-quantum cryptographic algorithms including CRYSTALS-Kyber and CRYSTALS-Dilithium. Prepare your infrastructure for the quantum computing era with hybrid certificate modes.

Improvement

50% Faster Certificate Discovery

Completely rewritten discovery engine with parallel scanning capabilities. Network scans now complete in half the time with improved accuracy and reduced false positives.

Security

Enhanced RBAC Permissions

New granular permission model with 40+ customizable roles. Implement precise access controls with attribute-based access control (ABAC) support.

Improvements

  • Dashboard performance improved by 60% with optimized queries
  • New certificate renewal preview mode to test automation workflows
  • Enhanced API rate limiting with intelligent request throttling
  • Improved mobile app experience with offline mode support

Bug Fixes

  • Fixed issue where Let's Encrypt renewals would occasionally timeout
  • Resolved certificate import errors for certain PEM formats
  • Fixed race condition in simultaneous multi-CA operations
  • Corrected timezone handling in expiration notifications
Version 3.4.2
Stable

Released on October 28, 2025

Highlights

New Feature

Kubernetes Certificate Operator

Native Kubernetes operator for automated certificate management. Deploy as a Helm chart and manage all your K8s certificates through custom resource definitions (CRDs).

Improvement

Advanced Webhook System

New webhook events for certificate lifecycle operations with payload customization, retry logic, and signature verification for enhanced security.

Improvements

  • Added support for Azure Key Vault HSM integration
  • New bulk import tool for migrating from legacy systems
  • Enhanced compliance reporting with custom templates
  • Improved ACME server compatibility

Bug Fixes

  • Fixed memory leak in long-running certificate monitoring tasks
  • Resolved edge case in wildcard certificate validation
  • Fixed notification delivery issues for large distribution lists
Version 3.4.0

Released on October 5, 2025

Highlights

New Feature

Multi-Cloud Certificate Manager

Unified dashboard to manage certificates across AWS ACM, Azure Key Vault, and Google Certificate Manager from a single pane of glass. Includes automated sync and drift detection.

Security

Certificate Transparency Monitoring

Real-time monitoring of Certificate Transparency logs to detect unauthorized certificate issuance for your domains. Get instant alerts for rogue certificates.

Improvement

API v3 with GraphQL

New GraphQL API alongside REST for more efficient data fetching. Query exactly what you need with powerful filtering and relationship traversal.

Improvements

  • New certificate lifecycle visualization with timeline view
  • Enhanced search with fuzzy matching and advanced filters
  • Improved documentation with interactive API playground
  • Added support for certificate bundles and chain management

Bug Fixes

  • Fixed issue with ECDSA certificate generation
  • Resolved API pagination inconsistencies
  • Fixed SSO redirect loop in certain edge cases
Version 3.3.0

Released on September 12, 2025

Highlights

New Feature

Certificate Policy Engine

Define and enforce custom certificate policies across your organization. Set rules for key algorithms, validity periods, certificate authorities, and more with automatic compliance checking.

New Feature

SSH Key Management

Comprehensive SSH key lifecycle management including discovery, rotation, and attestation. Supports OpenSSH, PuTTY, and SSH.com formats.

Improvements

  • New team collaboration features with shared workspaces
  • Enhanced audit logs with advanced search and export
  • Improved certificate renewal success rate to 99.97%
  • Added support for 15 new certificate authorities

Bug Fixes

  • Fixed issue with SAML authentication on mobile devices
  • Resolved certificate chain validation for cross-signed certificates
  • Fixed export functionality for reports over 10,000 records
Version 3.2.0

Released on August 18, 2025

Highlights

Improvement

Real-Time Certificate Monitoring

Live monitoring dashboard with WebSocket connections for instant updates. See certificate changes, renewals, and alerts in real-time without page refreshes.

Security

Zero-Trust Network Access

Integrated ZTNA capabilities with continuous verification and context-aware access policies. Ensure secure access to certificate management operations.

Improvements

  • Dark mode support across all interfaces
  • New notification channels: Microsoft Teams, Discord, PagerDuty
  • Performance optimizations for accounts with 100K+ certificates
  • Enhanced mobile app with biometric authentication

Bug Fixes

  • Fixed sorting issues in certificate inventory table
  • Resolved webhook delivery failures during network interruptions
  • Fixed date formatting inconsistencies across different locales
Version 3.1.0

Released on July 25, 2025

Highlights

New Feature

Certificate Automation Workflows

Visual workflow builder for complex certificate automation scenarios. Create custom workflows with conditional logic, approval gates, and integrations.

Improvements

  • New CSV/Excel import for bulk certificate operations
  • Enhanced reporting with custom dashboards and widgets
  • Improved API documentation with code examples in 8 languages
  • Added support for mTLS authentication

Bug Fixes

  • Fixed issue with certificate auto-renewal on weekends
  • Resolved CORS errors in API for specific origins
  • Fixed dashboard widget refresh timing issues
Roadmap preview

Coming soon

A sneak peek at what we're shipping over the next two quarters.

Visual attestation policy builder
Drag-and-drop editor for PCR policies, event-log rules, and IMA allow-lists. Capture a golden state from a live device, tune it in the UI, and roll it to a fleet — no JSON authoring required.
Post-Quantum migration wizard
Guided workflow for hybrid PQC certificate rollout: inventory scan, algorithm mapping, staged issuance, and rollback plan — aligned to the NSA CNSA 2.0 timeline.
Native SIEM audit streams
First-party connectors for Splunk, Datadog, and Microsoft Sentinel. Push every issuance, revocation, and attestation event with schema-mapped fields — no custom parsing.
Runtime IMA policy enforcement
Extend measured-boot attestation to userspace: allow-list specific binary hashes per fleet, deny unknown executions, and correlate IMA events across your entire estate.
Self-service developer portal
Scoped certificate self-service for application teams — request, rotate, and retire within policy guardrails without opening a ticket.
Anomaly-driven auto-revocation
ML-powered detection for certificate misuse patterns — unexpected geographies, unusual issuance velocity, PCR drift — with configurable automatic revocation.