Skip to content

Public key infrastructure & secure automation

Trust infrastructure,
engineered.

SK Enterprise designs, builds and runs the layer your business quietly depends on — the certificate authority that proves who you are, the hardware that guards your keys, the file channel that never leaks, and the applications and workflows built on top of them.

FIPS
validated hardware key custody
RFC 3161
compliant timestamping
mTLS
end-to-end mutual authentication
24/7
monitoring and alerting
A hardware-backed root of trust at the centre of a lattice connecting certificates, timestamping, secure transfer, automation and applications.
X.509 Root CAYubiHSM 2YubiKey PIVOCSPCRLRFC 3161 TSAPAdES PDF SigningSFTP / FTPSSMTP / IMAP / POP3DKIMSSH CAmTLSKeycloakOpenID Connectn8nSpring BootVaadinThymeleafAndroidiOSX.509 Root CAYubiHSM 2YubiKey PIVOCSPCRLRFC 3161 TSAPAdES PDF SigningSFTP / FTPSSMTP / IMAP / POP3DKIMSSH CAmTLSKeycloakOpenID Connectn8nSpring BootVaadinThymeleafAndroidiOS

Product 01

Mail System

Business email on your own domain, running on a mail server we wrote and operate ourselves. Free webmail to start, full access from any mail app when you need it — and nothing bolted on that you did not ask for.

  • Every address on your own domain name, on every plan
  • Webmail free; SMTP, IMAP and POP3 for USD 3 per account per month
  • DKIM-signed outbound mail, with SPF and DMARC set up alongside you
  • Email only — no calendars, contacts or suite you pay for and ignore
Inside the Mail System

Webmail

Read and send from any browser with nothing to install. Included on the free plan.

SMTP

Send from any mail app, or from your own applications, over an authenticated, encrypted connection.

IMAP

Mailboxes that stay in sync across your phone, laptop and browser.

POP3

Download mail to a single computer, for the people who prefer to work that way.

Custom Domain

[email protected] from day one, on the free plan as well as the paid one.

DKIM Signing

Every outbound message is signed so receiving servers can verify it really came from you.

TLS Everywhere

Client connections are encrypted, so passwords and messages never cross the network in the clear.

Two plans, from USD 0 Compare Free and Paid
SftpS architecture diagram: standard clients authenticate with mTLS, SSH CA, SSH keys or YubiKey; the server applies policy, audits every transfer, pushes files downstream and sends notifications by SMS, email, Telegram or webhook.

Product 02

SftpS

A proactive file transfer server. It does not sit and wait to be polled — it authenticates the sender against your CA, checks the payload, moves it where it belongs, and tells the right people it happened.

  • Nine ways in: passkeys, FIDO2, U2F, PIV, OTP, TOTP, mTLS CA, SSH CA and SSH key
  • Works today with WinSCP, FileZilla and the scp and sftp command line
  • Native integration hooks into storage, databases and n8n workflows
  • Files encrypted at rest, with keys held in hardware
  • Notifications by SMS, email, Telegram and webhook on every event
Inside SftpS

Why teams choose us

Security people who ship, product people who read the RFC.

Plenty of firms can build you a website. Fewer can build you a certificate authority. We do both, which is why the two never end up fighting each other.

Hardware first

If a key can be copied, it will be. We design every system so the private key is born in hardware and dies there.

Built to integrate

Standards before proprietary glue: PKCS#11, ACME, SCEP, OCSP, SFTP, REST. Your other vendors can talk to it.

Audit-ready by default

Append-only logs, dual control, documented policy. When the auditor asks, the answer is already written down.

Operated, not dumped

We stay on after go-live: monitoring, patching, certificate expiry watch and a human who picks up.

How we work

Four steps, no theatre.

Short engagements, visible progress, and a written handover at the end. You should never be locked in by ignorance of your own system.

01

Understand the constraint

A working session with the people who actually operate the system. We map the threat model, the compliance pressure and the deadline before we propose anything.

02

Design and price it openly

You get an architecture, a risk register and a fixed scope with a number attached. If a cheaper path exists, we say so.

03

Build in short increments

Two-week slices with something demonstrable at the end of each. Security reviews happen inside the build, not after it.

04

Hand over and stay close

Runbooks, key ceremony records and training for your team — then a support arrangement sized to how critical the system is.

Tell us what you are trying to protect.

A thirty-minute call is usually enough for us to tell you whether we are the right people for the problem — and what it would take.