YubiKey Integration
Operator identity and dual control on physical tokens, with PIV enrolment and lifecycle management.
Public key infrastructure & secure automation
SK Enterprise designs, builds and runs the layer your business quietly depends on — the certificate authority that proves who you are, the hardware that guards your keys, the file channel that never leaks, and the applications and workflows built on top of them.
What we do
Most of our clients start with a single piece — a website, an FTP replacement, a certificate authority — and stay because the pieces were built to fit together.
Product 01
A complete certificate authority you own outright: an air-gapped root, issuing sub-CAs, and every service a relying party needs to check its work — all anchored in hardware that never surrenders a private key.
Operator identity and dual control on physical tokens, with PIV enrolment and lifecycle management.
PKCS#11 key custody. Private keys are generated in hardware and cannot leave it.
RFC 6960 responder with pre-signed responses and sub-second answers under load.
Full and delta revocation lists published over HTTP on a schedule you set.
Delegate issuance per purpose or business unit, each with its own policy and name constraints.
RFC 3161 timestamp authority so signatures stay verifiable long after certificates expire.
PDF Signer producing PAdES B-LT signatures, batch or on demand, via API or UI.
Product 02
A proactive file transfer server. It does not sit and wait to be polled — it authenticates the sender against your CA, checks the payload, moves it where it belongs, and tells the right people it happened.
Why teams choose us
Plenty of firms can build you a website. Fewer can build you a certificate authority. We do both, which is why the two never end up fighting each other.
If a key can be copied, it will be. We design every system so the private key is born in hardware and dies there.
Standards before proprietary glue: PKCS#11, ACME, SCEP, OCSP, SFTP, REST. Your other vendors can talk to it.
Append-only logs, dual control, documented policy. When the auditor asks, the answer is already written down.
We stay on after go-live: monitoring, patching, certificate expiry watch and a human who picks up.
How we work
Short engagements, visible progress, and a written handover at the end. You should never be locked in by ignorance of your own system.
A working session with the people who actually operate the system. We map the threat model, the compliance pressure and the deadline before we propose anything.
You get an architecture, a risk register and a fixed scope with a number attached. If a cheaper path exists, we say so.
Two-week slices with something demonstrable at the end of each. Security reviews happen inside the build, not after it.
Runbooks, key ceremony records and training for your team — then a support arrangement sized to how critical the system is.
A thirty-minute call is usually enough for us to tell you whether we are the right people for the problem — and what it would take.