Skip to content

Public key infrastructure & secure automation

Trust infrastructure,
engineered.

SK Enterprise designs, builds and runs the layer your business quietly depends on — the certificate authority that proves who you are, the hardware that guards your keys, the file channel that never leaks, and the applications and workflows built on top of them.

FIPS
validated hardware key custody
RFC 3161
compliant timestamping
mTLS
end-to-end mutual authentication
24/7
monitoring and alerting
A hardware-backed root of trust at the centre of a lattice connecting certificates, timestamping, secure transfer, automation and applications.
X.509 Root CAYubiHSM 2YubiKey PIVOCSPCRLRFC 3161 TSAPAdES PDF SigningSFTP / FTPSSSH CAmTLSKeycloakOpenID Connectn8nSpring BootVaadinThymeleafAndroidiOSX.509 Root CAYubiHSM 2YubiKey PIVOCSPCRLRFC 3161 TSAPAdES PDF SigningSFTP / FTPSSSH CAmTLSKeycloakOpenID Connectn8nSpring BootVaadinThymeleafAndroidiOS

Product 01

Root CA System

A complete certificate authority you own outright: an air-gapped root, issuing sub-CAs, and every service a relying party needs to check its work — all anchored in hardware that never surrenders a private key.

  • Keys generated and held inside a YubiHSM 2 — never exported, never on disk
  • Dual-control key ceremonies with YubiKey operator cards
  • Live revocation over OCSP and CRL, plus RFC 3161 timestamping
  • PAdES-compliant PDF signing for documents that must survive an audit
Inside the Root CA System

YubiKey Integration

Operator identity and dual control on physical tokens, with PIV enrolment and lifecycle management.

YubiHSM Integration

PKCS#11 key custody. Private keys are generated in hardware and cannot leave it.

OCSP Module

RFC 6960 responder with pre-signed responses and sub-second answers under load.

CRL Repository

Full and delta revocation lists published over HTTP on a schedule you set.

SubCA Module

Delegate issuance per purpose or business unit, each with its own policy and name constraints.

TSA Module

RFC 3161 timestamp authority so signatures stay verifiable long after certificates expire.

Digital Signature

PDF Signer producing PAdES B-LT signatures, batch or on demand, via API or UI.

Seven modules, one platform See how they fit together
SftpS architecture diagram: standard clients authenticate with mTLS, SSH CA, SSH keys or YubiKey; the server applies policy, audits every transfer, pushes files downstream and sends notifications by SMS, email, Telegram or webhook.

Product 02

SftpS

A proactive file transfer server. It does not sit and wait to be polled — it authenticates the sender against your CA, checks the payload, moves it where it belongs, and tells the right people it happened.

  • Four authentication paths: mTLS CA, SSH CA, SSH key and YubiKey
  • Works today with WinSCP, FileZilla and the scp and sftp command line
  • Native integration hooks into storage, databases and n8n workflows
  • Notifications by SMS, email, Telegram and webhook on every event
Inside SftpS

Why teams choose us

Security people who ship, product people who read the RFC.

Plenty of firms can build you a website. Fewer can build you a certificate authority. We do both, which is why the two never end up fighting each other.

Hardware first

If a key can be copied, it will be. We design every system so the private key is born in hardware and dies there.

Built to integrate

Standards before proprietary glue: PKCS#11, ACME, SCEP, OCSP, SFTP, REST. Your other vendors can talk to it.

Audit-ready by default

Append-only logs, dual control, documented policy. When the auditor asks, the answer is already written down.

Operated, not dumped

We stay on after go-live: monitoring, patching, certificate expiry watch and a human who picks up.

How we work

Four steps, no theatre.

Short engagements, visible progress, and a written handover at the end. You should never be locked in by ignorance of your own system.

01

Understand the constraint

A working session with the people who actually operate the system. We map the threat model, the compliance pressure and the deadline before we propose anything.

02

Design and price it openly

You get an architecture, a risk register and a fixed scope with a number attached. If a cheaper path exists, we say so.

03

Build in short increments

Two-week slices with something demonstrable at the end of each. Security reviews happen inside the build, not after it.

04

Hand over and stay close

Runbooks, key ceremony records and training for your team — then a support arrangement sized to how critical the system is.

Tell us what you are trying to protect.

A thirty-minute call is usually enough for us to tell you whether we are the right people for the problem — and what it would take.