Skip to content

Products

Two systems we build, licence and run.

Both grew out of client work that had no acceptable off-the-shelf answer. Both are deployed in your own environment — on your hardware, under your keys.

Product 01

Root CA System

A certificate authority you own end to end — offline root, delegated issuing CAs, live revocation, trusted timestamps and document signing — with every private key locked inside a hardware security module.

  • YubiKey Integration
  • YubiHSM Integration
  • OCSP Module
  • CRL Repository
  • SubCA Module
  • TSA Module
  • PDF Signer
Root CA System architecture: an offline root anchored in a YubiHSM issues three sub-CAs, backed by OCSP, CRL and timestamping services, consumed by browsers, PDF signing and device identity.
SftpS architecture: WinSCP, FileZilla, command-line clients and applications authenticate by mTLS, SSH CA, SSH key or YubiKey; the server applies policy and audit, integrates downstream and notifies by SMS, email, Telegram or webhook.
Product 02

SftpS

A proactive FTP server. Files are authenticated against your certificate authority, checked on arrival, routed into the systems that need them, and announced to the people who are waiting — without a polling script anywhere.

  • Native system integration
  • YubiKey authentication
  • mTLS CA authentication
  • SSH CA authentication
  • SSH key authentication
  • Standard client support
  • SMS, email, Telegram, webhook

Better together

One trust anchor, two jobs.

Run them side by side and SftpS stops managing its own credentials. Every client certificate and every host key is issued, checked and revoked by the same authority you already operate — so offboarding a partner is one revocation, not a spreadsheet.

Issue once, trust everywhere

Client certificates minted by your Identity SubCA are accepted by SftpS with no separate user store.

Revoke in one place

A revoked certificate fails the next SftpS handshake because the server checks OCSP live.

Prove when it happened

Transfer receipts are timestamped by your own TSA, so delivery disputes end with evidence.

See either product on your own data.

We run a scoped pilot in your environment — your hardware, your policies, your clients — before anybody signs a licence.