top of page
Quantum
antecedente tecno fondo oscuro.png
antecedente tecno fondo oscuro

Everything that connects has to prove who it is

CyKey is your organization's own certificate authority.

It issues, renews, and revokes the digital identities of your servers

​Your operation depends on certificates that no one is managing

And on mathematics that have an expiration date

A server proves it is your bank using a certificate. An employee signs a contract with a certificate. A field meter connects to the network with a certificate. If that test fails, anyone can impersonate anyone.

Everything depends on
a single certificate

They are requested via email, written down in a spreadsheet, and discovered when they expire, almost always because a service stopped responding. The most critical key is usually in a file, with the password in a shared document.

Almost no one knows how many they have

The algorithms that support that trust today RSA and elliptic curve are broken by a quantum computer. And whatever an attacker encrypts today, they can store until a machine capable of opening it exists.

And the clock is already ticking

​The cryptography you choose this year is exactly what will be operating on the day the threat becomes real. Issuing today without thinking about post-quantum means making that decision without knowing you are making it.

A root of trust lasts between 10 and 20 years. A meter installed today is still in the field in 2041.

What changes the day CyKey goes into operation

The same organization and the same pool of servers and devices.

What changes is who is in control.

Before

With CyKey

Inventory
An outdated spreadsheet. No one knows how many certificates exist or where they are.
A single console: what exists, who requested it, and when it expires.
Issuance
Request via email, days of waiting, and subject to the criteria of whoever attends to it.
Minutes, with profiles by usage type and approval by a second pair of eyes.
Root Key
A file on a server. Whoever copies it can issue on behalf of your organization.
Inside an HSM. Signed within the hardware and never leaves.
Expirations
Discovered when the service is already down.
Notified and renewed before anyone notices a thing.
Auditing
Manually reconstructing who requested what, if any trace remains.
A log that only grows: user, date, action, and result.
Revocation
An email asking not to use it anymore. The certificate remains valid for the world.
Effective and published: whoever validates it sees it is no longer trusted.
Cost
Se paga por certificado a un tercero, y aun así no cubre lo internoPaid per certificate to a third party, and even then, it doesn't cover internal ones.
Issue as many as you need. Cost does not depend on volume.
Post-quantum
No plan, because there is no inventory of which algorithm each thing uses.
NIST-standardized algorithms from day one, coexisting with classical ones.

​Four steps and your organization has its own authority

​It is not a service to which you trust your keys. It is a certificate authority that operates within your perimeter.

Installed wherever you decide

In your data center or in your private cloud. Your keys and certificates never leave to a third party.

1

The root of trust is created

You choose the algorithm: classical where you need compatibility, post-quantum where validity is long-term. The private key is generated inside the HSM and signing happens right in there. CyKey asks the hardware to sign; it never asks for the key.

2

Rules are defined

Who can request, who approves, and who only queries. Which certificate corresponds to a server, a person, or a device. Critical operations require two different people.

3

Issued and operated

Servers and APIs, credentials for people, field devices, code signing, and documents. From the same console, each certificate's status is renewed, revoked, and published.

4

Your infrastructure

The root private key lives inside the HSM and never leaves: CyKey asks the hardware to sign. Externally, only certificates circulate, and whoever receives one can check online if it remains valid. Dotted lines represent status queries, not issuance.

HSM

Root private key. Never leaves here

Signs without the key ever leaving

CyKey Root CA

Delegates

ssuer CA per use case

Publishes revocations

Issues

Online Status

CRL

OCSP

Recipient

Browser

Server

App

Presented upon use

  • Servers and APIs

  • People and signing

  • Field devices

Issued Certificates

Start by knowing what you have

Migracion.png

The conversation doesn't start with a migration; it starts with an inventory: what certificates exist today, what algorithm each one uses, and which ones expire before you have the reach to replace them.

That diagnosis determines whether your case is urgent or if you have margin. In either scenario, the result is a scheduled plan.

CN=CyKey Root CA

O=Your Organization

Key in HSM

algorithm=ML-DSA-65

validity 2026›2046

Transfer and management

of confidential files

Confidential file management

Professional Support

Schedule a Demonstration

bottom of page