๐Ÿ” PATENT SUBMITTED โ€” #202621037440 ๐Ÿญ AIR-GAP READY โ€” WORKS IN OFFLINE OT NETWORKS ๐Ÿ›ก๏ธ IEC 62443 ยท ISO 27001 ยท IEC 62351-9 ALIGNED โšก ZERO TRUST ARCHITECTURE โ€” BUILT IN ๐Ÿ” PATENT SUBMITTED โ€” #202621037440 ๐Ÿญ AIR-GAP READY โ€” WORKS IN OFFLINE OT NETWORKS ๐Ÿ›ก๏ธ IEC 62443 ยท ISO 27001 ยท IEC 62351-9 ALIGNED โšก ZERO TRUST ARCHITECTURE โ€” BUILT IN
THE PLATFORM

Built for Governed PKI.
At Any Scale.

A unified PKI automation and governance engine combining certificate lifecycle operations, workflow orchestration, role-based governance, and audit intelligence โ€” in one platform.

03 | ARCHITECTURE

Multi-Tier System Architecture

Five tightly integrated layers โ€” each with a single responsibility, each contributing to the complete governance chain.

1

Presentation Layer

Web-based dashboards for the two governance panels, plus the operational surfaces devices actually touch.

CISO Panel
Governance Dashboard
Owner Panel
Self-Service Asset View
Enrolment
EST ยท API ยท Form
Console
Orchestrator Site Status
2

Orchestration Engine

Core PKI automation logic managing certificate lifecycle workflows, inventory matching, and CA interactions.

Workflows
Lifecycle Automation
Engine
Inventory Match Processing
CA
CA Interaction Layer
Policy
Policy Enforcement
3

Site Layer โ€” Trust & Compliance Orchestrator

Deployed once per OT site. Collects certificate requests locally and relays them outbound only โ€” the CA is never reachable from the site.

Intake
EST ยท Web Form ยท API
Queue
Incoming ยท Requested ยท Issued
Link
Store-and-Forward, Outbound Only
Footprint
Self-Contained Executable
4

Certificate Authority Layer

Hierarchical CA with offline Root CA (trust anchor) and online Intermediate CA (issuing authority) with air-gap support.

Root CA
Offline Trust Anchor
Int. CA
Online Issuing Authority
Anchor
Own Root or Public Root
CSR
Request Management
5

Data & Audit Layer

Structured storage for certificates, assets, and templates. Immutable audit event logs with full actor attribution.

Store
Certificate Repository
Assets
Asset Registry
Logs
Immutable Audit Trail
Detect
Anomaly Detection
04 | ROLE-BASED PANELS

Two Panels. Zero Overlap.

Requests arrive automatically from the Orchestrator, not from a person โ€” so governance needs only two roles, cleanly separated at the architecture level.

CISO Panel โ€” Security Governance

๐Ÿ›๏ธ Approval & Oversight

The control centre for the entire PKI environment. Approves assets, manages users, and holds certificate status for the whole estate.

โœ…
Asset Approval

New assets must be approved here before they can ever request a certificate โ€” the trust gate for the whole platform.

๐Ÿ‘ค
User Management

Add users, assign permissions, and enforce MFA and RBAC across both panels.

๐Ÿ“Š
Certificate Status, Estate-Wide

View the status of every certificate across every asset owner โ€” issued, pending, expiring, revoked.

๐Ÿšจ
Unknown-Device Alerts

An asset outside the inventory that requests a certificate is refused automatically and raised here for review.

Owner Panel โ€” Asset Owner Self-Service

๐Ÿ”ง Manage What You Own

An asset owner's own view of their own assets. Register, monitor, and keep certificates current โ€” nothing outside their scope.

๐Ÿ“ฆ
Add, Modify, Delete Assets

Full lifecycle control over the assets they own โ€” register a new device, update its details, or retire it.

๐Ÿ”
Certificate Status

View the certificate status of their own assets only โ€” no visibility into any other owner's estate.

โš ๏ธ
Error Checking

Surface failed or stalled requests for their own assets so problems are caught before they become outages.

โณ
Expiry Management

Track upcoming expiries and renewals for owned assets โ€” the same information the CISO Panel sees, scoped to their own estate.

09 | SECURITY

Built-In Security Architecture

Security is not a layer added on top โ€” it is the foundation the platform is built upon.

Security Control
Implementation
Multi-Factor Authentication
Optional enforcement of secondary authentication factors for all role panels โ€” Admin, User, Approver, and Auditor.
Role-Based Access Control
Access scoped strictly to role-specific modules. No cross-role data or function access permitted at any level.
Separation of Duties
Certificate request, approval, and issuance distributed across distinct roles โ€” no single person controls the full chain.
Policy-Driven Issuance
No certificate is ever issued without traversing the defined approval workflow. Governance is mandatory, not optional.
Secure Session Management
Session validation, timeout enforcement, and prevention of session reuse across all user interfaces.
Immutable Audit Logging
All system events recorded with actor attribution and timestamp. Tamper-resistant for forensic and regulatory purposes.
Cryptographic Standards
Industry-standard key algorithms (RSA, ECDSA) and certificate profiles aligned with RFC 5280.
CA Isolation
Root CA maintained in secure isolated environment. Operational exposure limited exclusively to the Intermediate CA.
10 | ROADMAP

Strategic Roadmap

The Trust Engine continues to evolve โ€” with a clear path toward HSM integration, Zero Trust, and Post-Quantum Cryptography.

Near-Term

Foundation Hardening

HSM Integration โ€” FIPS 140-2/3 cryptographic key protection
Automated certificate renewal & revocation with configurable lifecycle policies
API-based integration with enterprise IAM platforms
Mid-Term

Advanced Intelligence

Network Access Control (NAC) integration for certificate-driven network admission
Real-time anomaly detection using advanced behavioural analytics & ML
Zero Trust architecture integration โ€” continuous certificate-based trust verification
Long-Term

Future-Ready

Post-Quantum Cryptography (PQC) โ€” CRYSTALS-Dilithium, FALCON
Cloud-native deployment & multi-tenant architecture for managed PKI
Commercial Root CA integration for publicly trusted PKI architectures

See the Platform in Action

Schedule a live demonstration tailored to your environment and compliance requirements.

๐Ÿ” Request a Demo View Deployment Models โ†’
Chat on WhatsApp