A public-interest redesign of website certificates — ready for the quantum era. See how it works →
The problemWhy certificates break trust
The solutionYour keys, checked by many
Who runs itNo single party in charge
Questions & answersShort answers, no jargon
The certificate system, rebuilt

The padlock in your browser trusts hundreds of strangers.

Today, any one of hundreds of certificate authorities can vouch for any website in the world — including yours. ConsensusPKI puts the website owner back in charge, checks every claim from many independent places, and keeps the public record honest. No single party to hack, bribe or coerce.

No single point of trust Private by design Post-quantum ready
Website owner holds the only key that counts Public record tamper-evident, append-only Independent witnesses a majority must co-sign Your browser checks everything locally signed proof
0
online lookups when you visit a site — verification is local and private
14/20
independent witnesses must agree before a record counts
7/7
core security properties machine-verified with formal proofs
~5 KB
post-quantum proof size — no larger than today's certificates
The problem in one minute

One weak link can impersonate any website

The padlock in your browser means a certificate authority vouched for the site. There are hundreds of them, and your browser trusts them all equally — for every site on the internet.

Anyone can vouch for anyone

Any trusted authority can issue a certificate for any domain — your bank's, your government's, yours. The system's safety equals the safety of its weakest member.

It has gone wrong before

In 2011 a hacked Dutch authority issued fake certificates for major services, used to spy on hundreds of thousands of people. Browsers accepted every one of them.

Today's fix only watches

Modern transparency logs record every certificate so forgeries can be discovered — after the fact. Discovery is not prevention. The forged certificate still works.

What ConsensusPKI changes

Prevention, not just detection

Three changes, each simple to state: the owner's key is the only key that counts, every claim is checked from many places, and the public record cannot be quietly rewritten.

Your key is in charge

A certificate for your website only counts if it carries your own signature. Even if every authority in the world were compromised, none of them could speak for you.

Checked from many places

Domain checks run from multiple, unpredictably chosen network locations at once. Fooling one vantage point achieves nothing; an attacker would have to fool most of the internet, visibly.

A record no one can rewrite

The public record is co-signed every hour by a majority of independent witnesses. Showing different versions to different people requires most of them to conspire — and leaves evidence.

Built for what's coming

Ready for the quantum era

Quantum computers will eventually break the signatures that secure today's internet. Most systems will bolt on fixes later — and pay for it on every connection. ConsensusPKI was designed for the transition from day one.

Runs both worlds side by side

Classical and post-quantum signatures operate together, and every record can step up — but never down. Migration without a flag day.

No slow-down on your visit

Post-quantum signatures are big. ConsensusPKI moves the heavy material off the connection entirely, so a fully post-quantum proof stays no larger than today's certificates.

Standards, not experiments

Built on the NIST-standardised post-quantum algorithms (ML-DSA) — the same ones governments and browsers are adopting.

Who it serves

Built for the people who run the internet's trust

Certificate authorities & TSPs

Your validation expertise becomes more valuable, not less — while the liability of unilateral issuance disappears. A better role in a safer system.

Governments & regulators

Digital identity and eIDAS-era services need infrastructure no single party can subvert — and a credible post-quantum answer. This is both.

Enterprises

Your domains, your keys, your rules: opt out of remote takeover entirely, and get an audit trail that survives even a future quantum adversary.

Not just promises

Security you can check

The core guarantees are machine-verified with a formal prover, the wire formats are locked by public test vectors, and a full reference implementation exists with a growing test suite. A peer-reviewed paper is in preparation.

  • Authorisation survives compromise of every single authority — formally proven
  • Record tampering requires majority witness collusion — formally proven
  • 110+ automated tests, including every known failure mode
  • All sizes and costs generated from published models, not estimates

For the technically curious

The full research paper will be published here once it has been submitted to peer review. Until then, the Research page tracks what exists today and what has been verified.