ConsensusPKI is a public-interest project: a certificate system whose security doesn't depend on trusting any single company, government or operator — including us.
ConsensusPKI began as academic research into a stubborn question: why does the security of every website still depend on the honesty of hundreds of organisations, any one of which can speak for all of them? The question grew into a design, the design into formal proofs, and the proofs into a working reference implementation.
The project is developed and stewarded by Nextarp B.V., a Rotterdam-based engineering company working in digital trust, identity and financial infrastructure. The intent is for governance of the deployed system — its validators, witnesses and policies — to be distributed across independent organisations, because that distribution is the security model.
A peer-reviewed paper is in preparation, and the reference implementation, formal models and cost models will be opened alongside it.
Not a company, not a log operator, not a government — and not the project's own founders. Every power in the system is checked by an independent majority.
Verifying a website must never tell anyone which websites you visit. The design forbids online lookups entirely rather than promising to be careful with them.
No security system is absolute. The design's limits — what it cannot defend against — are documented with the same care as its guarantees.
Questions about the project, the research, or a potential pilot? We answer email from researchers, journalists, certificate authorities, public-sector teams and the simply curious.
Email: info@consensuspki.org
Initiative of: Nextarp B.V., Otto Reuchlinweg 1142, 3072 MD Rotterdam, The Netherlands
Company site: nextarp.com
We're glad to explain the certificate system, the quantum transition, or this project — at any technical level, in English or Dutch. Reach out via the address on the left.