A public-interest redesign of website certificates — ready for the quantum era. See how it works →
The problemWhy certificates break trust
The solutionYour keys, checked by many
Who runs itNo single party in charge
Questions & answersShort answers, no jargon
For decision-makers

A safer trust model that works with you, not against you

ConsensusPKI doesn't replace the organisations that run the internet's trust — it gives them a stronger role in a system no single party can subvert. Here's what it means for yours.

Certificate authorities & trust service providers

Your expertise becomes more valuable

The hard, valuable work a CA does is validation — proving that a party really controls a domain or really is who they claim. ConsensusPKI keeps all of that. What it removes is the unilateral signing power that turns every CA into a single point of catastrophic failure and a magnet for liability.

You become a validator: your existing validation infrastructure and audit regime carry over, your attestations are publicly auditable, and your signature can no longer be the thing that mis-issues a certificate for a domain you've never dealt with. Less risk, same expertise, a clearer role.

  • Existing domain-validation and ACME infrastructure carries over
  • Unilateral mis-issuance liability disappears by design
  • Your attestations become publicly reproducible evidence
  • A credible post-quantum story for your customers, now
Governments & regulators

Infrastructure worthy of digital identity

National digital identity, eIDAS-era trust services and the European Digital Identity Wallet all rest on public-key infrastructure. Building that on a model where any one authority can impersonate any party is a strategic vulnerability — and one a hostile state actor understands well.

ConsensusPKI offers infrastructure where no single operator, and no single compromised authority, can subvert the binding between a name and a key — with a migration path to post-quantum security that doesn't require a flag day. Its guarantees are formally verified, and its evidence trail survives even a future quantum adversary.

Standards-aligned

Designed around the NIST post-quantum standards (ML-DSA, SLH-DSA) and the transparency mechanisms already deployed at web scale. The approach is compatible with the direction of ETSI trust-service standards and European post-quantum migration roadmaps — a complement to that work, not a competitor to it.

Enterprises

Your domains, your rules

Opt out of remote takeover

High-value domains can set a one-way flag that disables remote recovery entirely: from then on, only your own key can ever change your records. No support-desk social-engineering path, no authority that can be leaned on.

An audit trail that outlasts the threat

Because the record's integrity rests on hashing, its history stays tamper-evident even against a future quantum adversary — the forensic trail survives when signatures alone would not.

Private and offline for your users

Your customers' browsers verify without contacting anyone. No third party learns who visits your services, and no outage of an external checker can take your site offline.

Where the project is today

Research-ready, pilot-curious

ConsensusPKI exists as a complete design with a working reference implementation, machine-verified security proofs and reproducible cost models. A peer-reviewed paper is in preparation. We're now looking for the right partners to pressure-test it.

  • Reference implementation of all four roles, openly developed
  • Core security guarantees formally verified
  • Interested in pilots with CAs, TSPs and public-sector PKI teams

Explore a pilot or collaboration

Whether you run a certificate authority, a public-sector trust service, or a large enterprise PKI, we'd welcome a conversation about where ConsensusPKI could fit.