Your own Certificate Authority — dedicated to your organization
SSL’s Dedicated PKI products give your organization a privately owned CA hierarchy: your Root CA, your Issuing CA(s), your certificate policies. Two products differ on one axis — whether WebTrust audit coverage is required.
Private Compliance PKI
Audited, compliance-grade, for regulated industries and ecosystem trust
Private Enterprise PKI
Dedicated infrastructure, full CA control, internal use, without the audit program
Both are built on the same FIPS-hardened platform, supported by the same unified REST API, and operated by SSL’s PKI team.
Which product is right for you?
| Private Compliance PKI Learn more → | Private Enterprise PKI Learn more → | |
|---|---|---|
| What you get | Your own Root + Issuing CA(s), WebTrust-audited | Your own Root + Issuing CA(s), private trust |
| WebTrust audit | ✅ Included — same audit covers your hierarchy | ❌ Not included |
| Trust scope | Internal / partner ecosystem | Internal only |
| Key Ceremony | ✅ Auditor-witnessed | Standard, documented |
| Compliance use | SOC2, HIPAA, supply chain, banking, IoT | Internal operational PKI |
| PQC (hybrid) | ✅ Ecosystem tier | ✅ Available |
| Pricing model | Annual tier ($20k–$80k/yr + $10k setup) | Monthly subscription |
| Best for | Regulated industries, IoT at scale, audit pass-through | Internal mTLS, dev/staging, VPN/Wi-Fi, device identity |
If you need to demonstrate independently audited CA governance to partners, regulators, or customers — choose Private Compliance PKI.
If your use cases are internal and third-party audit evidence is not a requirement — Private Enterprise PKI delivers the same infrastructure at lower cost.
Shared platform capabilities
FIPS 140-2 Level 3 HSMs
All CA private keys generated and stored in certified hardware — never exportable in plaintext.
Dedicated Root CA
SSL's PKI operations are independently audited — the same audit covers your dedicated or shared hierarchy.
Enrollment protocols
ACME (RFC 8555), SCEP, EST, REST API — covers servers, devices, MDM, Kubernetes, CI/CD.
Unified REST API
Same API used for public-trust certificates — no separate integration required.
Certificate lifecycle
Issuance, renewal, rekey, rollover, revocation, expiration alerting, SIEM export.
Observability
Certificate inventory, issuance analytics, expiration forecasting, immutable audit logs.
Integrations
Active Directory/Entra ID, Intune/Jamf, Kubernetes, HashiCorp Vault, SIEM/SOAR.