Skip to main content
NG Technologies

Public key infrastructure

A PKI is not a software project

It is a long-term commitment to key custody, continuity and the value of the evidence, carrying obligations that will outlast you. What you decide at scoping, you operate for a decade. That holds for a state’s root authority just as much as for a large group’s internal PKI or a bank’s delegated registration authority. Remote Trust PKI is built for exactly that: issuing signature certificates on an HSM, close to the signer.

One discipline, at three scales

Control of the keys, traceability, continuity: the requirements don’t change from one scale to the next. What changes is what you lose when they give way.

  • States, regulators, certification authorities

    National and sovereign PKI

    A root authority operated in your name, on your territory, carrying the evidentiary weight the law grants it, not the weight a foreign vendor is willing to concede.

    • Offline root authority and a hierarchy of intermediate authorities
    • Certificate policy and certification practice statement
    • Qualified signature certificates for citizens and civil servants, on an HSM
    • Digital public procurement and electronic invoicing
    • Transfer of skills to the national teams
  • Banks, insurers, telecoms, energy, healthcare, industry

    Enterprise PKI

    An internal authority for signing and sealing your flows. Your internal uses stop depending on a public authority’s calendar.

    • An internal authority for the uses that need not be public
    • Employee signature certificates on an HSM, activated remotely
    • Company seal certificates for all the documents issued in volume
    • Signing and sealing of business and document flows
    • A clean separation between internal trust and public trust
  • Banks, ministries, operators, notaries

    Delegated registration authorities

    You enrol your own customers or citizens at the counter, under the central authority’s policy. The certificate is issued on an HSM and signs at once.

    • Remote Trust AED portal for your registration operators
    • Face-to-face identification, documents and checks set by the policy
    • The signer’s key generated and kept in the HSM
    • Certificate consumed directly by NGSIGN, with no wiring
    • Roles, logging and partitioning per entity

Four steps, and nothing unplanned between them

  1. 01

    Scoping

    Architecture and policies

    Audit of what exists, authority hierarchy, signature levels, documents to stamp. Certificate policies and practice statement, all written before anything is bought.

  2. 02

    PKI foundation

    HSM, authorities and ceremony

    Supply and installation of the HSMs, key ceremony of the root authority, then the intermediate authorities, the OCSP responder and timestamping brought into production.

  3. 03

    Services

    Signature and visible stamp

    The electronic signature service and the visible electronic stamp go live. Pilot applications are integrated by API and accepted with your teams.

  4. 04

    Operations

    Training and handover

    Training for PKI administrators, registration operators and developers, skills transfer, then transition support through to your teams’ full autonomy.

The expensive mistake is building the wrong foundation

A certification authority or a signature platform is operated for a decade. What you settle at scoping (deployment architecture, signature types, functional scope) you carry for all of it. We come in before that, and we train the people who will hold the infrastructure afterwards.

Advisory

We work the decision before it costs anything: what the regulatory framework requires of you, what your existing estate already imposes, and what your teams will still be able to operate in five years.

  • Scoping study and authority architecture
  • Certificate policy and certification practice statement
  • Platform and HSM selection, with no vendor tie
  • Inventory and audit of the existing certificate estate
  • Preparation for homologation and compliance audit

Training

A PKI your teams cannot operate is a PKI you are renting from someone. We train the people who will hold it, through to full handover.

  • PKI and electronic signature fundamentals
  • Day-to-day operation of a certification authority
  • Key ceremony: roles, secret holders, written record
  • Separate sessions for technical teams and for decision-makers
  • Skills transfer at the end of a programme

The facts, and where to check them

Certifications and homologations

  • eIDAS certification of the platform

    Qualified trust service, certified on a PKI and HSM-based electronic signature deployment built with our products. The certificate names the “Remote Trust CA” authority policies.

    • Regulation (EU) No 910/2014
    • Accredited, independent certification body
    • Periodic surveillance audits after it
    • EN 319 401, 411-1/-2, 412-1/-2/-5
  • Six ANCE homologations, every signature type

    The National Electronic Certification Agency (ANCE) has homologated the platform for every signature level recognised in Tunisia, from the token to the visible stamp.

    • Qualified signature on an HSM, at ANCE or on your premises
    • Qualified signature on a USB token
    • Legal-entity seal and the visible electronic stamp
    • Mobile ID backed by the national identity (E-Houwiya)
    Download the six attestations →

National and institutional PKIs deployed

  • HAICOP

    Tunisia

    Overhaul of the PKI and trust-services foundation of the national public procurement platform

  • NACEF · CIMF

    Tunisia

    Trust services of the Ministry of Finance Information Technology Centre

  • ANSSI

    Burkina Faso

    National electronic signature platform, migration to the new version under way

  • ASIN

    Benin

    National trust services and the visible electronic stamp

  • Port Autonome de Cotonou

    Benin

    Deployment of the NGSIGN electronic signature platform

  • SIGMAP

    Mauritania

    Public procurement and purchasing management information system

Our clients · Key accounts

Governments and public agencies

  • CNAM, Caisse Nationale d’Assurance Maladie
  • Agence Foncière Agricole
  • MTNIMA, Ministère de la Transformation Numérique, Mauritanie
  • Ministère du Numérique et de la Digitalisation, République du Bénin
  • ANSICE, Tchad
  • CNI, Centre National de l’Informatique
  • Port Autonome de Cotonou
  • ANSSI, Agence Nationale de Sécurité des Systèmes d’Information, Burkina Faso
  • TUNEPS
  • ASIN, Agence des Systèmes d’Information et du Numérique, Bénin
  • Ministère de la Transition Numérique et de la Modernisation de l’Administration
  • HAICOP
  • CIMF, Centre Informatique du Ministère des Finances
  • TunTrust
  • RNE, Registre National des Entreprises
  • ANSUT

Banks and insurers

  • Obour, Electronic Payment Solutions
  • Bourse de Tunis
  • QNB
  • Hannibal Lease
  • UBCI
  • ATB, Arab Tunisian Bank
  • Amen Bank
  • BNA, Banque Nationale Agricole
  • STAR Assurances
  • Carte Assurances
  • Tunis Re
  • GAT Assurances
  • Tunisie Leasing & Factoring
  • OLEA Insurance Solutions Africa
  • UIB
  • Maghrebia

Pharmaceutical industry and distribution

  • SMT
  • Pfizer
  • Opalia Recordati
  • Pharmatec
  • Médis
  • Univers Pharmacie
  • Okba Médicaments
  • Cophadis
  • Neapolis Pharma
  • IPS, Industrie Pharmaceutique Saïd

Other sectors

  • Ennakl Automobiles
  • UGFS North Africa
  • TIC Group, Technique Inspection & Contrôle
  • Délice Holding
  • CCT, Compagnie des Comptables de Tunisie
  • Vivo Energy
  • Paretec, filiale Parenin
  • OMV
  • CPG, Compagnie des Phosphates de Gafsa
  • CMA CGM
  • Equipement Moderne Automotive
  • Parenin
  • Aziza
  • Dataxion
  • ETAP
  • STIR
  • Agil, SNDP
  • Orange

No vendor agreement steers our recommendation

We are tied to no vendor. The platform we recommend follows from the programme’s constraints: sovereignty, certification level, existing estate, cost of operation. We stay accountable for the result in production whichever product is chosen. The choice follows the requirement, never the other way round.

Standards we build to

PAdES signatures for PDF, XAdES for XML, created and validated to the ETSI standards. The references that make evidence hold up.

  • PAdES · ETSI EN 319 142 · Baseline B, T, LT, LTA
  • XAdES · ETSI EN 319 132 · Baseline B, T, LT, LTA
  • CAdES · ETSI EN 319 122
  • Validation · ETSI EN 319 102
  • eIDAS (UE) n° 910/2014
  • ETSI EN 319 411-1 / 411-2
  • ETSI EN 319 421 / 319 422
  • X.509 · RFC 5280
  • Common Criteria (HSM)
  • 2D-DOC (ANTS) · ISO 22376:2023

Let’s talk about your needs before we talk about product.

Tell us the regulatory framework and the scale you’re aiming at. We’ll tell you what actually needs building, including if it turns out to be less than you thought.