Public key infrastructure
A PKI is not a software project
It is a long-term commitment to key custody, continuity and the value of the evidence, carrying obligations that will outlast you. What you decide at scoping, you operate for a decade. That holds for a state’s root authority just as much as for a large group’s internal PKI or a bank’s delegated registration authority. Remote Trust PKI is built for exactly that: issuing signature certificates on an HSM, close to the signer.
One discipline, at three scales
Control of the keys, traceability, continuity: the requirements don’t change from one scale to the next. What changes is what you lose when they give way.
States, regulators, certification authorities
National and sovereign PKI
A root authority operated in your name, on your territory, carrying the evidentiary weight the law grants it, not the weight a foreign vendor is willing to concede.
- Offline root authority and a hierarchy of intermediate authorities
- Certificate policy and certification practice statement
- Qualified signature certificates for citizens and civil servants, on an HSM
- Digital public procurement and electronic invoicing
- Transfer of skills to the national teams
Banks, insurers, telecoms, energy, healthcare, industry
Enterprise PKI
An internal authority for signing and sealing your flows. Your internal uses stop depending on a public authority’s calendar.
- An internal authority for the uses that need not be public
- Employee signature certificates on an HSM, activated remotely
- Company seal certificates for all the documents issued in volume
- Signing and sealing of business and document flows
- A clean separation between internal trust and public trust
Banks, ministries, operators, notaries
Delegated registration authorities
You enrol your own customers or citizens at the counter, under the central authority’s policy. The certificate is issued on an HSM and signs at once.
- Remote Trust AED portal for your registration operators
- Face-to-face identification, documents and checks set by the policy
- The signer’s key generated and kept in the HSM
- Certificate consumed directly by NGSIGN, with no wiring
- Roles, logging and partitioning per entity
Four steps, and nothing unplanned between them
- 01
Scoping
Architecture and policies
Audit of what exists, authority hierarchy, signature levels, documents to stamp. Certificate policies and practice statement, all written before anything is bought.
- 02
PKI foundation
HSM, authorities and ceremony
Supply and installation of the HSMs, key ceremony of the root authority, then the intermediate authorities, the OCSP responder and timestamping brought into production.
- 03
Services
Signature and visible stamp
The electronic signature service and the visible electronic stamp go live. Pilot applications are integrated by API and accepted with your teams.
- 04
Operations
Training and handover
Training for PKI administrators, registration operators and developers, skills transfer, then transition support through to your teams’ full autonomy.
The expensive mistake is building the wrong foundation
A certification authority or a signature platform is operated for a decade. What you settle at scoping (deployment architecture, signature types, functional scope) you carry for all of it. We come in before that, and we train the people who will hold the infrastructure afterwards.
Advisory
We work the decision before it costs anything: what the regulatory framework requires of you, what your existing estate already imposes, and what your teams will still be able to operate in five years.
- Scoping study and authority architecture
- Certificate policy and certification practice statement
- Platform and HSM selection, with no vendor tie
- Inventory and audit of the existing certificate estate
- Preparation for homologation and compliance audit
Training
A PKI your teams cannot operate is a PKI you are renting from someone. We train the people who will hold it, through to full handover.
- PKI and electronic signature fundamentals
- Day-to-day operation of a certification authority
- Key ceremony: roles, secret holders, written record
- Separate sessions for technical teams and for decision-makers
- Skills transfer at the end of a programme
The facts, and where to check them
Certifications and homologations
eIDAS certification of the platform
Qualified trust service, certified on a PKI and HSM-based electronic signature deployment built with our products. The certificate names the “Remote Trust CA” authority policies.
- Regulation (EU) No 910/2014
- Accredited, independent certification body
- Periodic surveillance audits after it
- EN 319 401, 411-1/-2, 412-1/-2/-5
Six ANCE homologations, every signature type
The National Electronic Certification Agency (ANCE) has homologated the platform for every signature level recognised in Tunisia, from the token to the visible stamp.
- Qualified signature on an HSM, at ANCE or on your premises
- Qualified signature on a USB token
- Legal-entity seal and the visible electronic stamp
- Mobile ID backed by the national identity (E-Houwiya)
National and institutional PKIs deployed
HAICOP
TunisiaOverhaul of the PKI and trust-services foundation of the national public procurement platform
NACEF · CIMF
TunisiaTrust services of the Ministry of Finance Information Technology Centre
ANSSI
Burkina FasoNational electronic signature platform, migration to the new version under way
ASIN
BeninNational trust services and the visible electronic stamp
Port Autonome de Cotonou
BeninDeployment of the NGSIGN electronic signature platform
SIGMAP
MauritaniaPublic procurement and purchasing management information system
Our clients · Key accounts
Governments and public agencies
Banks and insurers
Pharmaceutical industry and distribution
Other sectors
No vendor agreement steers our recommendation
We are tied to no vendor. The platform we recommend follows from the programme’s constraints: sovereignty, certification level, existing estate, cost of operation. We stay accountable for the result in production whichever product is chosen. The choice follows the requirement, never the other way round.
Standards we build to
PAdES signatures for PDF, XAdES for XML, created and validated to the ETSI standards. The references that make evidence hold up.
- PAdES · ETSI EN 319 142 · Baseline B, T, LT, LTA
- XAdES · ETSI EN 319 132 · Baseline B, T, LT, LTA
- CAdES · ETSI EN 319 122
- Validation · ETSI EN 319 102
- eIDAS (UE) n° 910/2014
- ETSI EN 319 411-1 / 411-2
- ETSI EN 319 421 / 319 422
- X.509 · RFC 5280
- Common Criteria (HSM)
- 2D-DOC (ANTS) · ISO 22376:2023
Let’s talk about your needs before we talk about product.
Tell us the regulatory framework and the scale you’re aiming at. We’ll tell you what actually needs building, including if it turns out to be less than you thought.



























































