PKI & Secrets Management:
Simplified, Automated, Secure

Issue and manage certificates, protect secrets, and secure cryptographic keys with HSM-backed workflows
—built for Kubernetes

One platform for certificate operations and secret security

Most teams run PKI, secrets, and key management in disconnected tools. KeyAuthority centralizes cryptographic operations so security and platform teams can move faster with policy, traceability, and automation.

Main Features

Private CAs & PKI Orchestration

Centralized management of your certificate lifecycle. Automate issuance, renewal, and revocation across multiple CAs with fine-grained control and compliance-ready audit trails.

Secrets Management

Secure storage for API keys, passwords, and configuration data with role-based access controls, encryption at rest, and visibility into access activity.

Hardware Security Module Integration

Enterprise-grade key protection through PKCS#11. Keep sensitive cryptographic material in tamper-resistant hardware while retaining automated workflows.

Cloud-Native & DevOps Ready

Built for Kubernetes and modern delivery pipelines. Integrate with GitLab CI/CD, federate identities through OIDC and Keycloak, deploy with Helm, and scale horizontally.

Tiers and Pricing

Free

Includes core features: Private CAs, secrets management, and full web UI/API access. Ideal for individuals and small teams getting started with certificate and secret ops.

Enterprise

Includes everything in Free, plus HSM integration and dedicated support with your self-hosted deployment. Ideal for organizations that need advanced security and operational guarantees.

Cloud

Fully managed by us, with all Enterprise features delivered as a hosted service, in a region of your choice (CH/EU/Other). Ideal for teams that want Enterprise capabilities without running infrastructure.

Explore KeyAuthority

Product UI

Explore the staging environment and product workflows

Visit our staging

Certificate Documentation

Review signer and certificate-management documentation

Read docs

Secrets Documentation

Review secrets-management concepts and workflows

Read docs

Frequently Asked Questions

Yes. You can deploy and use it without cost, with optional paid features and support available.

Use the KeyAuthority Helm chart published on ArtifactHub.

No, but the platform is optimized for Kubernetes deployments.

KeyAuthority integrates with cert-manager to automate certificate lifecycle management. See the certificate documentation.

KeyAuthority exposes APIs that allow GitLab runners and other CI/CD workloads to access secrets. See the secrets documentation.

OIDC federation is supported, with Keycloak as a common integration pattern.

Yes. Access and lifecycle events are recorded for traceability and audits.

Yes. The Enterprise Edition supports PKCS#11-compatible HSM integrations.

Deploy KeyAuthority on Kubernetes

Start with the Helm chart, or contact us for Enterprise and managed Cloud options