Certificate Authority in your Cloud



Certificate Cloud Authority Service in Tenant based on Azure Key Vault.


Release is coming soon!

Seamless two-tier PKI

Issuing CA and offline Root CA can easily be deployed in your tenant. Or you can also use your on-premises Root CA.

Secure Azure Key Vault

CA private keys are generated and kept in Azure Key Vault. You can use software or hardware keys and even managed HSM!


PQC Ready

Certificates can be issued and signed either with traditional RSA or ECC or with the promising  Post-Quantum Crypto-Algorithm ML-DSA .


"Secardeo certCAST is a highly available and secure CA service under your full control eliminating traditional PKIaaS dependencies and vendor lock-ins ."

Lower PKI costs and avoid dependencies!


  • No costs for planning, setup and operation of a complex internal PKI.
  • Avoid problems caused by missing skilled resources.
  • Azure service level and costs can easily be planned and adjusted.
  • Don't fall into a difficult-to-break dependency on a single PKIaaS provider.
  • Keep full control over your CA keys and all certificates.


Manage all types of certificates.


  • Request or revoke certificates for users, servers, clients and devices automatically using Secardeo TOPKI components.
  • Revocation information is published in a Certificate Revocation List (CRL) or it can be retrieved online using OCSP.


Enroll certificates on-premises or in the cloud.


  • Autoenrollment for Intune managed devices or Azure Kubernetes containers with certCAST can be done seamlessly with Secardeo certPort.
  • Even native Active Directory certificate autoenrollment can be performed with certEP - certCAST is a cost-effective highly available alternative to your Microsoft CA ADCS.


How it works

More information is coming soon!

  • Features

    • Deployed as an App Service in your Azure Tenant
    • Can easily be deployed as a two-tier offline Root CA or subordinate Issuing CA or a single-tier CA
    • Will use Azure Key Vault  Standard with a software key, Premium with an HSM key or Azure Managed HSM
    • Supports RSA and elliptic curve cryptography (ECC) for signing certIficates
    • Optionally supports post-quantum cryptography algorithm ML-DSA for signing certIficates
    • Issues any type of  end-entity certificate based on CSR and additional request parameters
    • Provides Root CRL and Issuing CA CRL
    • Provides OCSP for online status check
    • Can be integrated via REST API
    • Provides audit logs by Azure Log Analytics

Resources (coming soon!)