Certificate Authority in your Cloud
Cloud CA Service in your Tenant based on Azure Key Vault.
Release is coming soon!
Seamless two-tier PKI
Issuing CA and offline Root CA can easily be deployed in your tenant. Or you can also use your on-premises Root CA.
Secure Azure Key Vault
CA private keys are generated and kept in Azure Key Vault. You can use software or hardware keys and even managed HSM!
PQC Ready
Certificates can be issued and signed either with traditional RSA or ECC or with the promising Post-Quantum Crypto-Algorithm ML-DSA .
"Secardeo certVault CA is a highly available and secure certificate authority service under your full control eliminating traditional PKIaaS dependencies and vendor lock-ins ."
Lower PKI costs and avoid dependencies!
- No costs for planning, setup and operation of a complex internal PKI.
- Avoid problems caused by missing skilled resources.
- Azure service level and costs can easily be planned and adjusted.
- Drastically reduce the costs of a Microsoft Cloud PKI.
- Don't fall into a difficult-to-break dependency on a single PKIaaS provider.
- Keep full control over your CA keys and all certificates.


Enroll certificates on-premises or in the cloud.
- Autoenrollment for Intune managed devices or Azure Kubernetes containers with certVault CA can be done seamlessly with Secardeo certPort.
- Even native Active Directory certificate autoenrollment can be performed with certEP - certVault CA is a cost-effective highly available alternative to your Microsoft CA ADCS.
Manage all types of certificates.
- With certVault CA, you are not limited to SCEP-based client certificates; you can also issue server, user, or (IoT) device certificates – in the cloud or on-premises.
- For automated enrollment, use the appropriate TOPKI components.
- Revocation information is published in a Certificate Revocation List (CRL) or it can be retrieved online using OCSP.

How it works
More information is coming soon!

