Product ยท Government & compliance

Built for the boundary, not retrofitted to it

Air-gapped enclaves, ATO packages, CAC-only access, and post-quantum mandates aren't edge cases here. The Government edition is a first-class build of the same codebase, hardened for public-sector and regulated environments.

The air-gap foundation, in every edition

These aren't Government add-ons; they're how Certheim is built. The Government edition hardens further from here.

No phone-home, offline license

Zero outbound calls and an offline-verifiable signed license. A fully disconnected enclave installs, licenses, and operates without ever reaching the internet.

FIPS 140-3, honestly scoped

All cryptography runs through a CMVP-validated OpenSSL FIPS provider, enforced at runtime and validated on RHEL/AlmaLinux 9 (CMVP #4857). We document exactly what's in scope, not a marketing checkbox.

CAC / PIV authentication

mTLS client-certificate login against your issuer chain, with local accounts as a controlled fallback. Smart-card-only access is a config choice, not a custom build.

The Government edition Government

Everything in Commercial, plus an assurance, access-control, federal-PKI, and compliance pack built for accreditation.

๐Ÿงพ

Tamper-evident WORM audit

The audit log upgrades to write-once, hash-chained storage: evidence your assessor can verify, not just a table nobody may have edited.

๐Ÿ‘ฅ

Separation of duties & dual control

Enforce that no single operator can request, approve, and sign; require two-person control for the operations that matter most.

๐Ÿ›๏ธ

Federal PKI trust

Federal trust anchors with full chain validation, plus DoD and service certificate subject profiles and organizational-unit presets out of the box.

๐Ÿ“‹

NIST 800-53 evidence

Control mapping with OSCAL and eMASS-ready export, so your ATO package pulls live evidence from the system instead of screenshots.

๐Ÿ›ก๏ธ

STIG-hardened

STIG/SCAP-aligned deployment hardening and government consent banners: the install your ISSO can absorb without a waiver.

๐Ÿ”ฎ

CNSA 2.0 & PQC readiness

A CNSA 2.0 alignment report over your real inventory (built on the crypto bill of materials) and post-quantum migration tooling (including ML-DSA CA support), so the quantum mandate is a plan, not a panic.

๐Ÿ”Œ

Offline revocation

CRL generation and distribution designed for disconnected enclaves, where OCSP responders can't reach.

๐Ÿ“ฆ

Cross-domain transfer

Structured, verifiable transfer bundles move issuance artifacts across security domains under guard review. No sneakernet tarballs.

๐Ÿ—๏ธ

FIPS key ceremonies

Documented, witnessed key-generation ceremonies with HSM/PKCS#11 anchoring for CA keys that must be born and stay in hardware.

Know your cryptography

  1. 1

    Crypto bill of materials

    Inventory the algorithms, key sizes, and protocols actually in use across your certificate estate: the raw material for any migration plan.

  2. 2

    Assess against policy

    Score the inventory against CNSA 2.0 and PQC readiness: what's compliant, what's aging, what breaks first.

  3. 3

    Migrate deliberately

    Pilot ML-DSA chains with the local CA, migrate templates on your schedule, and prove progress with exportable evidence.

Next up

See it for yourself

Generate a key and CSR in your browser, walk the guided setup, or stand up Community for free. No sales call required.

Questions first? Talk to us. Design partners and air-gapped evaluations are welcome.