Product ยท Government & compliance
Air-gapped enclaves, ATO packages, CAC-only access, and post-quantum mandates aren't edge cases here. The Government edition is a first-class build of the same codebase, hardened for public-sector and regulated environments.
These aren't Government add-ons; they're how Certheim is built. The Government edition hardens further from here.
Zero outbound calls and an offline-verifiable signed license. A fully disconnected enclave installs, licenses, and operates without ever reaching the internet.
All cryptography runs through a CMVP-validated OpenSSL FIPS provider, enforced at runtime and validated on RHEL/AlmaLinux 9 (CMVP #4857). We document exactly what's in scope, not a marketing checkbox.
mTLS client-certificate login against your issuer chain, with local accounts as a controlled fallback. Smart-card-only access is a config choice, not a custom build.
Everything in Commercial, plus an assurance, access-control, federal-PKI, and compliance pack built for accreditation.
The audit log upgrades to write-once, hash-chained storage: evidence your assessor can verify, not just a table nobody may have edited.
Enforce that no single operator can request, approve, and sign; require two-person control for the operations that matter most.
Federal trust anchors with full chain validation, plus DoD and service certificate subject profiles and organizational-unit presets out of the box.
Control mapping with OSCAL and eMASS-ready export, so your ATO package pulls live evidence from the system instead of screenshots.
STIG/SCAP-aligned deployment hardening and government consent banners: the install your ISSO can absorb without a waiver.
A CNSA 2.0 alignment report over your real inventory (built on the crypto bill of materials) and post-quantum migration tooling (including ML-DSA CA support), so the quantum mandate is a plan, not a panic.
CRL generation and distribution designed for disconnected enclaves, where OCSP responders can't reach.
Structured, verifiable transfer bundles move issuance artifacts across security domains under guard review. No sneakernet tarballs.
Documented, witnessed key-generation ceremonies with HSM/PKCS#11 anchoring for CA keys that must be born and stay in hardware.
Inventory the algorithms, key sizes, and protocols actually in use across your certificate estate: the raw material for any migration plan.
Score the inventory against CNSA 2.0 and PQC readiness: what's compliant, what's aging, what breaks first.
Pilot ML-DSA chains with the local CA, migrate templates on your schedule, and prove progress with exportable evidence.
Next up
Generate a key and CSR in your browser, walk the guided setup, or stand up Community for free. No sales call required.
Questions first? Talk to us. Design partners and air-gapped evaluations are welcome.