Dedicated
Your own Certificate Authority, dedicated to your organization
SSL’s Dedicated PKI products give your organization a privately owned CA hierarchy: your Root CA, your Issuing CA(s), your certificate policies. Two products differ on one axis, whether WebTrust audit coverage is required.
Private Compliance PKI
Private Enterprise PKI
Both are built on the same FIPS-hardened platform, supported by the same unified REST API, and operated by SSL’s PKI team.
Which product is right for you?
| Private Compliance PKI Learn more → | Private Enterprise PKI Learn more → | |
|---|---|---|
| What you get | Your own Root + Issuing CA(s), WebTrust-audited | Your own Root + Issuing CA(s), private trust |
| WebTrust audit | ✅ Included, same audit covers your hierarchy | ❌ Not included |
| Trust scope | Internal / partner ecosystem | Internal only |
| Key Ceremony | ✅ Auditor-witnessed | Standard, documented |
| Compliance use | SOC2, HIPAA, supply chain, banking, IoT | Internal operational PKI |
| PQC (hybrid) | ✅ Ecosystem tier | ✅ Available |
| Pricing model | Annual tier ($20k–$80k/yr + $10k setup) | Monthly subscription |
| Best for | Regulated industries, IoT at scale, audit pass-through | Internal mTLS, dev/staging, VPN/Wi-Fi, device identity |
If you need to demonstrate independently audited CA governance to partners, regulators, or customers, choose Private Compliance PKI.
If your use cases are internal and third-party audit evidence is not a requirement, Private Enterprise PKI delivers the same infrastructure at lower cost.
Shared platform capabilities
FIPS 140-2 Level 3 HSMs
All CA private keys generated and stored in certified hardware, never exportable in plaintext.
Dedicated Root CA
SSL's PKI operations are independently audited; the same audit covers your dedicated or shared hierarchy.
Enrollment protocols
Full enrollment protocol suite: ACME (RFC 8555) for automated renewal, SCEP for device enrollment, EST (RFC 7030) for constrained devices, REST API for custom integrations. Covers servers, devices, MDM platforms, Kubernetes clusters, and CI/CD pipelines.Unified REST API
The same SSL.com Web Services (SWS) REST API used for public-trust certificates: one integration covers both private and public PKI needs without separate code paths, credentials, or platform integrations.Certificate lifecycle
Full certificate lifecycle management: issuance, renewal, rekey, rollover, revocation (OCSP and CRL), expiration alerting via email and webhook, and SIEM export for compliance audit trails.Observability
Certificate inventory dashboards, issuance analytics with per-template breakdowns, expiration forecasting for fleet planning, and immutable audit logs with tamper-evident timestamping for compliance evidence.Integrations
Integrations with Active Directory/Entra ID for user enrollment, Microsoft Intune and Jamf Pro for MDM device certificates, Kubernetes cert-manager, HashiCorp Vault PKI backend, and SIEM/SOAR platforms.