All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
A bank or manufacturer that roots its certificate authorities, issuance policies, and machine identities in Keyfactor takes on switching friction that runs through issuance and lifecycle workflows, though the record does not document replacement scope. That friction, together with the engineering of running certificate authorities at scale, is the durable part of the business. Keyfactor owns the open-source EJBCA authority, which is Common Criteria certified, and sponsors the FIPS 140-3 Bouncy Castle libraries, an independently audited posture. The limits are plain: the EJBCA core is open source and reproducible, no named cross-customer data asset appears in the record, and identity platform vendors could bundle certificate management into suites large buyers already own.
| Description | Machine-identity and PKI platform that issues and automates digital certificates, runs certificate authorities, signs code, and discovers cryptographic assets to prepare enterprises for post-quantum cryptography. | [f1] |
|---|---|---|
| Founded | 2001 | [f2] |
| HQ | Independence, Ohio, United States | [f3] |
| Latest funding | Minority investment from Sixth Street Growth (Oct 2023, ~$1.3B enterprise value, joining Insight Partners) | [f4] |
| Product | What it does |
|---|---|
| Keyfactor Command | Certificate lifecycle automation that discovers, inventories, issues, and renews certificates and keys across clouds, Kubernetes, and on-prem from one console. |
| EJBCA Enterprise | Enterprise public key infrastructure built on the open-source EJBCA certificate authority, deployable on-prem or in the cloud for human and machine identities. |
| Cryptographic Posture Management | Cryptographic discovery, inventory, and agility tooling (AgileSec, CipherInsights) that finds quantum-vulnerable algorithms and supports the transition to post-quantum cryptography. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Keyfactor issues and automates certificates, runs certificate authorities, signs code, and discovers cryptographic assets, defending conventional data, application, network, and device trust, so it is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Keyfactor names the pain precisely and a non-vendor source corroborates it: certificate lifetimes are collapsing toward 47 days while quantum standards force a cryptographic migration, and NIST is urging administrators to begin transitioning now. The buyers are enterprise security and PKI teams managing growing certificate volumes. [s9, s3, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The capability set is documented and independently checked: Keyfactor owns the open-source EJBCA authority, which carries Common Criteria certification against the NIAP Protection Profile for Certification Authorities, and sponsors the FIPS 140-3 validated Bouncy Castle cryptographic module. That is differentiation across multiple data points. [s4, s15, s16, s19] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Two dated buyer-side forces drive demand inside the window: NIST finalized its post-quantum standards in 2024 and public certificate lifetimes are moving toward 47 days, both of which make certificate automation a baseline requirement. [s9, s3, s1] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Cofounder Ted Shorter is listed as CTO of a company shipping cryptographic products since 2001, verifiable in-domain experience that places the team at the experienced-operator level rather than a category-defining exit or sustained independent recognition. [s2, s14] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Traction is multiply sourced: BankInfoSecurity independently reported Sixth Street's minority investment valuing Keyfactor near $1.3 billion, Keyfactor reports a top placement in Frost & Sullivan's 2024 PKI-as-a-Service Frost Radar, and the customer wall names Schneider Electric, Siemens, ServiceNow, and M&T Bank. [s10, s20, s11, s2] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Keyfactor reached a roughly $1.3 billion valuation on disclosed funding of $77M in 2019 and $125M in 2021, with visible output in integrated acquisitions and shipping cadence, but as a private company it discloses no independently confirmed revenue or margin, so efficiency cannot be verified. [s10, s8] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | PKI and certificate lifecycle management is an established category that analysts track and buyers place without coaching, and Frost & Sullivan benchmarks a named PKI-as-a-Service market, but Keyfactor is one of several players rather than the definer (Venafi is the named category creator of machine identity management) and the Frost placement is read off its own page, which fits 4 not 5. [s11, s20, s8, s13] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Keyfactor is itself an incumbent with an open-source install base and CA-agnostic depth, but its value sits between commoditizing basic certificate management below it and identity giants such as CyberArk folding machine identity into access suites above it, and its EJBCA-based private and enterprise PKI is not the publicly trusted root position that a higher score would require. [s13, s4] |
Keyfactor addresses an operational crisis building inside enterprise cryptography. Certificates that once lasted years now expire in weeks, and the company points to a twelvefold rise in renewals as public TLS lifetimes shrink toward 47 days. A missed renewal takes production systems down, so the manual tracking most organizations still rely on is becoming untenable.
A non-vendor force corroborates the urgency. NIST finalized its first post-quantum encryption standards in 2024 and urges administrators to begin transitioning now, which means enterprises must first find every place quantum-vulnerable cryptography is used. Most organizations lack that visibility today.
The buyers are enterprise security, PKI, and infrastructure teams at large regulated organizations. They carry both the duty of keeping certificates current at machine speed and a multi-year cryptographic migration, and Keyfactor sells to both needs from one platform. [s1, s3, s9]
Keyfactor spans the machine-identity stack from certificate authority to lifecycle automation to cryptographic discovery. Keyfactor Command discovers and inventories every certificate and key, including post-quantum and hybrid certificates, and automates issuance and renewal from one console.
The distinctive asset is owning the certificate authority and sponsoring the cryptography beneath it. EJBCA, which Keyfactor describes as the most widely used open-source PKI, is certified against the Common Criteria Protection Profile for Certification Authorities, the certification the US Commercial Solutions for Classified program requires, and the Bouncy Castle libraries Keyfactor sponsors carry a FIPS 140-3 validation listed by NIST. That open-source stack is a transparency advantage closed competitors cannot match by writing software.
The cryptographic-discovery layer is the newest addition. The 2025 InfoSec Global and CipherInsights acquisitions added cryptographic asset discovery, the ability to update cryptography without source-code changes, and passive network monitoring of cryptographic risk, which Keyfactor packaged in 2026 as a Trust Control Plane for machine identities and cryptographic assets. [s3, s4, s15, s16, s19, s5, s7]
Keyfactor competes in a category identity platforms are actively consolidating. CyberArk completed its acquisition of Venafi, the vendor that created the machine-identity management category, from Thoma Bravo in 2024, and DigiCert, Entrust, AppViewX, and Sectigo round out the field. That consolidation leaves Keyfactor a focused independent while peers fold into broader platforms.
Keyfactor turns the consolidation into positioning. Its pitch is to choose a vendor devoted to certificates and cryptography rather than one whose roadmap now serves a broader access-management strategy, and the open-source EJBCA authority plus CA-agnostic automation are the differentiation it leans on. VentureBeat framed the 2021 PrimeKey merger as the move that gave Keyfactor end-to-end machine identity from authority to lifecycle.
The same dynamic is the threat. The platforms validating the market by buying into it become the competitors, and an identity giant or hyperscaler could absorb the focused position from above with a suite or below with bundled basics. [s13, s8, s4]
Keyfactor backs its scale claims with named references and outside validation. The enterprise customer wall names Schneider Electric, Siemens, ServiceNow, and M&T Bank, and Sixth Street's 2023 minority investment valued the company near $1.3 billion, which BankInfoSecurity reported independently.
An analyst benchmark reinforces the position. Frost & Sullivan benchmarks a named PKI-as-a-Service market in its 2024 Frost Radar, scoring vendors on growth and innovation, and Keyfactor displays a resulting top placement on its own pages.
The growth figures originate with the company. Keyfactor's own release reports more than 1,500 organizations and a three-year revenue CAGR over 70 percent, repeated in press without audited revenue, so the headline rate rests on the company's own accounting even where the customer names are verifiable. [s10, s11, s20, s6, s2]
Keyfactor pairs founding continuity with a built-out executive bench. Cofounder Ted Shorter remains Chief Technology Officer of a company that has shipped cryptographic products for over two decades, originally as Certified Security Solutions before the November 2018 rebrand to Keyfactor.
The leadership roster lists a full operating team under CEO Jordan Rackie. The credibility signal is sustained domain operation and the integration of PrimeKey and InfoSec Global rather than a marquee exit history, which is the appropriate read for an established category vendor. [s2, s14, s6]
Keyfactor's products are themselves trust infrastructure, so buyers scrutinize its cryptographic provenance closely. The open-source EJBCA codebase gives enterprises inspectable certificate-authority software, a transparency advantage for security teams running their own private trust.
The audited posture is documented in independent registries. EJBCA carries Common Criteria certification against the NIAP Protection Profile for Certification Authorities, the certification the US Commercial Solutions for Classified program requires, and the Bouncy Castle FIPS Java API that Keyfactor sponsors holds a FIPS 140-3 validation listed by the NIST Cryptographic Module Validation Program.
The products also help customers meet their own mandates. The cryptographic-discovery line ships templates for standards such as PCI DSS and HIPAA, which lowers a buyer's audit burden, though that is a feature serving the customer's obligation rather than Keyfactor's own federal authorization. [s4, s15, s16, s19, s5]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| CyberArk | adjacent | Identity security incumbent that acquired certificate lifecycle leader Venafi from Thoma Bravo in 2024, folding machine identity into its access-management platform. | |
| Venafi | competes with | The vendor that created the certificate lifecycle category, now CyberArk Machine Identity Security and Keyfactor's primary head-to-head rival. | |
| DigiCert | competes with | Public certificate authority and certificate lifecycle vendor competing for the same enterprise PKI automation budget. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Entrust | competes with | PKI and HSM incumbent selling into the same enterprise trust and machine-identity programs. | |
| SandboxAQ | competes with | Post-quantum and cryptographic discovery specialist competing on the crypto-agility and quantum-readiness front Keyfactor entered through acquisition. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with Keyfactor.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Once an enterprise roots its certificate authority, issuance policies, automation, and machine identities in Keyfactor, its grip on issuance and lifecycle workflows suggests switching friction, though the record does not document replacement scope. Operating certificate authorities at scale is demanding engineering. The open-source EJBCA core is Common Criteria certified and the sponsored Bouncy Castle module is FIPS 140-3 validated, an independently audited posture. Against that, customers buy software, self-hosted or hosted by the vendor, the core is reproducible by a funded rival, and no named cross-customer data asset appears. The watch item is whether that install-base lock holds against an identity platform bundling certificate management into a suite the buyer already owns.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy the software platform (Command, EJBCA, signing, cryptographic discovery), self-hosted or in Keyfactor-hosted delivery that includes managed private PKI operations, and the record shows no judgment layer accepting accountability for security outcomes, the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Replacing Keyfactor means reissuing certificates and re-pointing issuance policies, automation, and machine identities, friction at the reissuance-and-workflow level, and the public record does not document the scope of the replacement work or a dependence beyond it. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | EJBCA is Common Criteria certified against the NIAP Protection Profile for Certification Authorities, the certification the US Commercial Solutions for Classified program requires, and Keyfactor sponsors the FIPS 140-3 validated Bouncy Castle module, an independently audited cryptographic posture above customer-facing templates. It is not the absolute liability gate a 3 would need. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Running certificate authorities at enterprise scale, automating millions of renewals, and updating cryptography without source-code changes for a post-quantum migration is security-critical cryptography and distributed-systems engineering that takes years of specialized expertise. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Keyfactor has sold the line to large regulated enterprises and governments at scale, with named references including Schneider Electric, Siemens, ServiceNow, and M&T Bank and the company reporting an install base above 1,500 organizations, where procurement slows replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | The certificate authority and lifecycle automation sit in the authentication and trust path other systems depend on to function, and a missed certificate renewal takes production systems down, infrastructure rather than an end-user application. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The EJBCA core is open-source and reproducible by definition, and while the 2025 acquisitions added cryptographic-agility technology, no named non-public cross-customer data corpus appears in the record. Any advantage is engineering and install base rather than an accumulated data asset. |
Keyfactor targets the enterprise that must manage cryptographic trust at machine scale across hybrid and multi-cloud estates. The buyer is the security, PKI, and infrastructure leader accountable for the certificates, keys, and machine identities that keep production systems trusted, and the pain is concrete: certificate volumes are exploding while public TLS lifetimes shrink toward 47 days, so a missed renewal takes systems down.
The segment skews to large regulated organizations and governments. The customer wall names Schneider Electric, Siemens, ServiceNow, and M&T Bank, and the company reports an install base above 1,500 organizations, accounts where procurement and audit gate any change to trust infrastructure.
The post-quantum transition widens the same segment rather than replacing it. NIST finalized its post-quantum standards in 2024 and urges immediate migration, which reframes the certificate buyer as the same leader now accountable for finding and replacing quantum-vulnerable cryptography across the estate.
Keyfactor spans the trust stack from certificate authority to lifecycle automation to cryptographic discovery on one platform. Keyfactor Command discovers and inventories every certificate and key, including post-quantum and hybrid certificates, and automates issuance and renewal from one console, which lets a buyer consolidate work most enterprises run with scripts and spreadsheets.
The differentiator is owning the certificate authority and sponsoring the cryptography beneath it. EJBCA, which Keyfactor describes as the most widely used open-source PKI, is Common Criteria certified against the NIAP Protection Profile for Certification Authorities, and the Bouncy Castle libraries Keyfactor sponsors hold a FIPS 140-3 validation. That open-source, independently audited stack is a transparency advantage a closed competitor does not share.
The cryptographic-agility layer is the newest capability and the one tied to the AI and quantum framing. The 2025 InfoSec Global and CipherInsights acquisitions added cryptographic asset discovery, the ability to update cryptography without source-code changes, and passive network monitoring of cryptographic risk, which Keyfactor packaged in 2026 as a Trust Control Plane for machine identities and cryptographic assets.
Go-to-market rests on a large named-reference base and a channel motion appropriate to the company's scale. The enterprise customer wall names Schneider Electric, Siemens, ServiceNow, and M&T Bank rather than anonymized logos, and the company reports more than 1,500 organizations using its products.
Outside validation extends beyond customer counts. BankInfoSecurity reported that Sixth Street's 2023 minority investment valued the company near $1.3 billion, a financial-sponsor signal a younger vendor cannot manufacture, and Keyfactor reports a top placement in Frost & Sullivan's 2024 PKI-as-a-Service Frost Radar.
What the record qualifies is that the growth figures originate with Keyfactor. The 70 percent three-year CAGR and customer count trace to the company's own release, repeated in press, with no audited revenue disclosed, so the headline rate rests on the company's own accounting even where the customer names are verifiable.
Keyfactor publishes no list pricing. The public pages market the products and their capabilities without dollar figures or a public pricing tier, and the sales path routes through demo requests, the shape of a sales-led enterprise motion.
The implied unit of value is the trust estate under management, and the pages publish no per-unit pricing mechanics, so an outside reader gets no forecastable benchmark for what a deployment costs.
The absence of published pricing fits security and PKI teams buying through procurement, and the public pages show no self-serve purchase path.
Keyfactor delivers across the deployment shapes its enterprise buyers require. Keyfactor Command runs on-prem, in the cloud, in a Kubernetes cluster, or combined with fully managed PKI, and EJBCA deploys on-prem or in the cloud, so a customer can place trust infrastructure wherever its compliance and architecture demand.
The operational core is continuous discovery and automated lifecycle rather than manual tracking. The platform continuously discovers and inventories every certificate and key, including post-quantum and hybrid certificates, and automates renewal, which is what makes a 47-day certificate world operable where manual processes fail.
The heavier operational question is that the product becomes part of the trust path. A certificate authority and lifecycle automation that issue the credentials production systems depend on are a dependency whose failure blocks trusted connections, so a careful security review probes availability, disaster recovery, and the integrity of the issuance pipeline before rooting trust in it.
Keyfactor sells trust infrastructure, so its own provenance is scrutinized closely. The EJBCA codebase is open-source, giving enterprises inspectable certificate-authority software, a transparency posture that matters to security teams running their own private trust and a genuine differentiator against closed competitors.
Vendor documentation and the NIST CMVP registry document the audited posture. EJBCA holds Common Criteria certification against the NIAP Protection Profile for Certification Authorities, the certification the US Commercial Solutions for Classified program requires, and the Bouncy Castle FIPS Java API that Keyfactor sponsors holds a FIPS 140-3 validation under the NIST Cryptographic Module Validation Program, the kind of independent checks regulated buyers require.
The cryptography it ships still carries operational risk a buyer must weigh. NVD records CVE-2022-34831, a critical flaw in EJBCA before 7.9.0 that let a non-compliant client obtain a certificate for names that were never validated, so a careful buyer probes the integrity of the issuance pipeline and patch currency before rooting trust in it.
Keyfactor positions as a platform other systems depend on for trust, not a feature inside one cloud's identity service. The 2026 Trust Control Plane frames the products as a unified operating model for machine identities and cryptographic assets, so the platform sits underneath the systems that consume its certificates and keys across public and private authorities.
The breadth was assembled partly through acquisition. VentureBeat reported that the 2021 PrimeKey merger added the EJBCA certificate authority alongside a $125 million Insight Partners round, and the 2025 InfoSec Global and CipherInsights deals added cryptographic discovery and agility, so the platform consolidates capabilities a typical enterprise would otherwise buy from several vendors.
The EJBCA open-source community is a real outward asset. A widely used open-source certificate authority gives Keyfactor a broad deployment base, though the public pages document integration breadth more than a third-party builder marketplace.
Keyfactor pairs founding continuity with a built-out operating bench. Cofounder Ted Shorter remains Chief Technology Officer of a company that has shipped cryptographic products for over two decades, originally as Certified Security Solutions before the 2018 rebrand, which gives the team sustained domain standing in a field where credibility compounds slowly.
The leadership roster lists a full executive team under CEO Jordan Rackie, the bench an at-scale category vendor needs to run channel, finance, and the integration of multiple acquisitions.
The credibility signal is operating longevity and execution rather than a marquee serial-exit pedigree. Keyfactor has integrated PrimeKey and InfoSec Global while reaching a roughly $1.3 billion valuation, which is the track record that matters for an established vendor even absent the research-publication record that lifts the strongest startup teams.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | About Keyfactor mission and cryptography | official | 2026-06-20 |
| f2 | Certified Security Solutions re-brands as Keyfactor (Nov 1, 2018) | official | 2026-06-21 |
| f3 | Exa company record Keyfactor headquarters | research | 2026-06-20 |
| f4 | Keyfactor minority investment from Sixth Street Growth (~$1.3B) | official | 2026-06-20 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Keyfactor homepage trust infrastructure “Trust Infrastructure for AI & Machines ... 12x Increase in certificate renewals with 47-day TLS lifespans. Certificates expire in weeks, not years. Outages take down critical systems.” | official | 2026-06-29 |
| s2 | Keyfactor about page customer wall and compliance marks “Schneider-Electric-logo ... Siemens-Logo ... ServiceNow-logo ... mT-bank ... Keyfactor maintains certifications and compliance with the world's leading regulatory and security frameworks. FedRAMP_Logo ... AICPA SOC logo” | official | 2026-06-29 |
| s3 | Keyfactor Command certificate lifecycle automation “With Command, you'll continuously discover and inventory every certificate and key, including post-quantum (PQ) and hybrid certificates, from one console” | official | 2026-06-20 |
| s4 | EJBCA Enterprise open-source PKI “Powered by the most trusted and widely used open-source PKI, EJBCA Enterprise empowers teams to establish trust with identity-first security for every human and machine, anywhere.” | official | 2026-06-20 |
| s5 | Keyfactor acquires InfoSec Global and CipherInsights “"These acquisitions mark a major leap forward in securing digital trust," said Jordan Rackie, CEO, Keyfactor. "We're uniting the best of the best, the most advanced discovery capabilities for cryptographic assets at rest and in motion” | official | 2026-06-20 |
| s6 | Keyfactor Sixth Street minority investment (~$1.3B) “trusted by more than 1,500 organizations to build and maintain digital trust. Increasing market demand has resulted in Keyfactor's staggering three-year revenue CAGR of over 70%.” | official | 2026-06-20 |
| s7 | Keyfactor launches Trust Control Plane “CLEVELAND, Ohio - June 9, 2026 - Keyfactor, the leader in trust infrastructure for AI and machines, today announced the Trust Control Plane, a unified operating model for the machine identities and cryptographic assets” | official | 2026-06-20 |
| s8 | VentureBeat: Keyfactor raises $125M and merges with PrimeKey (Chris O'Brien, Apr 15, 2021) “The first is a merger with PrimeKey, which creates the certificates that serve as crucial tools for identifying machines. The second is $125 million in new funding to power growth and comes two years after the company raised $77 million.” | press | 2026-06-29 |
| s9 | NIST finalizes first 3 post-quantum encryption standards “NIST is encouraging computer system administrators to begin transitioning to the new standards as soon as possible.” | research | 2026-06-29 |
| s10 | BankInfoSecurity: Keyfactor earns $1.3B valuation (Michael Novinson, Oct 24, 2023) “A machine identity management provider led by a former Tricentis executive notched a $1.3 billion valuation after receiving a minority investment from Sixth Street Group.” | press | 2026-06-29 |
| s11 | Frost & Sullivan: Frost Radar PKI-as-a-Service 2024 (Keyfactor profiled) “Frost & Sullivan analyzes numerous companies in an industry. Those selected for further analysis based on their leadership or other distinctions are benchmarked across 10 Growth and Innovation criteria to reveal their position on the Frost Radar” | research | 2026-06-29 |
| s12 | NVD CVE-2022-34831: Keyfactor PrimeKey EJBCA ACME validation bypass (CVSS 9.8 Critical) “An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0 ... a non-compliant client can include additional dnsNames the CSR sent to the finalize endpoint, resulting in EJBCA issuing a certificate including the identifiers that were not validated.” | research | 2026-06-29 |
| s13 | CyberArk completes acquisition of Venafi (Oct 1, 2024) “the successful completion of its acquisition of Venafi, a leader in machine identity management, from Thoma Bravo ... Venafi is a cybersecurity market leader and the category creator of machine identity management” | press | 2026-06-29 |
| s14 | Certified Security Solutions re-brands as Keyfactor “CLEVELAND, Ohio - November 1, 2018 - Certified Security Solutions (CSS), a leading provider of secure digital identity management solutions, has rebranded as Keyfactor. The company, established in 2001” | official | 2026-06-21 |
| s15 | EJBCA Enterprise achieves Common Criteria certification (NIAP cPP, CSfC) “PrimeKey's EJBCA Enterprise has achieved Common Criteria certification conformant to the Protection Profile for Certification Authorities ... the certification is a mandatory requirement to be part of the Commercial Solutions for Classified (CSfC) Program.” | official | 2026-06-29 |
| s16 | NIST CMVP certificate 4943: Bouncy Castle FIPS Java API, FIPS 140-3 “Module Name BC-FJA (Bouncy Castle FIPS Java API) Standard FIPS 140-3 Status Active ... Overall Level 1 ... Module Type Software” | research | 2026-06-29 |
| s17 | NVD CVE-2023-34196: Keyfactor EJBCA RA servlet partial DoS (CVSS 8.2 High) “In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates to unauthenticated or less privileged users may occur.” | research | 2026-06-29 |
| s18 | The Quantum Insider on the Keyfactor InfoSec Global acquisition “Key capabilities include AgileSec Analytics for deep cryptographic visibility, AgileSec Agility for managing and updating cryptography without source code changes, and CipherInsights for real-time passive network monitoring of cryptographic risks.” | press | 2026-06-20 |
| s19 | Keyfactor announces NIST FIPS 140-3 certification for Bouncy Castle “As a sponsor of the Legion of the Bouncy Castle, the charitable organization behind Bouncy Castle, Keyfactor enables continued development and FIPS certification for the popular APIs.” | official | 2026-06-29 |
| s20 | Keyfactor recognized as the leader in PKI-as-a-Service by Frost & Sullivan (vendor-displayed) “named the top leader in Frost & Sullivan's 2024 Frost Radar for PKI-as-a-Service (PKIaaS). Keyfactor was recognized as the strongest performer on both the Innovation and Growth Indexes for its innovative PKIaaS offering” | official | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Keyfactor homepage trust infrastructure “Trust Infrastructure for AI & Machines ... 12x Increase in certificate renewals with 47-day TLS lifespans. Certificates expire in weeks, not years. Outages take down critical systems.” | official | 2026-06-29 |
| s2 | Keyfactor Command certificate lifecycle automation “With Command, you'll continuously discover and inventory every certificate and key, including post-quantum (PQ) and hybrid certificates, from one console, so nothing slips by.” | official | 2026-06-20 |
| s3 | EJBCA Enterprise open-source PKI “Powered by the most trusted and widely used open-source PKI, EJBCA Enterprise empowers teams to establish trust with identity-first security for every human and machine, anywhere.” | official | 2026-06-20 |
| s4 | About Keyfactor mission and leadership “Cryptography is the foundation of trust. It protects data, verifies identities, and secures connections. ... Jordan Rackie CEO Ted Shorter CTO & Cofounder” | official | 2026-06-29 |
| s5 | Keyfactor acquires InfoSec Global and CipherInsights “"These acquisitions mark a major leap forward in securing digital trust," said Jordan Rackie, CEO, Keyfactor. "We're uniting the best of the best, the most advanced discovery capabilities for cryptographic assets at rest and in motion” | official | 2026-06-20 |
| s6 | Keyfactor Sixth Street minority investment (~$1.3B) “trusted by more than 1,500 organizations to build and maintain digital trust. Increasing market demand has resulted in Keyfactor's staggering three-year revenue CAGR of over 70%.” | official | 2026-06-20 |
| s7 | Keyfactor launches Trust Control Plane “CLEVELAND, Ohio - June 9, 2026 - Keyfactor, the leader in trust infrastructure for AI and machines, today announced the Trust Control Plane, a unified operating model for the machine identities and cryptographic assets” | official | 2026-06-20 |
| s8 | VentureBeat: Keyfactor raises $125M and merges with PrimeKey (Chris O'Brien, Apr 15, 2021) “The first is a merger with PrimeKey, which creates the certificates that serve as crucial tools for identifying machines. The second is $125 million in new funding to power growth and comes two years after the company raised $77 million.” | press | 2026-06-29 |
| s9 | BankInfoSecurity: Keyfactor earns $1.3B valuation (Michael Novinson, Oct 24, 2023) “A machine identity management provider led by a former Tricentis executive notched a $1.3 billion valuation after receiving a minority investment from Sixth Street Group.” | press | 2026-06-29 |
| s10 | NIST finalizes first 3 post-quantum encryption standards “NIST is encouraging computer system administrators to begin transitioning to the new standards as soon as possible.” | research | 2026-06-29 |
| s11 | NVD CVE-2022-34831: Keyfactor PrimeKey EJBCA ACME validation bypass (CVSS 9.8 Critical) “An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0 ... a non-compliant client can include additional dnsNames the CSR sent to the finalize endpoint, resulting in EJBCA issuing a certificate including the identifiers that were not validated.” | research | 2026-06-29 |
| s12 | EJBCA Enterprise achieves Common Criteria certification (NIAP cPP, CSfC) “PrimeKey's EJBCA Enterprise has achieved Common Criteria certification conformant to the Protection Profile for Certification Authorities ... the certification is a mandatory requirement to be part of the Commercial Solutions for Classified (CSfC) Program.” | official | 2026-06-29 |
| s13 | NIST CMVP certificate 4943: Bouncy Castle FIPS Java API, FIPS 140-3 “Module Name BC-FJA (Bouncy Castle FIPS Java API) Standard FIPS 140-3 Status Active ... Overall Level 1 ... Module Type Software” | research | 2026-06-29 |
| s14 | Keyfactor about page customer wall and compliance marks “Schneider-Electric-logo ... Siemens-Logo ... ServiceNow-logo ... mT-bank ... Keyfactor maintains certifications and compliance with the world's leading regulatory and security frameworks. FedRAMP_Logo ... AICPA SOC logo” | official | 2026-06-29 |
| s15 | Frost & Sullivan: Frost Radar PKI-as-a-Service 2024 (Keyfactor profiled) “Frost & Sullivan analyzes numerous companies in an industry. Those selected for further analysis based on their leadership or other distinctions are benchmarked across 10 Growth and Innovation criteria to reveal their position on the Frost Radar” | research | 2026-06-29 |
| s16 | NVD CVE-2023-34196: Keyfactor EJBCA RA servlet partial DoS (CVSS 8.2 High) “In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates to unauthenticated or less privileged users may occur.” | research | 2026-06-29 |
| s17 | Certified Security Solutions re-brands as Keyfactor “CLEVELAND, Ohio - November 1, 2018 - Certified Security Solutions (CSS), a leading provider of secure digital identity management solutions, has rebranded as Keyfactor. The company, established in 2001” | official | 2026-06-21 |
| s18 | Keyfactor announces NIST FIPS 140-3 certification for Bouncy Castle “As a sponsor of the Legion of the Bouncy Castle, the charitable organization behind Bouncy Castle, Keyfactor enables continued development and FIPS certification for the popular APIs.” | official | 2026-06-29 |
| s19 | Keyfactor recognized as the leader in PKI-as-a-Service by Frost & Sullivan (vendor-displayed) “named the top leader in Frost & Sullivan's 2024 Frost Radar for PKI-as-a-Service (PKIaaS). Keyfactor was recognized as the strongest performer on both the Innovation and Growth Indexes for its innovative PKIaaS offering” | official | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.