A public-interest redesign of website certificates — ready for the quantum era. See how it works →
The problemWhy certificates break trust
The solutionYour keys, checked by many
Who runs itNo single party in charge
Questions & answersShort answers, no jargon
About the project

Infrastructure should belong to no one in particular

ConsensusPKI is a public-interest project: a certificate system whose security doesn't depend on trusting any single company, government or operator — including us.

The initiative

From research question to working system

ConsensusPKI began as academic research into a stubborn question: why does the security of every website still depend on the honesty of hundreds of organisations, any one of which can speak for all of them? The question grew into a design, the design into formal proofs, and the proofs into a working reference implementation.

The project is developed and stewarded by Nextarp B.V., a Rotterdam-based engineering company working in digital trust, identity and financial infrastructure. The intent is for governance of the deployed system — its validators, witnesses and policies — to be distributed across independent organisations, because that distribution is the security model.

A peer-reviewed paper is in preparation, and the reference implementation, formal models and cost models will be opened alongside it.

  • Research-first: claims are proven or measured before they're published
  • Honest about limits: what the design cannot defend against is documented as prominently as what it can
  • Built in the open: reproducible artifacts, public test vectors
  • Designed for shared governance from day one
Principles

Rules we don't bend

No single point of trust

Not a company, not a log operator, not a government — and not the project's own founders. Every power in the system is checked by an independent majority.

Privacy is not negotiable

Verifying a website must never tell anyone which websites you visit. The design forbids online lookups entirely rather than promising to be careful with them.

Say what it can't do

No security system is absolute. The design's limits — what it cannot defend against — are documented with the same care as its guarantees.

Contact

Talk to the team

Questions about the project, the research, or a potential pilot? We answer email from researchers, journalists, certificate authorities, public-sector teams and the simply curious.

Email: info@consensuspki.org
Initiative of: Nextarp B.V., Otto Reuchlinweg 1142, 3072 MD Rotterdam, The Netherlands
Company site: nextarp.com

For media & speaking

We're glad to explain the certificate system, the quantum transition, or this project — at any technical level, in English or Dutch. Reach out via the address on the left.