ConsensusPKI doesn't replace the organisations that run the internet's trust — it gives them a stronger role in a system no single party can subvert. Here's what it means for yours.
The hard, valuable work a CA does is validation — proving that a party really controls a domain or really is who they claim. ConsensusPKI keeps all of that. What it removes is the unilateral signing power that turns every CA into a single point of catastrophic failure and a magnet for liability.
You become a validator: your existing validation infrastructure and audit regime carry over, your attestations are publicly auditable, and your signature can no longer be the thing that mis-issues a certificate for a domain you've never dealt with. Less risk, same expertise, a clearer role.
National digital identity, eIDAS-era trust services and the European Digital Identity Wallet all rest on public-key infrastructure. Building that on a model where any one authority can impersonate any party is a strategic vulnerability — and one a hostile state actor understands well.
ConsensusPKI offers infrastructure where no single operator, and no single compromised authority, can subvert the binding between a name and a key — with a migration path to post-quantum security that doesn't require a flag day. Its guarantees are formally verified, and its evidence trail survives even a future quantum adversary.
Designed around the NIST post-quantum standards (ML-DSA, SLH-DSA) and the transparency mechanisms already deployed at web scale. The approach is compatible with the direction of ETSI trust-service standards and European post-quantum migration roadmaps — a complement to that work, not a competitor to it.
High-value domains can set a one-way flag that disables remote recovery entirely: from then on, only your own key can ever change your records. No support-desk social-engineering path, no authority that can be leaned on.
Because the record's integrity rests on hashing, its history stays tamper-evident even against a future quantum adversary — the forensic trail survives when signatures alone would not.
Your customers' browsers verify without contacting anyone. No third party learns who visits your services, and no outage of an external checker can take your site offline.
ConsensusPKI exists as a complete design with a working reference implementation, machine-verified security proofs and reproducible cost models. A peer-reviewed paper is in preparation. We're now looking for the right partners to pressure-test it.
Whether you run a certificate authority, a public-sector trust service, or a large enterprise PKI, we'd welcome a conversation about where ConsensusPKI could fit.