Consulting
Cryptography is not a product – it is a discipline.
Our team combines deep expertise in cryptography and key management with many years of project experience in demanding corporate environments.
We know the underlying standards and algorithms in detail – from the bit level to the management presentation. This combination of theoretical foundation and practical implementation competence enables us to address even complex requirements securely and sustainably.
Why Professional Consulting is decisive
Cryptographic key management and public key infrastructures are the foundation of digital security – but their complexity is frequently underestimated. Errors in architecture or implementation often only become apparent late, but are then difficult and costly to correct.
We advise vendor-neutrally and align with open standards – from RFC, PKIX and PKCS to the recommendations of NIST and BSI. Our goal is a meaningful architecture that is not only secure and standards-compliant, but can also be operated long-term and economically.
Typical challenges:
- Inconsistent, unclear or incomplete requirements for the crypto infrastructure
- Grown structures without consistent architecture or governance
- Uncertainty in selecting appropriate standards, algorithms and products
- Missing internal policies for the use of cryptographic methods
- Open questions on preparing for post-quantum cryptography
With our experience from numerous projects, we help you avoid these risks – and build a security architecture that fits your organisation.
Our Consulting Services
Cryptography Consulting and PQC Strategy
We advise you on all aspects of applied cryptography: from the selection of suitable algorithms and protocols to the evaluation of existing implementations and the development of company-wide cryptography strategies.
Of increasing importance is the preparation for post-quantum cryptography (PQC). The standardisation of new, quantum-resistant methods by NIST and IETF is progressing, and organisations must prepare early for the migration. We actively track current developments in this area and support you in developing a practical migration strategy.
Services overview:
- Evaluation and selection of cryptographic methods and standards
- Analysis of existing crypto implementations and identification of weaknesses
- Development of cryptography policies and governance frameworks
- PQC readiness analysis and migration strategy
Architecture, Design and Policies
A powerful security infrastructure begins with a well-thought-out architecture. We analyse your specific requirements – technical, organisational and regulatory – and develop a tailored solution from them.
Our core competence lies in designing customer-specific PKI architectures that map the entire certificate lifecycle: from issuance through renewal and revocation to secure key management with Hardware Security Modules (HSMs). We also design security architectures for specialised deployment scenarios, for example in IoT or for distributed cloud infrastructures.
Our expertise:
- Customer-specific PKI design and architecture, design of certificate profiles
- Need-adapted use of HSMs for cryptographic key management
- Security architectures for IoT, cloud and distributed systems
- Development of internal cryptography and key management policies through to the definition of Certificate Policies (CP) and Certificate Practice Statements (CPS)
Implementation & Specialist Solutions
Consulting doesn't end on paper with us. Our team has solid development competence and can also accompany special requirements in implementation – from adapting existing systems to developing new cryptographic components from scratch.
We rely on proven technologies and our own products such as OpenXPKI and clca, adapt these specifically to customer-specific requirements and develop tailored solutions in Go or C if required.
We support you with:
- Development of cryptographic applications and protocol implementations
- Customisation and extension of PKI solutions, especially OpenXPKI
- Integration with existing IT systems and infrastructure components
- Prototyping and proof-of-concept development
Our Approach
1.
2.
No PKI without a concept. We develop a tailored strategy for your key management.