Post-Quantum Issuance. Production-Ready.
ZetaCA signs in ML-DSA. Classical, hybrid or full PQC — your choice. Your certificates are future-proof today.
Loading
ZetaCA issues classical (RSA, ECDSA) and post-quantum (ML-DSA, FIPS 204) certificates designed to withstand cryptanalytic attacks from quantum computers as currently understood. Validated on Utimaco u.trust GP, PKCS#11-compatible.
Available for proof of concept and integration projects.

Post-quantum issuance on every deployment mode. Your infrastructure, your constraints. ZetaCA adapts.
Sovereign hosting in France/EU. Fully managed.
Your servers. Docker Compose or VM. Automated deployment.
Fully disconnected. Built for classified and critical environments.
ZetaCA signs in ML-DSA. Classical, hybrid or full PQC — your choice. Your certificates are future-proof today.
Native PKCS#11 compatible. Tested and validated on Utimaco u.trust GP HSM (CryptoServer firmware). Works with any PKCS#11-compliant HSM.
| Subject | Status |
|---|---|
| api.zetacert.com | ISSUED |
| vault.internal | ISSUED |
| iot-gateway-01 | ISSUED |
| expired-legacy.corp | EXPIRED |
| dev-signing-key | REVOKED |
| new-service.staging | PENDING |
Technology Partnership
Hardware protection for your cryptographic keys. Classical and post-quantum.
ZetaCA natively integrates with Utimaco u.trust GP HSMs (CryptoServer firmware) via PKCS#11 R3. Your private keys stay in hardware, non-exportable, protected by certified silicon. From classical PKI to post-quantum cryptography, without changing your infrastructure.
PCIe or network HSM (Se-Series, CSe-Series). Certified CryptoServer firmware, centralized key management for enterprise deployments.
Post-quantum application package activated in-field. ML-DSA in hardware via PKCS#11, NIST CAVP testing during the 2025 cycle (certificate references available on request).
Private keys never leave the HSM. Certified hardware protection.
CA key rotation without service interruption. Guaranteed cryptographic continuity.
Engineered for what's next.
Strong device identity at scale. Millions of certificates, lightweight footprint, zero compromise on security.
Pick your level of orchestration: ZetaCA as a standalone CA for isolated or air-gapped environments, or paired with PKIFactor for multi-CA centralised governance.
Cryptographic power meets orchestration intelligence. The complete enterprise PKI stack.
ZetaCA Editions
Classical PKI with Starter. HSM and high availability with Enterprise. Post-quantum native with Quantum.
Compare EditionsAvailable for proof of concept and integration projects.