Keyfactor
Keyfactor provides digital identity management and cryptographic trust infrastructure for enterprises, built on its Trust Control Plane platform that orchestrates machine identities, keys, and certificates across hybrid environments, serving over 40% of the Fortune 500.
- Company typePrivate
- Founded2001
- HeadquartersIndependence, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingSoftware
What Keyfactor does
Keyfactor is a privately held cybersecurity company that provides digital identity management and cryptographic trust infrastructure for global enterprises. Founded in 2001 and headquartered in Independence, Ohio, the company has scaled to 501-1000 employees and reached unicorn status at a $1.3 billion valuation following an undisclosed Series E led by Sixth Street in October 2023, with cumulative funding of approximately $218 million across prior rounds.
The company's core offering is the Trust Control Plane, a unified cryptographic operating platform launched in June 2026 that orchestrates machine identities, keys, and certificates across enterprise environments through a five-stage loop (Observe, Analyze, Provision, Orchestrate, Govern). Underlying components include EJBCA Enterprise (a Common Criteria-certified and NSA CSfC-approved PKI platform built on the most widely deployed open-source PKI core, inherited from the July 2021 PrimeKey merger), Keyfactor Command for certificate lifecycle automation, PKI as a Service for fully managed cloud-hosted PKI, AgileSec for cryptographic discovery and inventory, SignServer and Signum for high-volume digital signing, and the Bouncy Castle cryptographic libraries. EJBCA and Bouncy Castle anchor an open-source ecosystem that, together with deep integrations across ITSM (ServiceNow), HSM (Thales, Utimaco), DevOps, and cloud (AWS, Azure, GCP) platforms, supports a developer- and ecosystem-led go-to-market posture. Keyfactor serves more than 40% of the Fortune 500, including Schneider Electric, Siemens, ServiceNow, M&T Bank, and RSA Security, with quantified customer outcomes such as a 356% ROI and $12.7M in benefits over three years per a 2026 Forrester Total Economic Impact study.
Keyfactor generates revenue primarily through subscription and license fees: PKI as a Service subscriptions with unlimited certificate issuance and no per-certificate fees; EJBCA Enterprise licensing across SaaS, cloud, software appliance, and hardware appliance deployment models; Keyfactor Command recurring revenue deployed on-prem, as CLAaaS/PKIaaS/SaaS Lite, or via Kubernetes; managed 24/7 PKI operations bundled with PKI as a Service; and digital signing subscriptions and usage fees for SignServer and Signum. Enterprise pricing is quote-based and not publicly disclosed; free 30-day Test Drives, AWS and Azure Marketplace listings (including the Command MCP Server for AI-assisted certificate operations), a global channel partner network (Climb Channel Solutions in North America, CyberKnight in MEA, F5 ADSP, IBM Consulting joint quantum-safe solution), and flagship events such as Tech Days 2027 in San Diego round out the commercial motion.
Keyfactor firmographics
Firmographics- Name
- Keyfactor
- Legal name
- Keyfactor Inc.
- Website
- https://www.keyfactor.com
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- Keyfactor provides digital identity management and cryptographic trust infrastructure for enterprises, built on its Trust Control Plane platform that orchestrates machine identities, keys, and certificates across hybrid environments, serving over 40% of the Fortune 500.
- Ownership category
- akta.pro rank
Keyfactor industry classification
Industry- Product category
- Public Key Infrastructure (PKI) and Machine Identity Management
- NAICS
- Software Publishers (5132), Financial Transactions Processing, Reserve, and Clearinghouse Activities (522320)
- SIC
- Finance Services (6199), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Blockchain Data & Indexing Infrastructure for Finance (Nodes, Indexers, Oracles) (FSAGAMAL)
Keywords
Where Keyfactor is headquartered
LocationHeadquarters
- HQ city
- Independence
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Keyfactor business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- PKI as a Service Subscription: Recurring subscription revenue from cloud-hosted, single-tenant private PKI deployments with 24/7 security operations, unlimited certificate issuance, and no per-certificate fees.
- Certificate Lifecycle Automation (Command): Recurring subscription/license revenue from Keyfactor Command deployed on-prem, as CLAaaS, PKIaaS, SaaS Lite, or Kubernetes; combined with Keyfactor Orchestrators and pre-built plugins.
- EJBCA Enterprise Licensing: License and appliance revenue from EJBCA Enterprise PKI deployed as SaaS, Cloud, Software Appliance, or Hardware Appliance (with built-in HSM).
- Managed Services: 24/7 PKI expert operations, patch management, vulnerability testing, backup and recovery, CA/CRL renewals, and incident response delivered as part of PKI as a Service.
- Digital Signing Services (SignServer / Signum): Subscription and usage revenue from high-volume signing engine (SignServer) and policy-driven signing-as-a-service (Signum) for code, containers, firmware, and documents.
- Events & Sponsorships: Revenue from Keyfactor Tech Days conference registration (Early Bird $449, Standard $549, Full Rate $699) and sponsor/speaker ecosystem.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | PKI as a Service — fully managed cloud PKI subscription with unlimited certificate issuance and no per-certificate fees |
| Subscription | Annual | EJBCA Enterprise — turnkey PKI platform available as SaaS, Cloud, Software Appliance, or Hardware Appliance |
| Subscription | Annual | Keyfactor Command — certificate lifecycle automation; CLAaaS, SaaS Lite (Azure), or self-hosted |
| Subscription | Annual | Signum — policy-driven cloud signing-as-a-service with built-in cloud HSM |
| Subscription | Annual | AgileSec — Cryptographic Discovery & Inventory, deployable on-prem or in the cloud |
| Other | Pay-as-you-go | Keyfactor Tech Days 2027 conference registration tiers |
Go-to-market motion1 record
Distribution channels6 records
Marketing channels8 records
Keyfactor product offering
Product offeringCore offering
Keyfactor sells a unified cryptographic operating platform (the Trust Control Plane) and an integrated product portfolio that issues, manages, and automates the lifecycle of machine identities, digital certificates, cryptographic keys, and code-signing operations across enterprise, cloud, IoT, and AI agent environments. Its products include EJBCA Enterprise PKI, Keyfactor Command for certificate lifecycle automation, fully managed PKI as a Service, AgileSec cryptographic discovery, SignServer/Signum digital signing, Enterprise Code Signing, and the Bouncy Castle open-source cryptographic libraries.
Product overview
Keyfactor offers a platform-plus-modules architecture centered on the Keyfactor Trust Control Plane, a unified cryptographic operating platform that orchestrates machine identities, keys, and certificates across enterprise environments. The Trust Control Plane comprises five stages (Observe, Analyze, Provision, Orchestrate, Govern) and is delivered through a portfolio of products and modules including Keyfactor Command (Certificate Lifecycle Automation), EJBCA Enterprise (Modern PKI Platform), Keyfactor PKI as a Service, Keyfactor AgileSec (Cryptographic Discovery and Inventory), Cryptographic Posture Management, Enterprise Code Signing, Signum (Signing as a Service), SignServer Enterprise (Signing Platform), Bouncy Castle APIs (Cryptographic Libraries), SSH Key Management, and IoT Identity Management. These components are designed to interoperate as a single trust infrastructure, supporting crypto-agility and post-quantum cryptography readiness for AI and machine identity workloads.
Differentiator
Problem solved
Functional benefit
Brands
- Keyfactor EJBCA Enterprise: Modern PKI platform for issuing trust identities across environments, deployed as SaaS, cloud, software, or hardware appliance.
- Keyfactor Command
- Keyfactor AgileSec
- Keyfactor SignServer
- Keyfactor Signum
Products and services
- Keyfactor Trust Control Plane Unified cryptographic operating platform that orchestrates machine identities, keys, and certificates across enterprise environments through five stages (Observe, Analyze, Provision, Orchestrate, Govern). Delivers visibility, identity issuance, lifecycle automation, and crypto-agility for AI-era and post-quantum environments.
- EJBCA Enterprise (Modern PKI Platform) Quantum-ready private PKI platform built on the most widely used open-source PKI (EJBCA). Issues cryptographically verifiable identities for devices, workloads, and users. Deployable as EJBCA SaaS, Cloud, Appliance, or Software with support for ACME, SCEP, EST, CMP, and Microsoft Autoenrollment.
- Keyfactor PKI as a Service Fully managed, cloud-hosted private PKI combining 24/7 security operations with certificate lifecycle automation. Deployed in a dedicated single-tenant cloud environment with built-in Cloud FIPS 140-3 HSM protection, always-offline air-gapped root CA, and unlimited certificate issuance.
- Keyfactor Command (Certificate Lifecycle Automation) Observe and orchestrate layer of Keyfactor's Trust Control Plane that delivers complete visibility, lifecycle governance, and zero-touch automation for every certificate across any CA, cloud, and environment. Deployable on-premises, as CLAaaS, PKIaaS, SaaS Lite, or Kubernetes.
- Keyfactor AgileSec (Cryptographic Discovery and Inventory) Continuously discovers and inventories cryptographic assets (keys, certificates, algorithms, protocols, libraries) across systems, endpoints, networks, cloud environments, and code repositories. Identifies vulnerabilities and prioritizes risks to accelerate post-quantum readiness.
- Enterprise Code Signing Flexible and secure digital signing solution that protects integrity and authenticity of code, software, containers, AI, and documents. Includes policy-driven signing and high-performance API-based signing, with keys stored in HSMs.
- Signum (Signing as a Service) Fully cloud-hosted signing-as-a-service solution with a built-in cloud HSM. Integrates with platform-native signing tools such as SignTool, Jarsigner, and Cosign, with automated policy enforcement embedded in every signing operation.
- SignServer Enterprise (Signing Platform) Centralized, server-side signing engine designed for high-volume signing and time-stamping workloads. Enables signing via web interface or API and is available as a turnkey software appliance, hardware appliance, or in the cloud.
- Bouncy Castle Cryptographic Libraries Trusted, quantum-resilient cryptographic APIs that enable developers to build secure applications. The Bouncy Castle open-source library is supported and offered by Keyfactor as part of its Cryptographic Libraries product line.
- IoT Identity Management Capability that embeds certificate-based identity into thousands or millions of connected products, providing a fast and scalable PKI solution for product security teams across IoT and connected device deployments.
- Keyfactor Command MCP Server MCP server enabling AI-assisted certificate operations and secure digital trust infrastructure for agentic AI workflows, distributed via AWS Marketplace.
Quantifiable outcome
- 356% ROI over three years; $12.7M in benefits; payback under six months
- +6 more outcomes
Companies that use Keyfactor
Customer profileNamed customers1 record
Ideal customer profiles4 records
Keyfactor technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability9 records
Feature8 records
Keyfactor partnerships and signals
Strategic signalPartnerships
15 partnerships are on record, tiered flagship, core and minor.
- IBM ConsultingflagshipJoint solution for enterprise quantum-safe modernization combining Keyfactor's cryptographic discovery, PKI, digital signing, and certificate lifecycle automation with IBM Consulting's cybersecurity expertise and Quantum Safe Migration Orchestrator. Establishes Cryptographic Centers of Excellence to drive long-term crypto-agility as enterprises prepare for NIST and global regulatory standards.
- F5flagshipKeyfactor joined F5's Application Delivery and Security Platform (ADSP) Partner Program as one of seven Select-tier strategic partners, providing enterprises with a unified multicloud security ecosystem. Delivers validated interoperable certificate lifecycle automation and PKI integration.
- ServiceNowflagshipNew and enhanced integrations with ServiceNow — Keyfactor Command with ServiceNow ITSM, Keyfactor EJBCA with ServiceNow ITOM, and Keyfactor AgileSec Analytics with ServiceNow Vulnerability Response — available on the ServiceNow Store. Enables enterprise customers to automate certificate issuance, discovery, lifecycle management, and cryptographic vulnerability monitoring directly within the ServiceNow AI Platform. Integration between Keyfactor Command and Service Graph Connector expected later that year.
- CyberKnightcoreCyberKnight joined the Keyfactor Partner Network to promote machine identity management and security solutions across the Middle East and Africa, supporting digital trust and compliance in finance, government, and healthcare.
- InfoSec GlobalcoreAcquired by Keyfactor on May 13, 2025 to expand cryptographic discovery and asset management capabilities within the PKI ecosystem. Capabilities combined into the Trust Control Plane offering for MSSPs.
- CipherInsights (Quantum Xchange)coreAcquired by Keyfactor on May 13, 2025 alongside InfoSec Global. CipherInsights capabilities are now part of Keyfactor's Trust Control Plane for MSSP cryptographic lifecycle management.
- Climb Channel SolutionscoreNorth American channel partner announced by Climb Channel Solutions to distribute Keyfactor's digital trust and machine identity management solutions to enterprises across the region.
- PrimeKeyflagshipMerger completed under the Keyfactor brand; PrimeKey provided flexible private PKI and certificate authority software (EJBCA Enterprise is built on the EJBCA open-source core originally developed by PrimeKey). Merged entity focuses on PKI as-a-Service and machine identity management.
- Amazon Web Services (AWS)coreCloud integration and EJBCA SaaS availability in AWS.
- Microsoft AzurecoreEJBCA SaaS availability and Command SaaS Lite listing in Azure Marketplace.
- ThalescoreIntegration with Thales HSM referenced on the Cryptographic Posture Management integrations page.
- CrowdStrikecoreEDR integration referenced on the Cryptographic Posture Management integrations page.
- UtimacocoreHSM integration referenced on the Cryptographic Posture Management integrations page.
- VenaficoreIntegration referenced on the Cryptographic Posture Management integrations page; competitor/adjacent ecosystem pairing.
- Insight PartnersminorIdentified by Insight Partners as a vendor in the emerging Agent IAM theme; potential deal-flow partner for enterprise security M&A.
Scale indicators12 records
Recent moves7 records
Expansion highlights6 records
Keyfactor competitors and assessment
Company assessmentDirect peers
- DigiCert: DigiCert is one of the largest public and private certificate authorities and the dominant TLS/SSL certificate provider. It directly competes with Keyfactor's EJBCA Enterprise and PKI as a Service in private PKI and certificate lifecycle management, and was named alongside Keyfactor in ABI Research's Enterprise PKI Vendor Competitive Ranking.
- Entrust: Entrust is a long-standing PKI and certificate authority vendor offering on-prem and managed PKI, HSMs, and identity verification solutions. It competes head-to-head with Keyfactor in enterprise PKI and post-quantum readiness, and was also named in ABI Research's Enterprise PKI ranking.
- Venafi (CyberArk): Venafi is a leading machine identity management platform focused on certificate lifecycle automation and cryptographic key management. Now part of CyberArk, it is the closest direct competitor to Keyfactor Command and is listed by Keyfactor itself as both an integration partner and adjacent ecosystem competitor.
- Sectigo: Sectigo is a certificate authority providing public TLS/SSL and private enterprise PKI, including automated certificate issuance and IoT identity use cases. It competes with Keyfactor in private PKI deployments, IoT device identity, and certificate lifecycle automation.
- AppViewX: AppViewX is a certificate lifecycle automation and PKI management platform serving large enterprises with machine identity, DevOps, and NetOps certificate use cases. It directly competes with Keyfactor Command in the certificate lifecycle automation category.
Emerging players
- HashiCorp Vault: HashiCorp Vault is a widely adopted secrets and certificate management platform used for dynamic PKI, transit secrets, and machine identity. It overlaps with Keyfactor's certificate lifecycle and signing capabilities, particularly in DevOps and cloud-native environments, though it does not focus on enterprise PKI modernization.
- Fortanix: Fortanix is a data security and HSM-as-a-service provider with a Confidential Computing platform and key management offerings. It competes with Keyfactor on cloud HSM-backed signing (Signum) and adjacent cryptographic key management use cases for enterprises.
Broad incumbents
- CyberArk: CyberArk is a broad identity security incumbent specializing in privileged access management, and acquired Venafi to add machine identity management. Its expanded portfolio competes with Keyfactor's certificate lifecycle, signing, and PKI offerings, particularly in regulated industries.
- AWS Private Certificate Authority: AWS Private CA is a managed private certificate authority service native to the AWS cloud, deeply integrated with AWS workloads and services. It competes with Keyfactor's PKI as a Service and EJBCA SaaS for cloud-native customers standardized on AWS.
- Microsoft Active Directory Certificate Services: Microsoft AD CS is the de facto on-prem PKI for many enterprises and is bundled with Windows Server. It is the incumbent that Keyfactor's Modernize PKI and EJBCA replacement motions target, particularly where customers need stronger crypto-agility and discovery.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Keyfactor social profiles
Digital presenceKeyfactor compliance and trust
Trust signalCompliance5 records
Keyfactor financial estimates
Financial estimateRevenue estimate
Valuation estimate
Keyfactor leadership team
Management profileNumber of profiles
Profiles20 records
Keyfactor subsidiaries and ownership
Company hierarchySubsidiaries3 records
Keyfactor funding detail
Funding detailFunding overview
Funding rounds8 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Keyfactor M&A and investment
M&A and investmentM&A4 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Keyfactor
What does Keyfactor do?
Keyfactor sells a unified cryptographic operating platform (the Trust Control Plane) and an integrated product portfolio that issues, manages, and automates the lifecycle of machine identities, digital certificates, cryptographic keys, and code-signing operations across enterprise, cloud, IoT, and AI agent environments. Its products include EJBCA Enterprise PKI, Keyfactor Command for certificate lifecycle automation, fully managed PKI as a Service, AgileSec cryptographic discovery, SignServer/Signum digital signing, Enterprise Code Signing, and the Bouncy Castle open-source cryptographic libraries.
Is Keyfactor a public or private company?
Keyfactor is a private company. It is classified as venture growth investor backed and is currently operating.
When was Keyfactor founded?
Keyfactor was founded in 2001. It employs 501 to 1,000 people.
Where is Keyfactor based?
Keyfactor is headquartered in Independence, United States, in the North America region.
How does Keyfactor make money?
Six revenue lines are on record. PKI as a Service Subscription is the primary driver. The others are certificate Lifecycle Automation (Command), EJBCA Enterprise Licensing, managed Services, digital Signing Services (SignServer / Signum) and events & Sponsorships.
Who are Keyfactor's main competitors?
Direct peers on record are DigiCert, Entrust, Venafi (CyberArk), Sectigo and AppViewX. Emerging players are HashiCorp Vault and Fortanix. Broad incumbents are CyberArk, AWS Private Certificate Authority and Microsoft Active Directory Certificate Services.
Does Keyfactor have an API?
Yes. Keyfactor offers multiple developer-facing APIs across its product line. EJBCA Enterprise supports REST, SOAP, ACME, SCEP, EST, CMP, and Microsoft Autoenrollment APIs for certificate enrollment and issuance. Keyfactor Command provides a REST API, pre-built plugins, and Keyfactor Orchestrators for certificate lifecycle automation. SignServer exposes a web interface and API for high-volume signing workloads. Signum integrates with native signing tools such as SignTool, Jarsigner, and Cosign. The Keyfactor Command MCP Server is available in AWS Marketplace to support AI-assisted certificate operations. Developer documentation is at docs.keyfactor.com.
What industry is Keyfactor in?
Keyfactor's product category is Public Key Infrastructure (PKI) and Machine Identity Management. Its primary akta.pro industry code is FSAGAMAL, Blockchain Data & Indexing Infrastructure for Finance (Nodes, Indexers, Oracles). Its NAICS code is 5132 and its SIC code is 6199.