Skip to main content

What is Sectigo Edge?

Sectigo Edge is a private PKI service that makes every certificate a two-party decision. A trust node that you run in your own environment (a Mesh Node) and Sectigo's globally distributed trust service must both approve the exact same request before your certificate authority signs anything.

Sectigo Edge landing page with the headline Edge security, reliability at scale, and the Create your account and Explore the demo buttons
The public Sectigo Edge site. Create your account starts the workspace sign-up described in this section.

The problem it solves​

Traditional hosted PKI concentrates authorization in one administrative plane. If that plane is compromised, an attacker can issue trusted certificates.

Sectigo Edge splits that authority:

  • Your environment is a required participant. Your Mesh Node evaluates every request against your policy, locally.
  • Sectigo independently checks the same request. The edge evaluates the identical, immutable transaction and keeps its own policy and lifecycle controls.
  • Only dual-approved requests reach the signer. Your CA (Sectigo Certificate Manager or a CA you bring) signs only when both sides agree.

If one side is compromised, the other side still says no.

How an issuance works​

StepWhoWhat happens
1. Workload requestsYour workloadAuthenticates locally and asks for a tightly scoped identity.
2. Your node decidesYour Mesh NodeYour policy evaluates the exact CSR, SANs, algorithm, validity and requester.
3. Sectigo decidesSectigo EdgeIndependently evaluates the same immutable transaction digest.
4. Your CA signsYour CAOnly dual-approved evidence reaches Sectigo SCM or your protected CA signer.

The main pieces​

What you can do with it​

  • Issue and inventory certificates for services, workloads and AI agents, with every request evaluated by both trust domains.
  • Rotate without downtime. Optional dual-slot mode stages the new certificate beside the one already serving, checks it, then promotes it atomically. Failed checks leave the active certificate untouched.
  • Plan cryptographic migrations, including post-quantum readiness, using evidence of what your endpoints can actually consume.
  • Prove what happened. Every issuance produces signed, hash-chained audit evidence on both sides that you can export.
  • Contain incidents with an issuance kill switch and break-glass controls that require a second, independent approver.

Where it fits​

Sectigo Edge does not replace your CA. It sits between your workloads and your signing authority:

  • Workloads keep using open protocols (ACME, EST, SPIFFE, mTLS) against a nearby Mesh Node.
  • Your CA keeps signing, but only for requests that both your node and Sectigo approved.
  • Your identity provider can be connected for enterprise SSO. A Sectigo Edge email-and-password account (with MFA) is also available.
Try it before you sign up

The live product demo runs the full console against isolated sample data (Acme Corporation). It never grants production access.

Next steps​