Russia’s SafeTech CA Evolves Into a Full-Fledged Digital Certificate Management Platform With an Agent-Based Subsystem
Russian developer SafeTech Lab has expanded the capabilities of its enterprise certificate authority, SafeTech CA, announcing a new CDM (Certificate Delivery Management) module. The developers say this is a major functional expansion of the product with no equivalent on either the Russian or international market. The module will make it possible to fully automate certificate delivery and manage the lifecycle of digital certificates on endpoint devices.

In the future, this technology could improve the efficiency and resilience of banks, industrial enterprises, government agencies and other organizations, since an expired or incorrectly installed certificate can disrupt an information system. Automation reduces the likelihood of such errors and helps keep business operations running without interruption.
A Long-Standing Need
SafeTech CA’s new functionality grew out of a longstanding customer need. Organizations that need to manage certificates, including their delivery, expiration monitoring and automatic renewal, often have to buy large, expensive PKI platforms with functionality they do not need. That creates additional costs, extends deployment timelines and requires dedicated staff to manage the entire workflow. As a result, the market has long needed an affordable, straightforward product that provides the most commonly used certificate management capabilities.
What sets SafeTech CA apart? Its developers have built certificate management on client nodes directly into the certificate authority itself. Customers no longer have to find a third-party solution, connect it to the CA and create a complex integration between separate products. Everything they need – certificate issuance, agent-based delivery, installation in the appropriate certificate store and automatic renewal – is now built into SafeTech CA through the new CDM module.
The new CDM (Certificate Delivery Management) service is the first agent-based subsystem embedded directly within the certificate authority itself. It can manage the entire lifecycle of technology certificates. Administrators can manage the agents, which can independently issue certificates on target nodes, monitor the validity of certificates already issued and automatically reissue them when necessary. A key advantage of the technology is its support for GOST (Russian national standard) cryptographic algorithms while remaining completely independent of domain infrastructure. The agents can operate in isolated segments and in environments without an LDAP directory (Lightweight Directory Access Protocol).

Convenience and Cost Savings Come First
Together, these new capabilities turn SafeTech CA from a conventional certificate authority into a full-fledged digital certificate management platform. Today, SafeTech CA is the only solution that can handle the most widely needed certificate management tasks across all components of an organization’s IT environment while cutting costs by eliminating unused functionality. The product turns PKI (public key infrastructure) management into a straightforward, transparent process.
The developers plan to keep expanding the platform. Future development of the CDM module will focus on making the agent more autonomous and deepening its integration with target systems. To make management easier, the SafeTech CA web interface will allow users to manually initiate certificate issuance and delivery to an agent and track task status, providing real-time visibility into the delivery process. The new version also adds other capabilities, including root and subordinate CA certificate rotation, configuration management through the web interface, and integration with HashiCorp Vault, a modern tool for centralized secrets storage and rotation. Over time, adding the CDM module to SafeTech CA could improve the resilience of banks, industrial enterprises and other organizations by minimizing the use of expired or incorrectly installed certificates.

Building Digital Trust
At the national level, projects like this represent a significant step toward replacing foreign PKI infrastructure with domestic technology. Russia’s enterprise certificate authority market previously relied almost entirely on foreign solutions, but it now includes four Russian enterprise CAs – SafeTech CA, Aladdin Enterprise CA, Avanpost CA and Clearway CA. The CDM module’s main prospects are tied to the development of a Russian technology stack for digital trust management.
The SafeTech CA enterprise certificate authority has been added to Russia’s software registry and received fourth-level trust certification from FSTEC of Russia in January this year. The technology is already used in industry, the public sector, retail and telecommunications. Experts expect demand for it to grow because of the global trend toward shorter certificate lifetimes. For example, while public TLS certificates governed by the CA/Browser Forum previously had validity periods of up to 200 days, that period will fall to 47 days starting in March 2029.

The product also has international potential. SafeTech CA supports the international RSA, ECDSA and EdDSA algorithms and standard public key infrastructure protocols, making it technically possible to deploy the solution outside Russia. The developer already has experience in international markets: SafeTech Group products are available in Belarus, Uzbekistan and Kyrgyzstan. The most realistic export opportunities are in CIS countries and other markets where Russian IT products already have established distribution channels.









































