Operational CPS status: internal private PKI. The offline root signs only constrained subordinate authorities through a recorded ceremony. Online issuing authorities are profile-scoped, keys are encrypted at rest, sensitive profiles require role-separated approvals, and revocation data is published through stable CDP locations.
This repository does not assert public or regulated external trust. See the repository for current authority material and fingerprints.