Implementations

Built on this
architecture.

This document describes a model; an implementation operationalizes it. If you are building one, we would like to hear from you.

How this page works

Listing an implementation.

How a listing works

An implementation states for itself how it meets each required capability.

Whether a conformance suite, a test harness or a certification body should exist is Open Question 2, and it is genuinely open. Until it is answered, read a listing against the required capabilities.

Implementation

ANKASecure©

A Crypto Agility Orchestration Platform built by ANKATech Solutions INC. It operationalizes the model: governed applications invoke cryptographic operations using key identifiers, while the platform resolves the applicable policy, lifecycle state and cryptographic mechanism, then coordinates execution through the appropriate cryptographic infrastructure.

Its capabilities contribute across the CAPA pillars rather than mapping to them individually. Cryptographic execution, key custody and Roots of Trust may remain distributed across designated HSMs, KMS platforms and trust domains, including PKCS#11-based environments, with the platform providing a common governance and orchestration layer above them. It supports classical, hybrid and post-quantum mechanisms, including NIST FIPS 203/204/205 (ML-KEM, ML-DSA, SLH-DSA) with hybrid coexistence.

ankatech.co →
Open invitation

Building an implementation?

Implementations of this architecture are welcome here, from any organization. Build against the required capabilities and get in touch to be listed.

Questions and corrections are equally welcome. Where the document is ambiguous or turns out to be wrong, open an issue and it gets fixed in public.

contact@cryptographiccontrolplane.org →
One requirement worth reading twice Required capability 05 — coordination across distributed trust infrastructure. A platform that requires all keys or Roots of Trust to reside in a single provider, repository or cryptographic failure domain does not implement this architecture, whatever else it provides. Centralized governance must not become centralized cryptographic risk, and that constraint is not negotiable within this model.