DigiCert, Inc. - Experts & Thought Leaders
Latest DigiCert, Inc. news & announcements
DigiCert, a pioneer in intelligent trust, announces support for the NVIDIA Open Agent Safety Platform to help enterprises establish verifiable identity and authority for autonomous AI agents. At the centre of the NVIDIA Open Agent Safety Platform is NVIDIA OpenShell, an open, secure runtime that places infrastructure-level controls around autonomous agents. OpenShell permits nothing by default, enforces policy outside the agent’s process, and records every decision to allow or deny an action. Infrastructure-level controls DigiCert complements those controls with DigiCert AI Trust Manager, which helps organisations discover and manage the AI agents they own or operate, establish each agent’s verifiable identity and ownership, define what it is authorised to do, and revoke that authority with a kill switch when trust changes. Together, the technologies address two critical requirements for autonomous AI: identifying which agent is acting and controlling what an agent can do. “AI agents are starting to do real work across business systems, and that means companies need to know exactly which agent is acting, what it’s allowed to do, and when to stop it,” said Amit Sinha, CEO of DigiCert. “NVIDIA helps create the boundary around the agent. DigiCert helps establish who that agent is and what authority it has. Together, that gives enterprises a much clearer way to put autonomous AI to work with control and accountability.” Security-policy enforcement NVIDIA OpenShell lets an agent retain its reasoning and skills while every file, network, process, credential, and inference call crosses a boundary controlled by the platform. Because enforcement occurs outside the agent’s process, even a compromised agent cannot override the restrictions. NVIDIA Sentry on BlueField-4, powered by NVIDIA DOCA, adds hardware-isolated, out-of-band monitoring of agent activity and security-policy enforcement that does not depend on the host. NVIDIA Vera supplies the compute for agents’ CPU-intensive workloads. DigiCert AI Trust Manager extends the OpenShell environment with enterprise-class agent management built around identity, authority, policy, and lifecycle control. DigiCert AI Trust Manager gives each agent a DigiCert AI Passport, a portable, cryptographically signed credential that verifies an agent’s identity and connects it to an accountable owner. Policy-based “visas” define which systems, data, and actions the agent may access, as well as how long that authority lasts. Same identity provider Because the DigiCert AI Passport and its permissions travel with the agent, other systems and organisations can independently verify them without relying on the same identity provider. If an agent attempts a prohibited action, DigiCert’s automated kill switch can block it and, under policies set by the agent’s owner or passport issuer, revoke its authority at the source and quarantine it. DigiCert’s support for NVIDIA Open Agent Safety Platform is designed around four areas: Identity that policy can act on. Agents running within an OpenShell environment can be associated with an AI Passport so policies can rely on verified identity. Verification before execution. Agents, models, and MCP servers can be signed and associated with an AI Bill of Materials to help establish what is being deployed before execution. Auditable evidence. OpenShell records policy allow-and-deny decisions. DigiCert’s approach is designed to bind trusted identity and cryptographic evidence to those interactions, creating a stronger record for governance and audit. Trust across company boundaries. PKI already enables independent verification of identity across the internet. DigiCert is extending that same trust model to agents so organisations can verify AI identities even when agents interact across companies, clouds and technology environments. Providing verifiable identity The approach is designed to complement, not replace, the security controls provided by NVIDIA Open Agent Safety Platform. NVIDIA establishes and enforces the agent’s operating boundary. DigiCert provides verifiable identity and authority that can persist as the agent interacts beyond that boundary. “As agents begin interacting with other agents beyond company lines, identity cannot depend on every participant belonging to the same identity system,” Sinha said. “We need a trust model that can cross those boundaries. PKI solved that problem for the internet at scale, and we believe the same foundation has an important role to play in establishing trust for autonomous agents.” DigiCert AI Trust Manager support for NVIDIA Open Agent Safety Platform begins with NVIDIA OpenShell, with additional capabilities planned as DigiCert and NVIDIA continue to advance enterprise AI trust and agent security.
DigiCert, a pioneer in intelligent trust, announces the general availability of DigiCert Quantum Central, part of the DigiCert ONE platform, that helps organisations manage and demonstrate progress toward post-quantum cryptography (PQC) readiness. First introduced in preview in July, Quantum Central offers expanded capabilities that help organisations move from finding cryptographic risks to managing them. Teams can bring together cryptographic data from multiple sources, apply their own security policies, initiate remediation workflows, assign ownership, and track progress from a central location. Trackable readiness program The launch comes as organisations struggle to turn PQC planning into execution. According to the 2026 DigiCert Quantum Readiness Outlook, 87% of organisations are planning, testing or implementing PQC initiatives, yet only 7% have deployed quantum-safe or hybrid cryptography. “Most organisations understand the quantum risk. Their challenge is coordinating action across legacy systems, fragmented data and multiple technology owners,” said Kevin Hilscher, Senior Director of Product Management at DigiCert. “Quantum Central turns cryptographic visibility into a prioritised and trackable readiness program. Teams can begin with a critical environment, act on what they find and expand over time, while giving leadership, auditors and regulators clear evidence of progress.” Cryptographic bills of materials Quantum Central helps security, IT, risk and compliance teams: Create a unified cryptographic inventory: Consolidate and normalise data from DigiCert ONE, network scans, certificate lifecycle management platforms, key vaults, uploaded CSV files and software or cryptographic bills of materials. Establish policies and priorities: Define cryptographic policies based on organisational requirements, industry standards, and regulatory guidance. Quantum Central evaluates inventory data, identifies policy violations and alerts teams when action is needed. Turn findings into remediation: Translate policy violations into recommended actions and create change requests through established workflows, including Jira. Integration with DigiCert Trust Lifecycle Manager enables teams to initiate certificate lifecycle actions directly from their readiness program. Interpret inventory data faster: Use an inventory-aware AI assistant to understand findings, explore cryptographic exposure and identify practical next steps. Measure and report progress: Track remediation status, policy compliance, and overall cryptographic posture through centralised dashboards. Organisations can also export inventory data as cryptographic bills of materials for audits, assessments, and reporting. Connect external systems: Import cryptographic data programmatically through an API, allowing organisations to continue expanding their inventory as their readiness programs mature. Post-quantum readiness “The market is entering the operational phase of post-quantum readiness, and enterprises need a way to connect cryptographic discovery with business context, policy and remediation,” said Jennifer Glenn, Research Director for Information and Data Security at IDC. “Tying inventory, workflows, and reporting to that policy in a single view gives organisations a practical operating model for the complex, multiyear transition to quantum-safe cryptography.” Quantum readiness requires organisations to manage a multiyear technology transition while standards, vendor capabilities and regulatory expectations continue to evolve. Organisations can make practical progress now by assigning accountable owners, establishing enough cryptographic visibility to set priorities, adopting PQC where supported and documenting results. An incremental approach allows teams to begin with a critical application environment or infrastructure layer and expand their program without waiting for a complete enterprise-wide inventory. Complex PKI transition Quantum Central is the management layer for enterprise quantum readiness, spanning cryptographic use cases beyond PKI. DigiCert ONE managers provide the automation layer for certificates, software, devices and content, while DigiCert Private CA and CertCentral provide the trust and issuance foundation needed to put new cryptography into production. That combination helps organisations manage the broader readiness program while preparing for the more complex PKI transition that will unfold over time. DigiCert Quantum Central is available now. Organisations can start a free trial, request a demonstration or contact DigiCert to discuss an enterprise deployment. Resources: Organisations can deploy PQC today to protect their network traffic from harvest now, decrypt later attacks. Read their white paper, Recommendations for Quantum Safe TLS, for more details. Check the quantum readiness of the organisations and others’ websites with their online PQC Checker. Learn the basics about post quantum cryptography and understand the urgency to start quantum readiness now in DigiCert’s PQC for Dummies Guide.
DigiCert, a pioneer in intelligent trust, announces the general availability of DigiCert AI Trust Manager, part of the DigiCert ONE platform. The new solution helps organisations discover and manage the AI agents they own or operate, establish each agent’s verifiable identity and ownership, define what it is authorised to do, and revoke that authority with a kill switch when trust changes. AI agents can access sensitive data, use software tools, write code, make decisions, and complete transactions with limited human involvement. Yet most enterprise security systems were not built to govern autonomous agents moving across applications, clouds, and organisations at machine speed. Enterprise security systems The risks are already emerging. In a July 2026 DigiCert survey of 1,001 IT and cybersecurity leaders, 78% said their organisations had experienced an AI-related security incident or identified an AI vulnerability during the previous year. “For more than two decades, DigiCert has provided the cryptographic infrastructure that helped the internet scale,” said Amit Sinha, CEO of DigiCert. “We are now bringing that proven trust model to AI agents so organisations can verify who they are, who owns them, and what they are authorised to do.” Traditional identity systems Traditional identity systems work like employee badges, establishing trust within a single organisation. At the centre of DigiCert AI Trust Manager is the DigiCert AI Passport. It’s a portable, cryptographically signed credential that verifies an agent’s identity and connects it to an accountable owner. Policy-based “visas” define which systems, data, and actions the agent may access, as well as how long that authority lasts. Because the DigiCert AI Passport and its permissions travel with the agent, other systems and organisations can independently verify them without relying on the same identity provider. A receiving organisation can deny the agent access within its own environment. If the agent attempts a prohibited action, DigiCert’s automated kill switch blocks it and, under policies set by the agent’s owner or passport issuer, can immediately revoke its authority at the source and quarantine it before harm occurs. DigiCert AI Trust Manager allows enterprises to: Find and identify agents: Discover AI agents that were purchased, built internally or operating within the business, and connect each one to an accountable owner. Set clear limits: Define the systems, data, and actions an agent may access, and how long its permission remains valid. Extend trust across organisations: Allow other systems and companies to independently verify an agent without requiring both parties to use the same identity provider. Respond when trust changes: Update credentials, expire permissions, or revoke an individual agent or groups of agents upon policy, risks, or any other changes. New class of autonomous systems "Enterprise AI buying has moved from trust to proof. Buyers are ranking verifiable security controls as their top priority and name unverifiable vendor claims as their top frustration,” said Grace Trinidad, Research Director, AI Security and Trust, IDC. “Cryptographic identity, attestation, and revocation for agents, models, and MCP servers are the machinery that produces this proof, which in turn produces trust, and DigiCert is pointing the identity discipline the internet already runs at scale at exactly that problem." “As AI agents become more embedded in enterprise workflows, establishing clear identity and accountability will be essential to deploying them responsibly at scale,” said Ajitha Choudary, Vice President of Global Security Engineering & IAM at UKG. “We see DigiCert AI Trust as a promising approach to extending proven principles of digital identity to this new class of autonomous systems. The ability to verify an agent’s identity, define what it is authorised to do, and maintain visibility into its actions could give organisations the foundation they need to adopt agentic AI with greater confidence.” DigiCert AI Trust Manager is part of DigiCert’s broader AI trust architecture, which applies cryptographic verification across AI agents, models, and content. It complements existing identity and cybersecurity systems by providing a portable foundation for verifying an agent’s identity and authority wherever it operates.
Technology's role in securing banks and financial institutions
DownloadSecurity technologies promote real-time awareness in K-12 schools
DownloadIntegrated systems enable critical and compliant security for transportation
DownloadModernising physical access control
DownloadAccess. Intrusion. One estate.
Download