Keyfactor Raises Over $1 Billion to Tackle AI and Post-Quantum Security
The investment backs technology that manages digital certificates and cryptographic keys, as companies race to prepare for a generation of threats that today's encryption may not survive.

Key points
- Keyfactor received more than $1 billion in investment funding, reported by SecurityWeek.
- The money targets Keyfactor's platform for managing machine identities and cryptographic security.
- PKI, or Public Key Infrastructure, is the system of digital certificates that proves a website or device is genuine.
- The investment is partly driven by concerns about post-quantum computing, meaning computers powerful enough to crack the encryption protecting most internet traffic today.
- Enterprises are also under pressure to manage AI-driven security risks, where automated systems create millions of new digital identities that must each be verified.
Keyfactor builds software that tracks and manages digital certificates. Think of a digital certificate as an ID badge for a website or a connected device. When your browser shows a padlock in the address bar, a certificate is what made that padlock appear. Organisations can have thousands running at once, and when one expires or gets stolen, things break or criminals slip through.
Why does a billion-dollar investment matter to ordinary people?
It matters because the security of certificates behind everyday services, online banking, hospital records, payment terminals, is only as good as the tools managing them. Keyfactor's pitch is that existing tools aren't ready for two arriving problems.
The first is AI. Automated systems now spin up new devices and services at a pace humans can't track manually. Each needs its own digital identity. The second is post-quantum computing. Quantum computers process information in a fundamentally different way from conventional machines and are expected to eventually break the encryption most businesses rely on today. Security researchers call this the harvest-now-decrypt-later threat: criminals collect encrypted data now, planning to crack it once the hardware catches up. NIST published its first three post-quantum standards in 2024; a year later, only 5% of security teams had a defined strategy.
Neither threat has caused a widespread breach yet. The window for preparation isn't infinite.
Keyfactor's platform handles PKI management and what the industry calls machine identity: the automated issuing, renewal and revocation of certificates across a network. The billion-plus investment is intended to speed up product development and expand the company's reach.
Should you worry about your own exposure?
If your business relies on digital certificates, and most do even if IT staff handle them quietly in the background, now is a reasonable time to ask two questions: how many certificates are you running, and do you know when each one expires? Expired certificates are among the most common causes of outages and security gaps, and among the most preventable.
Post-quantum readiness is a longer project. The White House has mandated that high-value federal assets shift to post-quantum cryptography by 2030, and Microsoft pulled its own deadline forward to 2029. Organisations that start auditing their cryptographic dependencies now will scramble far less when standards shift.



