Security · Post-quantum PKI · Operations

Automate security, PKI and operations.

Zero Medium builds software that automates security, certificate and business operations, including the move to post-quantum cryptography, so your team spends its time on decisions instead of scripts. Every line is designed, written and supported in the United States.

  • KeystoneOur automation platform
  • SignedEvery module & agent update
  • 100%US-developed software
Keystone New

The automation platform for security & IT operations.

Keystone sends signed, trusted automation to every machine you manage, then brings the results back as data you can track, chart, alert on and act on. Discovery, certificate renewal, inventory and remediation stop being one-off scripts and become audited, permission-checked workflows, across every organization you look after. Hybrid-AI drafts the automation for you, but only signed, human-approved code ever runs on your machines.

Endpoint agent fleet

A single static agent for Windows and Linux that runs only trusted code, works on its own schedule and keeps results safe until they're delivered.

  • Signed self-updates with staged rollouts
  • Per-device settings from the console

Signed modules & actions

Versioned, signed modules run on agents or central workers. Interfaces separate what you ask for from who provides it, so you can change providers without touching a workflow.

  • Module designer with Hybrid-AI drafting
  • Python, PowerShell and shell

Workflows, jobs & triggers

Chain actions visually, fan out across many machines and reuse sub-workflows. Run them on a schedule or from a button on any record.

  • Visual workflow designer
  • Cron jobs with full run history

PKI & certificate automation

Find every certificate on your network, then renew the ones that are expiring automatically. Keys are generated on the device and never leave it, and the inventory is the starting point for a post-quantum migration.

  • TLS discovery across TLS 1.1–1.3
  • Pluggable CAs for crypto-agility

Data, dashboards & alerts

Every run produces structured data. Track changes, build dashboards, set alert rules and email the right people, with vulnerability lookups built in.

  • Change tracking & alert rules
  • OSV vulnerability data sources

Scale-out gateways

Gateways relay thousands of agent connections over a single upstream link, and chain together to reach segmented networks.

  • No agent changes beyond the address
  • Built for large, distributed fleets

How it works

One console. Every machine. A record of everything.

Administrators build and run automation in the Keystone console. The server dispatches signed work to agents, directly or through gateways, and to central queue workers for network and SSH tasks. Results come back as data, and every action is permission-checked and audited.

Consoleadmins & teams Keystone serverworkflows · jobs · data · audit Queue workersnetwork & SSH Gatewaysrelay & scale out Windows agents Linux agents Remote sites

Hybrid-AI

AI writes the code. Signed code does the work.

Keystone uses AI where it helps most, turning a plain-English request into a module or workflow, and keeps it away from where it would be riskiest. AI runs only in the console while you design. What reaches your machines is ordinary, reviewed code, signed and versioned, that runs the same way every time. No models, no prompts and no AI decisions on your devices.

  1. 01

    Describe

    Ask for a module or workflow in plain English.

  2. 02

    Draft & check

    AI drafts the code. Keystone checks it with the same validators as a hand edit.

  3. 03

    Approve & sign

    A person reviews and applies it. Publishing signs and versions it, and the request is audited in full.

  4. 04

    Run

    Agents and workers run only the signed code. They never run AI.

Where AI runs

  • In the console designers, only while you build
  • Optional and off by default
  • Gated by its own permission
  • Every request audited, prompt included
  • Your choice of Anthropic, OpenAI or Google

Where it never runs

  • On your agents and devices
  • In queue workers
  • Inside running workflows
  • In any decision made at run time

When Hybrid-AI is on, your prompt and the design context are sent to the AI provider your install is configured for. Nothing it proposes is saved, signed or run until a person applies it.

Secure by design, not by configuration.

  • Ed25519-signed modules and agent updates
  • TLS enforced; downgrades refused
  • Trust settings only the device can change
  • AES-256-GCM secrets, isolated per organization
  • Permission checks on every route
  • Complete audit log, including failed sign-ins
  • Multi-tenant organization hierarchy
  • LDAP sign-in with group-to-role mapping
Agents
Windows (MSI) · Linux (systemd)
Server & gateways
Linux, behind nginx
Hybrid-AI
AI drafts code in the console, never on your devices. Off by default
Built in
The USA, by Zero Medium

Why Keystone

Less administration.
More improvement.

Most IT and security teams spend their week on the same routine work: patching scripts, certificate renewals, inventory, one-off fixes. Keystone turns that work into automation that runs itself, so your people can spend their time making things better.

75%+

less administration labor*

Time your team gets back for continual improvement.

Routine administrationContinual improvement
Before Keystone
80%20%
With Keystone
20%80%

Illustrative: how a team's week shifts.

Write once. Never rewrite.

Automation is built as versioned modules and shared libraries, then reused across every organization and machine. Interfaces let you swap a provider, such as a certificate authority, without touching a single workflow.

Centralized control

One console for every organization, agent and gateway. Schedules, settings, rollouts and permissions are set in one place, not machine by machine.

Insider threat protection & visibility

Every action is tied to a named person and audited, failed sign-ins included. Only signed code reaches your machines, so there are no ad-hoc scripts on production. Least-privilege roles, and alerts when something changes.

Consistent every time

The same automation runs the same way on every machine, on schedule. There's no drift between administrators, shifts or environments.

Knowledge that stays

Automation lives in the platform, not in someone's head or in a script on a laptop. When staff change, your operations don't walk out the door.

Measurable improvement

Every run produces data. Dashboards and change tracking show progress over time, so continual improvement is something you can see and report on.

From → To

  • Scripts on laptopsSigned, versioned modules
  • Rewriting for every environmentWrite once, deploy everywhere
  • Logging in machine by machineOne console for the whole fleet
  • "Who changed that?"A full audit trail
  • Calendar reminders for certificatesAutomatic renewal
  • FirefightingContinual improvement
See it in your environment

* Up to 75% or more; based on Zero Medium deployment estimates. Actual results vary by environment and scope of automation.

Compliance & monitoring

Compliance that never stops checking.

Keystone turns policy into scheduled checks that run on every machine and device. It records what changed and when, and alerts you the moment something drifts, with the evidence already collected for your next audit.

  1. 01

    Collect

    Agents and connections gather configuration and state on a schedule.

  2. 02

    Compare

    Tracked data shows exactly what changed since the last check.

  3. 03

    Alert & act

    Alert rules notify the right people; workflows can remediate automatically.

  4. 04

    Prove

    History, run records and the audit log become audit-ready evidence.

Security compliance

Policy stops being a document and becomes something your systems are checked against, all the time.

  • Continuous policy checks across your fleet
  • Every check, change and action recorded: who, what, when
  • Drift alerts, with exclusions for approved exceptions
  • Evidence on demand from history and dashboards

Extend to any interface or device

One platform to monitor it, check its compliance and act on it.

  • Custom modules in Python, PowerShell or shell
  • SSH reaches network gear, appliances and agentless servers
  • HTTPS APIs and JSON / CSV data sources
  • Versioned interfaces plug new devices into existing workflows

If it has a shell, an SSH port or an API, Keystone can monitor it, check it and act on it.

  • Windows agents
  • Linux agents
  • SSH
  • HTTPS APIs
  • JSON / CSV feeds
  • PowerShell
  • Python
  • Shell
  • Custom modules

Map automated checks to the frameworks you answer to

  • NIST 800-53
  • NIST 800-171 / CMMC
  • CIS Benchmarks
  • SOC 2
  • HIPAA
  • PCI DSS
Talk to us about compliance

Keystone provides the automation, monitoring and evidence; checks are configured to your requirements. Keystone does not itself certify compliance.

Post-quantum PKI

Get ready for post-quantum cryptography.

Quantum computers will break the RSA and elliptic-curve keys behind almost every certificate in use today, and data captured now can be decrypted later. NIST has published the replacement standards. The algorithms are the easy part. The hard part is finding every certificate and key you have, then replacing them across every system without an outage.

  1. 01

    Discover

    Find every certificate and key, on servers, network gear, appliances and devices.

  2. 02

    Assess

    Flag what is quantum-vulnerable (RSA, ECC) and rank it by exposure and lifetime.

  3. 03

    Plan

    Choose hybrid or post-quantum algorithms for each system, and test with your CA.

  4. 04

    Migrate

    Re-issue and deploy through audited workflows, then keep checking for drift.

Crypto-agility

Swapping algorithms should be a configuration change, not a project.

  • Pluggable CAs behind versioned interfaces
  • Change providers or algorithms without rewriting workflows
  • Hybrid classical + post-quantum transition paths
  • Every issuance recorded

Certificates hidden in hardware

Phones, appliances and embedded devices carry certificates no network scan will find. Keystone's Hybrid-AI helps you build discovery that pulls device information from the systems that manage them, such as MDM platforms, vendor APIs and device inventories, into the same inventory.

  • Cell phones and tablets via MDM
  • Network appliances, HSMs and IoT
  • AI-drafted modules, approved by a person

Standards and timelines we work to

  • FIPS 203 ML-KEM
  • FIPS 204 ML-DSA
  • FIPS 205 SLH-DSA
  • NSA CNSA 2.0
  • NIST IR 8547: RSA/ECC deprecated 2030, disallowed 2035
Check your quantum readiness

Keystone provides discovery, inventory and deployment automation. Post-quantum certificate issuance depends on your certificate authority and on what each device supports. Zero Medium can help design and run the migration.

Capabilities

Automation for the work that can't go wrong.

Beyond Keystone, we build custom software in three areas, all around one idea: take the repetitive, high-stakes work off your team's plate and make every step traceable.

Security Automation

Continuous discovery, inventory and remediation that runs on a schedule instead of waiting for a person.

  • Network & endpoint discovery
  • Vulnerability tracking & alerting
  • Automated remediation workflows
  • Identity, access control & audit trails

Business Operations Automation

Workflow software that removes manual steps without removing accountability.

  • Workflow, task & approval systems
  • Multi-tenant SaaS platforms
  • Integrations, APIs & billing
  • Tamper-evident audit logging
  1. 01

    Automated

    If a person does it every week, software should do it every hour, the same way every time.

  2. 02

    Auditable

    Every action has an actor, a time and a result. You can always answer "who did what, and when?"

  3. 03

    Secure by default

    Signed code, enforced TLS, least-privilege access and no AI on your devices are the starting point, not an add-on.

Made in America

Designed, developed and supported in the USA.

Every product we ship, Keystone included, is written by engineers in the United States. No offshore subcontracting, no opaque supply chain: you know exactly who built the software that protects your business.

  • Domestic engineering team
  • Known code provenance
  • Direct access to the people who wrote it

Contact

Have a question?
Let's talk.

Want a Keystone demo, help preparing for post-quantum cryptography, or have security, PKI or operations work you'd like automated? An engineer, not a sales queue, will get back to you.

US-based team · Replies within one business day

Or email us directly at info@zeromedium.com