SYNEDAT® · Entrust
Entrust – Identities, certificates and keys
Digital trust needs clear ownership. Entrust provides PKI, key protection and identity solutions. SYNEDAT connects product selection with an inventory of your certificates, applications and operational processes.

Which product family fits your needs?
PKI & Certificate Lifecycle Management
Manage certificates and their lifecycle. We assess internal trust models, renewal, revocation and application integration.
nShield HSMs
Protect cryptographic keys in a dedicated security component. Integrations, key ceremonies and recovery shape the operating model.
Identity Verification & Authentication
Select identity verification and authentication for the process. SYNEDAT distinguishes onboarding, routine sign-in and account recovery.
Card & ID Issuance
Personalize and issue cards and credentials. We clarify volumes, permissions and interfaces with the authoritative identity system.
License scope, availability, term and support are reviewed for your project and specified in the quote.
Where the solution adds value
Make certificate renewal predictable
Which services depend on each certificate? SYNEDAT records owners and dependencies, pilots renewals and defines alerts and recovery procedures. Renewal becomes part of routine operations.
Protect signing keys in operation
Before deploying an HSM, we define who may generate, use and recover keys. A documented recovery exercise complements integration tests with signing applications.
What matters when choosing
- Identities and privileges
- Employees, administrators, service accounts and partners have different access needs. We define roles and approvals for the relevant systems.
- Protocols and devices
- FIDO2, certificates, SAML or RADIUS must fit the application. For security keys, USB connectors, NFC and supported platforms also matter.
- Lifecycle and recovery
- We plan issuance, enrollment, loss, revocation and emergency access. This simplifies rollout and avoids unresolved exceptions during operations.
From selection to deployment
Define requirements and objectives
We review systems, users, security requirements and budget. The result is a reasoned selection with a defined scope.
Validate suitability in a pilot
For an agreed pilot, we define tests, acceptance criteria and responsibilities. You receive a documented basis for the investment decision.
Plan rollout and operations
We plan migration, configuration, handover and support together. Scope and responsibilities are agreed before rollout.
Downloads and manufacturer information
Explore your options with the linked service overviews and manufacturer documents. The language shown refers to each document.
-
Entrust nShield KeySafe 5 v1.7.0 – User Guide, April 2026 (PDF)
English
Open PDF: Entrust nShield KeySafe 5 v1.7.0 – User Guide, April 2026 (PDF) (English) ↗
Questions to help you decide
Does an HSM replace the PKI?
No. An HSM protects keys and performs cryptographic operations. A PKI also needs policies, certification services and issuance, renewal and revocation processes. We design these components together.
How do identity verification and sign-in differ?
Identity verification establishes who a person is; sign-in authenticates access to an existing account. A process may need both. We also consider account recovery and exceptions.
How do MFA and privileged access management differ?
MFA strengthens sign-in with additional factors. PAM controls privileged permissions, credentials and, where supported, sessions. They can complement each other and are planned around your applications.
How do we start using security keys?
We first check applications and identity providers. A pilot group tests sign-in, spare keys and recovery. Issuance, enrollment and support can then be standardized for more users.
Can I request a demo or pilot first?
Yes. Tell us your intended use case. We will discuss available evaluation options, prerequisites, effort and acceptance criteria. A pilot is agreed separately before it starts.
What does SYNEDAT need for a quote?
Useful details include product family, deployment location, current systems, user or device count and target date. We clarify open points together and distinguish the product, implementation and ongoing services in the quote.
Can SYNEDAT help with rollout and ongoing operations?
We agree the services you need, such as architecture, integration, migration, documentation or operational support. Vendor support, response times and ongoing assistance are explicitly defined in the agreed scope.