Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

  • Home
  • Blog
  • AI
  • Why We Intend to Acquire Cofide: Verified Identity for Workloads and AI Agents

Why We Intend to Acquire Cofide: Verified Identity for Workloads and AI Agents

AI

Today we announced our intent to acquire Cofide, an open-standards identity platform for the software workloads and AI agents running across today’s cloud environments. The press release covers the news. This post covers the thinking behind it, because the why matters more than the what.

Trust is only as good as what it’s built on

If you’ve followed our Trust Control Plane story, you know where we stand: trust infrastructure is the cryptographic foundation that lets machines, applications, devices, and AI agents prove what they are and communicate securely. It works thousands of times a second, and nobody thinks about it until it breaks.

Here’s the part of that foundation that keeps coming up in every customer conversation lately: the automated systems acting inside enterprise environments now far outnumber employees and the gap is widening. AI agents initiate actions. Workloads call APIs. Services cross clouds and trust boundaries at machine speed.

And most of them are still secured with static credentials. API keys, tokens, shared secrets. A static secret proves exactly one thing: that whoever presents it has it. It says nothing about what the workload actually is and it hands the holder the same access as the system itself. Copy it, steal it, and you are the workload.

That model held up when machines were static, long running and lived inside a perimeter. It does not hold up for identities that need to be dynamic and travel across clusters, clouds, and trust domains. The market is moving from possession-based access to verified identity: every workload and agent carrying cryptographic proof of what it is, scoped to what it’s allowed to do, and expiring before it can be abused.

The standards are ready. Running them is the hard part.

The industry already agreed on how verified workload identity should work. SPIFFE  defines how to issue and validate unique, short-lived, cryptographically verified identities. OAuth and OIDC connect those identities to the broader identity ecosystem.

So why isn’t everyone doing this already? Because customers stall on securing their workloads because it’s operationally hard, not because the technology falls short. Policy, lifecycle automation, federation across environments, observability, IAM integration: all of it lands on the operator. Plenty of teams believe in the model and stall on the operations.

That gap between a sound standard and a running system is exactly where Cofide works.

What Cofide brings

Cofide gives every workload and AI agent its own unique, short-lived, cryptographically verified identity, replacing static secrets and API keys with proof of what a workload is.  Identities are issued per workload, scoped, and short-lived, with mutual TLS securing service-to-service communication. Built on open standards (SPIFFE, OAuth, OIDC), it also brokers policy-based access to your existing APIs and services, so AI agents never need to hold long-lived tokens.

Just as important, Cofide makes the standards practical to operate at enterprise scale. It adds the policy, automation, governance, and observability that turn SPIFFE from a promising project into something an enterprise can actually run for every kind of workload, from containers to VMs and serverless. And because it’s built on open standards, workload identity stays portable and interoperable instead of locked to one cloud or vendor.

Why this belongs in the Trust Control Plane

Verified identity for workloads and agents needs more than issuance. It needs lifecycle, orchestration, auditability, and governance. Those are the same disciplines enterprises already apply to certificates and machine identities, and they’re what the Trust Control Plane does today: it observes, analyzes, provisions, orchestrates, and governs trust infrastructure as one continuous system of control.

Cofide extends that control into the environments where modern workloads and AI agents operate: Kubernetes, hybrid and multi-cloud, serverless, service-to-service communication, and agent-to-agent and agent-to-tool interactions. Cofide does not create the platform vision. It extends the next frontier of it.

The result customers care about: auditability and control without slowing down their AI and cloud initiatives. Governance can’t be the tax on speed.

What happens next

We’re incubating Cofide’s technology and will share integration and commercialization plans as they mature. Nothing changes today for Keyfactor customers: your products, roadmap commitments, and support are unaffected.

What it tells you is where the platform is going. Trust infrastructure is extending from certificates and machine identities to the workloads and AI agents now reshaping the enterprise, and we intend to be the one system of control across all of it.

If workload or AI agent identity is on your roadmap, we want to hear about it. Talk to your account team, or find us at Black Hat in Las Vegas at our booth in the Cyber Fuel Lounge, August 1 through 6. Early customer input shapes how we prioritize.

Read the full press release | What is trust infrastructure?