Products / Storax OCSP Server

Certificate status, live.

The internet has never been able to answer the one question that keeps it safe — “is this certificate still valid, right now?” — for everyone, at once. Signing a fresh answer billions of times an hour was never affordable, so real-time status stayed a promise the web engineered around. Storax OCSP makes live, per-request certificate status practical — at internet scale, and post-quantum from day one.

1M+/s OCSP signatures · per GPU
Linear scale · every GPU & box
Millions domains resident per box
PQ + FIPS native · FIPS 140-3

The status gap

Real-time certificate status never scaled.

OCSP was designed to ask a certificate authority “has this been revoked since it was issued?” in real time. But signing a fresh, trustworthy answer for every request, at internet scale, was never affordable on CPUs and HSMs — so it was never truly deployed at scale. Browsers softened it, then dropped it; the web leaned on stapling, ever-shorter certificates, day-old blocklists — and fail open. A compromised, revoked certificate can keep the padlock for days.

LIVE · signed now What OCSP promised — the answer, this millisecond
STALE · hours–days old What the web settled for — cached lists, delayed pushes
SOFT-FAIL · unknown = trusted What attackers count on — revoked but still accepted

Possible. And affordable.

One GPU signs millions a second. The fleet scales linearly.

A single GPU signs well over a million fresh OCSP responses a second — hundreds of thousands on a mixed real-world keyring. Capacity scales linearly: every GPU and every box behind your load balancers adds its full throughput, with no architectural ceiling. Live certificate status stops being a research problem and becomes a line item.

1M+/s fresh signatures · per GPU
300k+/s mixed real-world keyring
Linear scale · GPUs & boxes
0 stale fresh-signed, every request

Per-GPU figures; throughput and capacity scale linearly with additional GPUs and boxes.

Relying parties The internet's flood of “is this valid?” questions.
Pool & dispatch Concurrent requests pooled and answered together.
Bulk signing Thousands of fresh signatures at once — atomic each. GPU-accelerated.
Live answers Signed, current status — returned per request.

Hyperscale by design

Millions of domains, answered live.

Throughput is independent of how many domains you serve — capacity is bound only by memory, and keys are a rounding error, so a server keeps millions of domains' keys resident at once. Serving volume then scales linearly across the fleet: add GPUs, add 10-gigabit front-ends, add boxes behind your load balancers, and capacity grows in proportion.

Serve the whole keyring

Every issuer's delegated signing key lives GPU-resident. Throughput doesn't care whether it's ten domains or ten million.

  • Millions of domains' keys resident per box — memory is the only limit
  • Flat throughput as the keyring grows — verified, not assumed
  • Scale-out behind load balancers; multi-GPU fan-out per box

Scale linearly, no ceiling

Throughput grows in direct proportion — add a GPU, add a box behind the load balancer, and the fleet does more. No architectural bottleneck, no diminishing returns.

  • Every GPU adds its full signing rate
  • Every box scales linearly behind your load balancers
  • Signing never becomes the bottleneck — requests never wait on crypto

Assurance

Post-quantum from day one.

This isn't a classical service with a quantum retrofit later — post-quantum is native from the start. Classical and PQC in one engine — ECDSA, RSA, Ed25519, ML-DSA and Falcon, every signature byte-exact against the standards — so the moment your CAs migrate to post-quantum, live revocation is already there, at scale. Post-quantum signing is considered heavy — larger signatures, more compute, the very reason many fear the migration will break high-volume services. Not on our box. Delegated keys are HSM-wrapped and GPU-resident; the CA's roots never move. And it's built to FIPS 140-3 — every deployment picks its posture:

Fast

FIPS 140-3 Level 1 · normal ops

Maximum throughput for the everyday internet — the default that makes live status affordable.

Constant-Time

FIPS 140-3 Level 3 · high assurance

Side-channel-resistant signing for regulated and high-security deployments, a switch away.

The hyperscaler story

Certificate status at planetary scale.

Hyperscalers terminate most of the world's TLS and run certificate estates in the hundreds of millions. When a certificate is compromised, “revoked” has to mean something in seconds — not days spent waiting on a stale list. And they are the ones leading the post-quantum migration. That combination — internet-scale volume, real-time freshness and post-quantum — is exactly the workload OCSP could never carry. Storax OCSP carries it: live, post-quantum certificate status across the whole estate, scaling linearly with the fleet they already run.

Planetary estate

Every domain, device and workload behind their edge — kept answerable in real time, growing linearly with the fleet, not fighting it.

Revoked means revoked

A compromised certificate stops being trusted the moment it is revoked — not after the next day-old list ships. Real-time trust, at their scale.

Ahead of post-quantum

The migration to post-quantum starts at the edge they run. Storax OCSP is post-quantum from day one — revocation is ready before the certificates are.

Live certificate status. At internet scale — for the first time.

Revocation doesn't have to be a stale list and a hope. Storax OCSP makes live, signed, per-request certificate status cheap enough to run everywhere.

Request a demo