Information Security Corporation (ISC) develops standards-based cryptographic software for government, enterprise, and commercial environments. Our products support PKI, certificate lifecycle management, credential and key storage, digital signatures, authenticated policy delivery, secure file protection, and encrypted storage. All products are built using our NIST CMVP-validated FIPS 140-3 cryptographic library.

ISC has decades of experience building public key infrastructure and applied cryptography products, including software used in high-assurance environments. Today, our work helps organizations strengthen identity, protect sensitive data, and support Zero Trust security architectures.

As the industry prepares for post-quantum cryptography, ISC is building PQC support into its PKI and trust infrastructure products so customers can begin testing, planning, and adopting new algorithms without replacing existing workflows all at once.

  • CertAgent

    NIAP Approved Certificate Authority, CertAgent, is on NSA’s Commercial Solutions for Classified (CSfC) Program Components List. CertAgent is a self-contained certificate authority designed to serve as the core of an enterprise public key infrastructure. It supports certificate issuance for employees, partners, and devices, with web-based enrollment, Enrollment over Secure Transport (EST), integrated certificate and CRL databases, and a built-in OCSP responder. CertAgent also provides a strong foundation for certificate-driven identity and trust in zero trust architectures.

  • SecretAgent

    Protect sensitive data at rest, in transit, and across shared workflows with a core encryption platform and optional add-ons for rules-based folder protection and encrypted virtual storage.Add Protected Folders for automatic encryption in selected folder locations, or Protected Storage for encrypted virtual storage of larger datasets, backups, and compartmentalized information.SecretAgent core can be centrally managed with Bagala Server. Additional license fees may apply.

  • DAS™

    DAS helps organizations share protected content within a Community of Interest (COI) without re-encrypting data every time membership changes. It performs cryptographic operations on behalf of properly authenticated users and checks current membership before decrypt or sign operations are performed.

  • Acala™

    Acala is a software-based HSM emulator that acts as a universal key store and cryptographic service provider. It stores private keys and X.509 certificates in a protected central repository and provides cryptographic operations to security-enabled applications through a PKCS#11 interface.

  • Centralized Credential Management Servlet™ / CCMS™

    CCMS interfaces with an organization’s infrastructure, including directories and certificate authorities, to provision users with certificates and manage credentials across enterprise environments. It also includes NPE certificate management capabilities for users, devices, and applications.

  • Central Key Generation Library (CKG)

    CKG is a Java-based library that generates RSA and Elliptic Curve keys and certificate requests aligned with an enterprise’s enrollment processes and security policies. It supports certificate enrollment with CertAgent through the Registration Authority Management Interface (RAMI), and supports certificate enrollment, revocation, recovery, and renewal with CCMS through CMP and the Remote Management API. Uses ISC’s FIPS 140-3 validated cryptography while supporting both software-based and HSM-based key pair and certificate request generation across CertAgent and CCMS workflows.

  • Bagala™

    Customer-hosted web service for centralized policy storage and authenticated policy retrieval for ISC client applications. Bagala allows authenticated applications to download policies based on user identity while restricting upload operations to authorized administrators. It supports centralized management of configuration and policy settings for ISC client applications, with storage keyed to distinguished name and attribute.

  • Dhuma™

    Dhuma is a customer-hosted web service that implements an RFC 6960–compliant OCSP responder designed to scale for large enterprise environments. It also functions as a Certificate Revocation List (CRL) distribution point for certificate issuers.

  • Tara™

    Leveraging CCMS, Tara enables administrators to manage and deploy server and application credentials, trust anchors, and CRLs throughout an enterprise. Once installed on a host, Tara periodically downloads and installs updated trust stores and CRLs, manages scheduled key rollover events, and reconfigures relying server processes to use updated keying material.

  • Credential Management Utility™ / CMU™

    CMU helps administrators automate credential management tasks that are often difficult for end users, including PKI enrollment, post-rollover application reconfiguration, browser credential synchronization, secure backups, and transparent profile updates for Outlook, S/MIME, MAPI, and related environments.

  • CSPid

    CSPid is a virtual smartcard that maintains a central repository for X.509 certificates and private keys. It provides a secure environment for cryptographic operations that security-enabled applications can access through Java, PKCS#11, or Microsoft CAPI.

  • Cryptographic Development Kits (CDKs)

    FIPS 140-3 validated cryptographic libraries for adding encryption, digital signatures, message authentication, and related security functions to applications and OEM products. ISC CDKs are flexible, cost-effective libraries of linkable cryptographic modules that reduce the cost of developing secure applications by making standards-based cryptographic building blocks available to developers and integrators. Use them to construct secure internal applications or OEM products for resale.

  • SpyProof!

    SpyProof! is a consumer file and folder encryption software distilled from ISC’s enterprise technology to deliver automatic, transparent protection without enterprise complexity. It protects data at rest in selected folders, cloud-synced folders, removable storage, backups, and shared files, while keeping your data under your control.