Blog

RESTART - partner of SafeTech Lab

RESTART LLC has become an authorized partner of SafeTech Lab, a Russian developer of solutions for PKI infrastructure and technology certificate management. Certificate No. 2026-010 gives the right to supply licenses, implement and maintain the manufacturer’s software throughout Russia.

Hero image for the page “RESTART is an authorized partner of SafeTech Lab for corporate PKI”

What happened

SafeTech Lab has confirmed the status of LLC "RESTART" as an authorized partner: certificate № 2026-010 with the status PARTNER grants the right to supply licenses, implement, and provide support for SafeTech Lab software throughout the territory of the Russian Federation. Term of validity — until 12/31/2026; the document was signed by the General Director of LLC «SafeTek Lab», Sanin A. I.

SafeTech Lab is a Russian developer of solutions for building PKI infrastructure, part of the SafeTech group. Flagship product — SafeTech CA, corporate certification center: a cross-platform service for issuing and managing technical certificates for IT landscape components. According to the manufacturer, the product is included in the Russian software registry (entry No. 26307) and holds an FSTEC of Russia conformity certificate No. 5032; we verify the validity of these entries in the registries prior to each delivery. Manufacturer's website · partner certificate (PDF).

What is SafeTech CA and the CDM service

A corporate certification center is a system that issues and manages technology certificates for network equipment, servers, workstations, services, and users. According to the manufacturer, SafeTech CA addresses the following tasks:

  • PKI hierarchy — root, intermediate, and issuing certification authorities based on «CryptoPro CSP»;
  • certificate lifecycle — issuance, renewal, revocation, publication in LDAP, CRL/AIA and OCSP publication points;
  • Russian and foreign cryptography — GOST, RSA, ECDSA, EdDSA in a single certification center;
  • standard release protocols — MS-WSTEP, ACME (TLS for web portals, Kubernetes, OpenShift), SCEP (macOS, iOS, Android, Linux, network equipment), SSH, REST API;
  • migration from Microsoft CA — import of templates and previously issued certificates without prolonged parallel operation of two CAs;
  • autoenrollment in Linux and integration with Russian operating systems and directory services;
  • Storing Certification Authority keys in HSMweb administration console, user personal account, release approval, notifications, reporting, and monitoring.

Separate service CDM (Certificate Delivery Management) Handles certificate delivery to end devices: the agent requests and installs certificates, monitors expiration dates, and renews them without administrator intervention, operates in isolated segments without an LDAP directory, and supports custom pre/post-scripts.

The composition of modules, versions, licensing scheme, infrastructure requirements, and certificate applicability are confirmed with the manufacturer prior to the commercial offer.

Why corporate PKI is needed and why it has become urgent

In large-scale infrastructures, certificates have long ceased to be a matter of "one admin with OpenSSL." Their count runs into the thousands, and every mistake is visible to the business:

Expired certificate = downtime

An expired certificate on a load balancer, integration bus, or internal portal stops the service just as reliably as hardware failure—and always at the most inconvenient moment.

Deadlines are shrinking

The industry is moving toward short-lived TLS certificates. Annual manual issuance is turning into an ongoing process that can't survive without automation.

Key compromise

Certificates need to be quickly revoked and reissued, which requires knowing where they are installed. Without inventory and agents, this means manually searching through the infrastructure.

Leaving Microsoft CA

Many PKIs have relied on Windows Certification Services for years. When migrating to Russian operating systems and directory services, a certification authority capable of accepting existing templates and certificates is required.

Plus a regulatory layer: in systems using GOST cryptography, certificates must be issued using domestic algorithms, and certification authority keys must be stored as required by the threat model, up to and including HSMs.

What does RESTART give?

  • Cryptographic layer next to licenses. The group holds an FSTEC Russia license for technical protection of confidential information (including installation, commissioning, and testing of information security software) and an FSB Russia license for distribution of cryptographic information protection tools (SKZI). The SafeTech Lab partnership status further adds the PKI platform itself: licensing, implementation, and support are all provided by a single company on a fully legal basis.
  • Direct channel to the manufacturer. Authorization enables direct work with the vendor: selecting editions and modules for the environment, technical consultations on compatibility with operating systems and directory services, and confirmation of delivery terms and conditions directly with the developer rather than a reseller.
  • Purchasing qualifications. Manufacturer authorization is a standard requirement for participants in tenders for software supply and implementation. Certificate No. 2026-010 is attached to the application and commercial proposal as supporting documentation.
  • Response to a common project request. Replacement of Microsoft certification services and automation of certificate issuance come up in almost every infrastructure import substitution project—now we have a Russian product for this task and the right to deploy it.
  • Expansion of the vendor ecosystem. PKI and certificate management has been added to the categories of cryptographic information protection (CIP), cryptographic information protection tools (CPT), network security, endpoint security, IDM/PAM, and monitoring—a domain previously covered by third-party solutions.

What does this give to clients?

  • One contractor for the entire journey. Assessment of the current certificate scheme, PKI architecture, license provisioning, implementation, integration with directory and services, operational procedures, and maintenance—all under a single contract and with a single point of responsibility.
  • Legal supply perimeter. If cryptographic means are included in the solution, their transfer is carried out within the framework of licenses of the FSB of Russia, and information security technical protection activities are carried out within the scope of the FSTEC of Russia license.
  • Fewer accidents due to certificates. Automated issuance and renewal, notifications, and a unified console eliminate the most common incident scenario—“no one noticed that the certificate expired.”
  • Managed migration from Microsoft CA. Importing templates and certificates allows for a phased transition without the need to run two certification authorities in parallel or wait for old certificates to expire.
  • Verified status for procurement. Partner Certificate is a document with a number and validity period: it can be attached to a tender proposal or provided to the customer's security service or legal team along with other materials of the trust package.

Where applicable

Managing technology certificates becomes mandatory where the infrastructure is large, distributed, and audited by a regulator:

CII and Federal Law No. 187-FZ

Authentication of nodes and services within critical facilities, segmentation isolation, trusted channels between sites and contractors.

GIS and ISPDn

Requirements for channel protection and node authentication, Russian cryptographic algorithms, documentary confirmation of implemented measures.

Banks and the digital ruble

mTLS in internal integrations, certificates for services and equipment, short validity periods, and rapid revocation upon compromise.

Infrastructure import substitution

Migration from Microsoft CA to a Russian certification authority along with migration of the OS, directory services, and VPN access.

Certificate details

  • Partner: RESTART LLC, TIN 9705056320
  • Manufacturer: SafeTech Lab LLC, Tax ID 7734429050
  • Partner Certificate No. 2026-010, status PARTNER
  • Subject: Supply of licenses, implementation, and maintenance of SafeTech Lab software throughout the Russian Federation
  • Validity period: until 12/31/2026
  • Signed: General Director of SafeTech Lab LLC, Sanin A. I.

Let's discuss your environment

Describe the task, current systems, constraints, and expected results. We will offer a practical first step: diagnostics, pilot, audit, roadmap or project team.

Contact us
AI assistant
Hello! I am an AI assistant at RESTART. I’ll help you find the right section of the site, answer questions about services, licenses, partnerships, contacts, or formulate an appeal to the sales department.