About Amit Sinha
In a July 2026 interview with ETCIO, Amit Sinha discussed DigiCert's AI trust architecture and the concept of "agent passports" for autonomous AI systems. Sinha argued that as AI agents move from simple assistants to autonomous operators, enterprises need verifiable digital identities, strong authentication, and policy-led access before allowing agents to interact with sensitive systems. He described agent passports as a way to establish who created an agent, how it was trained, what it is authorized to access, and which actions it can take.
Sinha also discussed DigiCert's work on confidential computing and content trust. He noted that DigiCert has been working with Google on third-party attestation for confidential computing environments, explaining that the company brings the same core third-party attestation used in certificate issuance to AI workloads running in cloud infrastructure. Additionally, he mentioned DigiCert's content trust platform, which uses the C2PA standard to provide media provenance for AI-generated videos and images.
Source: AI-verified profile updated from Amit Sinha's recent appearances.
Browse all interviews →
Transcript (34 segments)
J
Joshua Marquette0:12
Welcome to RSAC 2026. I'm Joshua Marquette. Joining me today is Amit Sinha, CEO at DigiCert. I mean, thank you for being here. This is so much fun. I've been enjoying interviewing people. We just had about a 20-minute conversation and it was lovely. We've talked about a lot of different topics, but right now just for our viewers, do you mind giving us a really quick interview or overview of DigiCert, please?
A
Amit Sinha0:35
Absolutely, Josh. First, it's a pleasure to be back. Really enjoyed our conversation. DigiCert, we're the global leader in intelligent trust. Our solutions are used by over 100,000 organizations, including about 90 plus percent of Fortune 500, to get security, authenticity, and encryption for all the digital interactions. Our core platform is called DigiCert One, and it brings together PKI, DNS, and certificate lifecycle management to secure infrastructure, software, devices, content, and now AI agents.
J
Joshua Marquette1:05
Is that DigiCert One new? It's fairly new.
A
Amit Sinha1:06
It's new. DigiCert One's new. It brings together PKI, DNS, and certificate lifecycle management to secure infrastructure, software, devices, content, and now AI agents.
J
Joshua Marquette1:18
Yeah, that's huge because we talked for a while about certificate lifecycle management. I ranted at you a little bit. I'm sorry. You ranted at me. We're on the same page. Certificate lifecycle management is incredibly useful. It is and it's so necessary with the lifespan shortening of certificates until 2029 and it's going to be 47 days. Like 10 years ago you could have a five-year cert. But now it's going to be 47 days in 2029.
J
Joshua Marquette1:46
So I could probably give the interview for you to a certain extent. I apologize. But like for how many companies is this going to be incredibly useful for to have a solid CLM vendor like DigiCert?
A
Amit Sinha2:00
Yeah. So Josh, we've gone from the point where CLMs were nice to have to now it's absolutely essential. I was talking to a CISO of a bank and he privately said, 'Hey, we have three certificate related outages a day.' And that is with a one-year cert. Now imagine one year goes to 47 days, you have 8x more certificate volumes being issued, so you're going to have like an outage an hour. So without automation, it's costly. You lack resilience. So you got to fix all of that now.
J
Joshua Marquette2:32
Oh, that's not...
A
Amit Sinha2:33
Without automation, and a bank, without automation, it's costly. You lack resilience. So you got to fix all of that now.
J
Joshua Marquette2:42
Yeah. Well, we have to. I mean, if my bank goes down once an hour, I'm going to be moving my deposits. Let's be clear. So you can't have that. We've literally gone to the point where it's unacceptable to have that kind of level of problem.
J
Joshua Marquette2:57
Okay. So we've talked about certificate lifecycle management and I said something and we both agreed on it. When you do CLM properly, you're doing things like being crypto agile, I think is proper. Excuse me. You're working on your zero trust, you're working on your post-quantum crypto and all that kind of stuff. I mean, what did I miss? What things is it useful for?
A
Amit Sinha3:17
Yeah. So with certificate lifecycle management, step one, you have to understand that there are 100 times more machine identities in an organization than humans, right? So without having an inventory of all your cryptographic assets, you don't even know where to start. So that's step one. With DigiCert One, you're able to get a full inventory of all your assets. But then what is more important is how do I automate the full lifecycle from issuance to last mile installation across my entire digital footprint? Think about all user laptops, all machines, cloud workloads, your CI/CD pipelines, your documents, OT. PKI just touches everything. And unless you have a proper solution that can give you full automation across all of these assets, you'll continue to have these outages or expenses. And we recently did a study with Forrester Research and found that our top organizations that have deployed DigiCert One with full automation were able to get their money back from the investment that they made in DigiCert in 6 months.
J
Joshua Marquette4:31
Wait, 6 months. Full CLM, full automation. You're dropping a good chunk of money on this, correct? But 6 months, I'm making my money back.
A
Amit Sinha4:38
6 months is the payback period. And in fact, most of these large organizations ended up saving close to $3 million just by automating.
J
Joshua Marquette4:48
Where do I get that study? Can I get it on your website?
A
Amit Sinha4:50
Yes, it's on the website. It's the Forrester Total Economic Impact report with DigiCert.
J
Joshua Marquette4:54
Fantastic. I want to get that. I'm actually going to download that because I can't tell you how many clients I have that I need to give them this report. Because they keep going, 'Why do I need a CLM?' And I go, 'Look, it's fantastic for the regulatory issues and the certificate lifecycle shortening, but also it works.' And we mentioned this as well for agentic AI, it goes incredibly well with understanding where your agents are, what are your agents doing, and giving them proper identity. So do you mind going into that a little bit?
A
Amit Sinha5:22
Yeah, 100%. Look, in the PKI world, we know how to secure machines and workloads. We can use DNS to give them a name. We can drop an X.509 cert and give them an immutable identity. And that's how it establishes the trust fabric within an organization. What is an AI agent? An AI agent is a smart workload. We strongly believe that all agents within an organization should have durable, immutable cryptographic identity. I call them digital passports. So Josh, if you come to work for DigiCert, the first thing we'd say is, 'Hey, prove to me that you're Josh. Show me your driver's license.' And we want to bring the same concept to AI agents. Next year maybe I'll have six AI agents working for me. But I have to know that those six are mine. I need to have an audit trail. I need to have a kill switch. If I don't want some agent, I need to be able to revoke it. And before I give these agents access to my enterprise kingdom, they better come with strong immutable cryptographic identities. This is a solved problem with SPIFFE, SPIRE, PKI. We've solved this with dynamic workloads. And what DigiCert One is doing now is extending those PKI-based mechanisms to agents to give them identity, which is step one for any zero trust implementation.
J
Joshua Marquette6:46
It's fascinating because we see agentic AI literally plastered all over this conference. It's everywhere here at RSAC. And I've talked to probably three or four different companies that have talked about agentic identity. And it's fascinating that they talk about providing guardrails for agentic identity and agentic privileges and permissions, which is understandable. But the fact that you're doing it from a cryptographically secure point of view is really fascinating to me. And I know there's going to be a lot of people like, 'What's the big deal? I don't want a North Korean agentic AI slipped in.' It sounds silly, but how many North Koreans got hired as IT workers in the past few years? Tens of thousands, I think. I think the foundational problem with the way people are approaching agentic AI identities is they are just substitute bearer tokens. They are acting on behalf of users. You do not have an inherent digital passport of the agent. That's foundational. After that, I look at the OAuth tokens or acting on behalf of this user as like visas on that passport saying, 'Hey, you're allowed to go to TSA.' But then you have a boarding pass that allows you to go through to different gates. People are obsessed with the boarding pass, authentication and authorization, but nobody is like, 'I want to know as an IT controller, I want to be able to say if I kill this root, does it immediately revoke all access within it?' And tokens don't. They have an inherent lifespan, whereas a root is immediate CRL certificate revocation list and everything dies.
A
Amit Sinha8:33
Correct. And we've solved this problem, Josh. Look, workloads, when I was at Zscaler, for example, you couldn't have a workload without a DNS entry, and that became like a registry of all my workloads. And then those workloads when they needed cryptographic identities and secure connections, you can issue the certificate tied to that internal name. So it's a solved problem. And what we're doing is we're bringing digital passports to AI agents using PKI, SPIFFE, SPIRE, OPA-based policies. And I think that's the step.
J
Joshua Marquette9:09
Open Policy Agent based policies. You're writing this in Rego to a certain extent. Oh, I love it. I'm a big fan of OPA. I think policy-based access control and understanding it using the policies is a monsterly huge thing. Correct. There's Open Policy actually is another company. I'm a big policy fan. So I love that. That's really nice. It provides the guardrails that go around the cryptography. With this cryptographic certificate, you were allowed to go here and here and not over there. But it's the same thing we do to humans. You have your ID, it'll badge you through this door and that door but not that door over there.
A
Amit Sinha9:45
Yeah. And so that's on the agent side, but AI is also introducing this whole problem of what's real, what's fake. Look at content. You guys will release this video, someone can download it, use Google Nano Banana Pro and change something. Where is the content provenance? Again, solved problem with PKI. You can sign a PDF document and we know this is tamper-proof. Here's all the metadata. So with DigiCert One, I can digitally sign my documents, my videos, my everything. And if anybody does a deep fake of it, it's not going to stop them from deep faking it, but I can attest original content provenance. So the original content has the provenance, so I can prove this is real. And I think we'll live in a world where you might have a blockchain of all trusted media providers. On LinkedIn, for example, you see now little CR tags that show up with media which has cryptographically signed content record. But there's all kinds of things. We have insurance companies coming to us and saying, 'Hey, we're getting fake accident reports.' We have camera manufacturers saying, 'I want to sign the metadata, GPS coordinates, timestamps, etc. of my image and raw files, because I want to be able to prove this originally came from this camera at this time in this place.' It's crypto. We digital fingerprinted it and cryptographically signed it. And then that picture, if it's this picture you're seeing with this cryptography attached to it, it's real. And the standard that we've been working with a lot of the media providers, Microsoft, Adobe, etc., is called C2PA, Content Provenance Initiative. DigiCert is a certified certificate authority for that, and we've also been accepted into the product conformance list to be able to sign these types of media using C2PA.
J
Joshua Marquette11:36
Are there any other roots? Okay, good. But DigiCert is leading the way is what I'm hearing. End-to-end solution, not just issuing, not just giving you the authority to sign, but also having our content trust platform that allows you to manage all of that just like we've done with PDFs and digital documents. So look, what do you use PKI for? You use it to give authenticity to machines and encryption, but that authenticity can be extended to media, to content, to software. We've already been doing it for documents and software, extending it to synthetic content, extending it to AI agents are all just a natural extension.
A
Amit Sinha12:16
This is fascinating. You've really... So did this start with you at DigiCert? You came to DigiCert a few years ago? Did this expansion of DigiCert's traditional PKI roots into 'there's so much more we can do with this' start with you?
Yeah. So I think the pivot that we made as a company after I joined about 3 years ago was we were a very reputed certificate authority, huge one. And now what we do is we say it's a full soup to nuts solution where we manage... we still are the best CA out there, and the ability to manage your public TLS, private PKI, replacing your internal CAs, your legacy CAs, and being able to provide a full lifecycle management around everything that PKI touches across your infrastructure, your workloads, your machines, your software, your content. So it is the whole platform that is automating PKI and DNS for you.
J
Joshua Marquette13:23
Wait, wait, back up. You just said something interesting. 'We are the complete platform.' Cool. Love it. I'm a big fan of integrated solutions because it means I don't have to deal with it. Okay. But PKI and DNS. So you're doing all of that.
A
Amit Sinha13:37
Yes. So we did acquire a company called UltraDNS and... Well, I know you bought UltraDNS. Yeah. So UltraDNS serves about one-third of the authoritative queries in the world, used by some of the biggest e-commerce engines and software companies. And the reason why PKI and DNS working together is so important is because as these certificate lifetimes are shrinking, you need to do the domain control validation through DNS more frequently. So if you have a fragmented solution, what happens is your PKI says, 'I need to check DNS, here's a secret, the DNS check the text fields or whatever.' The DNS doesn't respond, or worse still, the PKI and DNS teams are siloed, and the DNS team says, 'No, you can't add this record,' and automation fails. For failsafe automation, you need PKI and DNS working in a tight loop to be able to say, 'Hey, this cert on this machine is going to expire, we've already pre-authorized the DCV checks, and as soon as it expires, we have issued and installed and we've notified you,' as opposed to back in the day, tickets being opened, people running around, and that's where all the inefficiency and resiliency failures happen.
J
Joshua Marquette14:54
Okay, I'm going to go a little long here because I got a question for you and you can say no, but that implies that you're going to be going after mail security as well because SPF, DKIM, and DMARC are so heavily tied to DNS as well as PKI.
A
Amit Sinha15:08
So we did acquire a company called ValiMail. That's the leading provider. You bought ValiMail? Yes, we did. Last year? I didn't even hear about that. So look, DigiCert was always issuing verified mark certificates. I've been recommending ValiMail for years. Yes. So we love the solution because now it's a good solution when it comes to messaging trust, email trust. What are the two steps? You need to be DMARC compliant, and that's really tough alignment. You need the SPF, DKIM, and ValiMail is the leading provider of DMARC enforcement. With ValiMail, you're able to enforce DMARC, and with the DNS you're going to be able to do the SPF flattening. They have patents on these dynamic SPF records that are able to deal with the limitations of only so many DNS lookups. I have clients I have to call. This is great stuff. But here's the kicker. You do the DMARC, and then with DigiCert as the issuing authority for VMC and BIMI certificates, once you have DMARC, we can give you those marks, and you get Gmail gives you the blue check mark, your emails get placed prominently, higher opening rates. It's a beautiful solution.
J
Joshua Marquette16:28
Amit, thanks for joining us today. To learn more about DigiCert, please visit securityweekly.com/digicert rsac for full RSAC 2026 coverage from CyberAlliance visit securityweekly.com/rsac. Stick around, we'll be back after this break.
A
Amit Sinha16:44
Thank you, Josh.
J
Joshua Marquette16:45
Thank you.