ARKION
Field Notes/Field Note No. 09
Field Note · Architecture

54,118 Signatures
a Second.
The Engine Powering
Non-Human Identity.

Every AI agent, service, and machine workload needs an identity it can prove, instantly, at scale, without slowing anything down. This quarter, we put our signing engine to the test. It sustained 54,118 signatures per second, and every one of them still passed the full governance chain before it was issued.

Published
August 20, 2026
Category
Architecture
Read Time
5 min
Reference
FN-09-2026

The machine workforce is about to outnumber the human one by a wide margin. Every agent, service account, and workload in that population needs an identity it can present and prove in the moment it acts, not minutes later. An identity layer for that world has one non-negotiable property before any other: it has to sign fast, and keep signing, at a scale most systems never reach.

Built for Scale from Day One

This quarter we put Arkion’s cryptographic core under load. It sustained 54,118 signatures per second under continuous load, with individual signing operations completing in as little as 125 microseconds on the fastest profiles. It is a benchmark, and we say so plainly. But it is not a demo rig tuned for a headline: it is the same engine underneath the identity layer we are building for the agentic economy, measured with the full governance chain switched on. In that economy, the number of machine identities requiring governance is about to dwarf the number of humans who have ever logged into anything.

We ran it across the modern cryptographic spectrum: ECDSA, RSA, and NIST’s post-quantum standards, ML-DSA and SLH-DSA. We tested post-quantum on purpose. The identity layer being built now has to hold up where cryptography is going, not only where it is today. Few platforms in this category are testing for that yet. We already are.

The Rotation Dial

Raw throughput is not the goal. Rotation is. A certificate is only as safe as the window it stays valid for, and the surest way to shrink what a stolen credential is worth is to rotate identities often. That frequency should be a dial the customer sets, and that dial is exactly what signing throughput pays for.

At the standard end, the industry is already turning it. Since March 2026, the maximum lifetime of a public-trust TLS certificate is capped at 200 days, and the CA/Browser Forum schedule tightens it to 100 days in March 2027 and 47 days by March 2029. Shorter lifetimes mean more issuance, and more issuance means the platform underneath had better be fast.

Turn the dial tighter and the demands climb. Rotate an identity every day, or every 60 minutes, for the workloads that warrant it. Tighter still, rotate per transaction for high-value, high-integrity operations, so each action carries a credential good for exactly one use and never again, closer in spirit to a one-time password than to a long-lived key. Every step down that dial multiplies the signatures the platform has to produce, on time, under load.

What the number is for
54,118 signatures per second is not a bragging number. It is the headroom that lets a customer choose per-transaction rotation, or hourly, or daily, or the 47-day standard, and hit that requirement without breaking their systems or their budget. The rotation policy your security team wants is only real if the engine underneath can afford it.

Governance, Not Just Speed

Speed alone is not the point, and it is not the hard part. The hard part is doing the governance without giving the speed back. Every certificate Arkion issues runs through full authentication, policy evaluation, and audit logging before it is delivered, the chain that turns a raw signature into an identity you can actually hold accountable. Every signature issued in the benchmark run cleared that chain before it was delivered. Separately, we validated the pipeline end to end across twenty-one distinct cryptographic profiles, with the vast majority passing clean.

That combination is the bet we are making. The identity platform that wins the machine economy will not be the fastest signer or the most careful ledger on its own. It will be the one that does both, natively, in the same system, so governance is a property of every issuance rather than a tax paid on top of performance.

What’s Next

We are closing out qualification on the remaining cryptographic profile and moving straight into hardening the engine for production scale. The benchmark tells us the architecture holds under load. The next job is making it hold in the messier conditions of real deployment. The pace of this benchmark reflects the pace of the team building it.

Arkion Research Desk
Field Note FN-09-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings: research@arkion.ai
Sources & Notes
  • Arkion internal benchmark, Q3 2026: sustained signing throughput and latency measured on Arkion’s cryptographic core across ECDSA, RSA, ML-DSA, and SLH-DSA profiles, with the full authentication, policy-evaluation, and audit pipeline enabled. Latency varies by algorithm family; the 125-microsecond figure is the floor across profiles, not the median. First-party results; methodology, including per-profile latency, available to design partners on request.
  • CA/Browser Forum, Ballot SC-081v3 (April 2025): phased reduction of maximum public-trust TLS certificate lifetime to 200 days (March 2026), 100 days (March 2027), and 47 days (March 2029).
  • NIST post-quantum signature standards: ML-DSA (FIPS 204) and SLH-DSA (FIPS 205), finalized August 2024.
Next Step

Set the rotation dial
where you want it.

Per-transaction, hourly, daily, or the 47-day standard: Arkion is built so the rotation policy your security team wants is one your systems and budget can afford. Read the brief, or run a read-only Discovery Scan and see what is signing under your authority today.