Distributed signing authority
No single party can produce a CNML certificate at the root or Issuing Authority tier. Signing authority is distributed across an international threshold quorum of directors and officers using FROST threshold signatures. A court order directed at one officer cannot complete a signature, and theft of one key holder's hardware cannot forge a certificate. The aggregate public key survives director rotation, so all previously issued certificates remain valid without re-issuance.