Skip to content Book a PKI health check Get incident support

Hardware key custody

The key stays inside the boundary.

We help you choose the right HSM model, integrate it with ADCS, run a ceremony your auditors can follow and leave your operators ready to recover it.

Custody model

Signing crosses the boundary.
The private key does not.

Hardware protection matters because a stolen CA server should not automatically become a stolen CA identity. The design around the device — quorum, backup and recovery — is what makes that promise operational.

Key custody inside a hardware security module An issuing certificate authority generates its private key inside a hardware security module partition. Signing requests cross the boundary inward and signatures cross back out, but the private key never leaves the hardware. ISSUING CA CERTIFICATE SERVICES PRIVATE KEY HSM PARTITION — FIPS VALIDATED CA private key NON-EXPORTABLE · QUORUM 2 OF 3 KEY NEVER LEAVES THIS BOUNDARY ↓ IN SIGN REQUEST ↑ OUT SIGNATURE ONLY STOLEN SERVER = NO STOLEN KEY

Selection criteria

Choose for the operating model — not the brochure.

Scripted ceremony

Nothing important is improvised in the room.

  • Pre-approved commands and expected output
  • Named roles and M-of-N quorum
  • Witnessed evidence without exposed secrets
  • Tested backup and recovery
  • Signed operational handover

Integration and migration

Move the key without breaking trust.

We map the current provider, CA service behaviour, certificate chain and recovery path before any migration. Cutover gates prove that the CA can sign, publish and recover while existing certificates continue to validate.

Familiarity, not partnership

Engagements can cover network HSMs and cloud HSM services that expose supported Microsoft CSP/KSP integrations. Specific vendor and model fit is validated during discovery.

No manufacturer partnership or endorsement is implied. Recommendations remain vendor-neutral.

Plan an HSM engagement