Login
User Agreement & LicensingPrivacy Policy
FIPS 140-3
Common Criteria EAL5+

Products

  • ProvenHSM
  • ProvenBox
  • Native Security Applications
  • Software Developer Kit (SDK)
  • ProvenCore OS and TEE
  • ProvenVisor

Use Cases

  • Data Protection
  • PQC Migration
  • Key Management & Cloud KMS
  • Confidential Computing
  • Finance Innovation
  • Digital Signature (eIDAS 1.0)
  • Wallet & Identity (eIDAS 2.0)
  • Multi-Party Computation (MPC)
  • Enterprise PKI
  • Strengthening HPC Platforms

Resources

  • Blog and Whitepapers
  • Security and Certifications
  • Integrations

Company

  • Careers
  • About

In this article :

  • Keys Were Never the Point
  • Then AI Changed the Urgency
  • Radix: the Thesis Made Concrete
  • The roadmap, in three horizons

The HSM Is Step One: Toward Trust Governance for the AI Era

Keys Were Never the Point

An HSM protects cryptographic keys. But nobody actually wants protected keys; they want the things keys make possible — payments that cannot be forged, identities that cannot be usurped, signatures that stand up in court, updates that cannot be hijacked. The key is an instrument. What organizations ultimately need to protect is decisions: who may do what, under which policy, with which evidence.

Traditional HSMs stop at the instrument. They will sign anything a correctly authenticated caller asks them to sign. The approval workflow, the business rules, the policy — the actual governance — live outside the cryptographic boundary, in ordinary software on ordinary infrastructure, where they can be bypassed, misconfigured, or compromised. We have written before about why formal verification matters for modern HSMs and how incremental certification reconciles assurance with product velocity.

Those two properties — proven isolation and composable certification — are what let ProvenHSM pull governance logic inside the trusted boundary: custody approval flows, policy engines, signature activation, post-quantum hybrid schemes— running as isolated trusted applications on a formally verified kernel.

That is the platform thesis: the HSM is the first trusted application on it, not the last.

Then AI Changed the Urgency

Software is being rewritten at machine speed. As we argued in When AI Writes the World's Software, Who Verifies It?, code generation is racing ahead of code verification. But the deeper shift is not AI writing software — it is AI operating it. Autonomous agents are beginning to move money, commit capital, trigger settlements, and reconfigure systems, at a pace no human oversight loop can match.

This breaks the industry's default control model, which is retrospective: log everything, alert on anomalies, audit afterwards. By the time an alert fires, the transaction has settled. "The AI did it" is not an audit trail, and a log is not governance — it tells you what happened, not what was allowed to happen. Regulators are already drawing that distinction.

There is a second, subtler problem: most policy-enforcement software runs in the same environment as the systems it polices. If the runtime is compromised — or simply misconfigured — the policy dies with it. Governance you cannot separate from the governed is not governance; it is decoration.

So the question becomes: on what foundation can you build enforcement that is provably independent of the thing it constrains? Testing cannot answer that question — testing shows presence of function, never absence of interference. Only formal verification does: a mathematical proof that the isolation between the enforcing component and everything else holds on every execution path. This is precisely the property ProvenCore was built to prove, and precisely why EAL7 exists as an assurance level.

Radix: the Thesis Made Concrete

This is no longer theoretical. Radix— founded by the team behind NGRAVE, with ProvenRun as founding partner — has built the first hardware-enforced governance platform for autonomous systems, on ProvenCore and ProvenHSM-grade hardware.

The model inverts the logging paradigm. Policies, say, a treasury mandate authorizing intraday transfers up to a ceiling, within market hours, to approved entities — are authored, co-signed by compliance, security, and operations, then compiled into a trusted runtime that executes inside a formally verified enclave, separate from the AI systems proposing actions. Every action is checked before execution. Every decision, approval or denial, produces a signed governance receipt: what was checked, what was authorized, and cryptographic attestation of the trusted boundary that enforced it, down to the kernel hash.

When a regulator asks "can you demonstrate governance?", the answer is no longer a log archive. It is a certificate-anchored, as Radix puts it, in proof of isolation that is mathematically proven, not configured or audited. That anchoring is what ProvenRun contributes, and it is not replicable on a foundation that was merely tested.

The roadmap, in three horizons

Seen from here, our direction is one line with three points on it.

Protect the instruments. ProvenHSM as a certified, cloud-operated, PQC-ready root of trust for keys, identities, and credentials. This is shipping.

Host the trust services. Customers and partners deploy their own trusted applications — signature activation, wallet services, custody logic, custom cryptography — inside the proven boundary, with delta-certification keeping assurance intact as the platform evolves. This is what the SDK and the trusted-application catalog exist for, and what partners are building today.

Govern the decisions. The boundary extends from executing cryptographic operations to authorizing actions, human or autonomous;, under enforceable, attestable policy. Radix is the first platform on this horizon; finance and digital-asset custody are the first markets, because that is where ungoverned autonomy is most immediately expensive. Critical infrastructure, healthcare, and government follow the same pattern.

The through-line is the same conviction that produced ProvenCore fifteen years ago: in security, the difference between a claim and a proof is everything. AI has simply raised the price of that difference. Autonomy without verifiable governance is a liability; with it, delegation becomes something an institution can defend — to its auditors, its regulators, and itself.

The HSM was step one.

ProvenCore is Common Criteria EAL7 certified (ANSSI, 2019). ProvenHSM is in evaluation for FIPS 140-3 Level 3 and CC EAL5+ (AVA_VAN.5), target Q4 2026.

Learn more about building on ProvenHSM,download the full technical specifications, or talk to an expert.


Our others articles :

  • RIP Legacy HSM, Enter ProvenHSM

    A side-by-side look at how ProvenHSM compares with legacy network HSMs across operations, cloud readiness, crypto agility, extensibility, multi-tenancy, TCO, and business model

  • Abstract mathematical structures transition through flowing lines into a rack appliance

    ProvenRun spent 15 years proving low-level software correct. Here's why the team behind the world's only EAL7-certified OS decided its next product had to be a cloud-operated hardware security module.

  • generic_partnership_white

    CryptoNext Security and ProvenRun announce the integration of post‑quantum cryptography into ProvenHSM, reinforcing their shared ambition to deliver a fully integrated, high‑assurance, end‑to‑end security stack built for the post‑quantum era and the most demanding environments.

Explore ProvenHSM
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo