Login
User Agreement & LicensingPrivacy Policy
FIPS 140-3
Common Criteria EAL5+

Products

  • ProvenHSM
  • ProvenBox
  • Native Security Applications
  • Software Developer Kit (SDK)
  • ProvenCore OS and TEE
  • ProvenVisor

Use Cases

  • Data Protection
  • PQC Migration
  • Key Management & Cloud KMS
  • Confidential Computing
  • Finance Innovation
  • Digital Signature (eIDAS 1.0)
  • Wallet & Identity (eIDAS 2.0)
  • Multi-Party Computation (MPC)
  • Enterprise PKI
  • Strengthening HPC Platforms

Resources

  • Blog and Whitepapers
  • Security and Certifications
  • Integrations

Company

  • Careers
  • About
All customer stories

OVHcloud — Cloud infrastructure

Running Sovereign Key Management on Certified Infrastructure

Digital Cloud
OVH Cloud Logo

Company

OVHcloud

HQ

Roubaix, France

Industry

Cloud infrastructure

Focus

Sovereign KMS, tenant key isolation, compliance

Products used

  • ProvenHSM
  • ProvenCore
A sovereignty claim is only worth what you can demonstrate. Being able to point a regulated customer at a proof of isolation, instead of at a policy document, changed the shape of those conversations entirely.
Full nameJob title

Key outcome

Tenant Key Isolation Backed by Formal Proof

A sovereign key management service has to prove, not merely assert, that one tenant’s keys can never be reached from another tenant’s context. ProvenHSM provides that guarantee at the platform level, so isolation is a property of the certified base rather than of application code.

The challenge

Multi-Tenancy Without Weakening the Trust Boundary

Traditional HSMs were certified as monolithic appliances: any change triggered a full re-evaluation, which meant slow time-to-market and frozen firmware. Cloud environments need the opposite — modularity, rapid integration of new cryptographic services, and the ability to add post-quantum algorithms without a hardware refresh.

The solution

A Certified Base Platform with Composable Modules

ProvenHSM keeps a formally verified operating system as the certified foundation, with crypto services plugging in through clearly defined interfaces (REST, PKCS#11, KMIP). Each new module can be certified incrementally through delta certification, preserving the base platform’s assurance while shortening the path to deployment.

We can add a cryptographic service without reopening the platform evaluation. That is the difference between shipping quarterly and shipping once a year.
— Full name, OVHcloud
Previous storyEviden (BullSequana SH)Next storyOrange

More customer stories

Metal Processor
Bull Logo

High-performance computing

Strengthening HPC Platform Integrity with ProvenCore

Digital Lock
Orange Logo

Telecommunications

Securing Secure Element Provisioning at Carrier Scale

Digital Processor
Renault Logo

Automotive

Hardening Connected Vehicle Gateways and OTA Updates

Explore ProvenHSM
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo