OVHcloud — Cloud infrastructure
Running Sovereign Key Management on Certified Infrastructure

A sovereignty claim is only worth what you can demonstrate. Being able to point a regulated customer at a proof of isolation, instead of at a policy document, changed the shape of those conversations entirely.
Key outcome
Tenant Key Isolation Backed by Formal Proof
A sovereign key management service has to prove, not merely assert, that one tenant’s keys can never be reached from another tenant’s context. ProvenHSM provides that guarantee at the platform level, so isolation is a property of the certified base rather than of application code.
The challenge
Multi-Tenancy Without Weakening the Trust Boundary
Traditional HSMs were certified as monolithic appliances: any change triggered a full re-evaluation, which meant slow time-to-market and frozen firmware. Cloud environments need the opposite — modularity, rapid integration of new cryptographic services, and the ability to add post-quantum algorithms without a hardware refresh.
The solution
A Certified Base Platform with Composable Modules
ProvenHSM keeps a formally verified operating system as the certified foundation, with crypto services plugging in through clearly defined interfaces (REST, PKCS#11, KMIP). Each new module can be certified incrementally through delta certification, preserving the base platform’s assurance while shortening the path to deployment.
We can add a cryptographic service without reopening the platform evaluation. That is the difference between shipping quarterly and shipping once a year.











