Serve millions of citizens without requiring secure hardware on each device
ProvenHSM provides an assurance foundation for Independent Software Vendors (ISVs), Qualified Trusted Service Providers (QTSPs), and Trust Service Providers (TSPs) building the future of European digital identity.
AUDIENCE
ProvenHSM is a WSCD-ready appliance engineered to host these components in a sovereign, auditable, and high-assurance environment.
By separating crypto trust from service logic, it establishes clear governance boundaries and enables regulators, operators, and ISVs to work from a dependable, pre-certified foundation.
This means developers can deploy WSCA applications without rebuilding complex security infrastructure from scratch.
The secure environment for all cryptographic operations.
The application logic acting on behalf of both the wallet and the citizen.
ARCHITECTURE
As Europe prepares for the 2026–2027 eIDAS v2 rollout, network-attached HSMs have emerged as the most practical and scalable option.
Serve millions of citizens without requiring secure hardware on each device
Fit naturally into existing audit and oversight models used by TSPs
Maintain full digital sovereignty by keeping sensitive operations in government-controlled data centers
ProvenHSM is designed to accelerate development and reduce overhead for software vendors.
WSCA applications run inside a Common Criteria–certified execution environment, allowing teams to focus on business logic, user value, and innovation rather than building a secure base layer.
Thanks to compositional certification (unique to ProvenHSM), applications inherit assurance from the platform, lowering entry barriers and enabling a more interoperable and vibrant digital identity ecosystem.
For QTSPs and public-sector operators, ProvenHSM simplifies operations end-to-end:
Applications Run in a Controlled Zone With Predictable Interfaces
Audits Focus on Application Behavior Instead of the Entire Infrastructure
Third-Party Onboarding Becomes Safer and More Transparent
FEATURES
Across architectures (Arm and RISC-V), evaluation schemes (Common Criteria, SESIP, PSA Certified), and industry partners, ProvenRun consistently demonstrates that high-assurance, formally-verified security can scale to real-world products. These certifications reflect our ongoing commitment to delivering operating systems that meet the needs of regulated industries, safety-critical infrastructures, and next-generation IoT platforms.