Platform / Keys
Key Management (HSM)
⌘K
Chain synced
Platform
Key Management (HSM)
All signing material lives in FIPS 140-2 Level 3 HSMs. Keys never leave the enclave; rotations are auditable.
Active keys
+1
14
HSM regions
stable
4
Signatures (24h)
+8%
188,410
Next rotation
on schedule
12days
Key inventory
all signing material · HSM-backed
| Alias | Algorithm | HSM | Created | Last rotated | Uses | |
|---|---|---|---|---|---|---|
| issuer-signing-01 | Ed25519 | AWS CloudHSM · use1-a | 2024-11-04 | 2025-06-01 | 41,208 | |
| notary-tsa-01 | ECDSA-P256 | Azure Dedicated HSM | 2024-10-14 | 2025-04-14 | 12,047 | |
| oracle-attest-01 | Ed25519 | GCP Cloud KMS | 2025-01-10 | 2025-07-10 | 8,422 | |
| audit-anchor-01 | Ed25519 | Bare-metal Thales | 2024-06-01 | 2025-06-01 | 128,401 | |
| credential-revoke-01 | Ed25519 | AWS CloudHSM · euw | 2025-02-22 | 2025-08-22 | 322 |
Rotation policy
per key class
Issuer signing keys180 days
Notary TSA keys180 days
Oracle attestation keys90 days
Recovery keys (offline)365 days
Public key registry
on-chain issuer DIDs
did:ledger:z6MkNorthwind-corp#keys-1
published
did:ledger:z6MkAurora-labs#keys-2
published
did:ledger:z6MkDHL-transit#keys-1
published