Platform / Keys
Key Management (HSM)
Chain synced
Platform

Key Management (HSM)

All signing material lives in FIPS 140-2 Level 3 HSMs. Keys never leave the enclave; rotations are auditable.

Active keys
+1
14
HSM regions
stable
4
Signatures (24h)
+8%
188,410
Next rotation
on schedule
12days

Key inventory

all signing material · HSM-backed

AliasAlgorithmHSMCreatedLast rotatedUses
issuer-signing-01
Ed25519
AWS CloudHSM · use1-a2024-11-042025-06-0141,208
notary-tsa-01
ECDSA-P256
Azure Dedicated HSM2024-10-142025-04-1412,047
oracle-attest-01
Ed25519
GCP Cloud KMS2025-01-102025-07-108,422
audit-anchor-01
Ed25519
Bare-metal Thales2024-06-012025-06-01128,401
credential-revoke-01
Ed25519
AWS CloudHSM · euw2025-02-222025-08-22322

Rotation policy

per key class

Issuer signing keys180 days
Notary TSA keys180 days
Oracle attestation keys90 days
Recovery keys (offline)365 days

Public key registry

on-chain issuer DIDs

did:ledger:z6MkNorthwind-corp#keys-1
published
did:ledger:z6MkAurora-labs#keys-2
published
did:ledger:z6MkDHL-transit#keys-1
published