The cryptographic root of trust, back under your control. On every cloud
Hardware-backed key protection without the appliance: keys are generated, stored and used inside sealed environments no provider or administrator can reach, and released only to workloads that prove their integrity.
COEXISTS WITH YOUR EXISTING HSM ESTATE — NO RIP-AND-REPLACE. VAULT AND NITRIDE SHIP AS CORE APPS ON THE PLATFORM.
Key management is a committee purchase. This is the answer each seat at the table is looking for.
Keys are protected from cloud providers, administrators and privileged users; release is zero-trust and attestation-gated; every key use, access attempt and admin action lands in an immutable audit trail with SIEM integration.
“Cloud providers, administrators and infrastructure operators cannot access my organization's encryption keys.”
Replace fragmented HSM appliances and per-cloud KMS architectures with one abstraction: high availability, clustering, backup and DR built in, and the same controls on every provider — workloads move without redesigning key management.
“I give every cloud workload the same key management capabilities, regardless of where it runs.”
REST/gRPC APIs, SDK and CLI, Kubernetes secrets and CSI integration, sidecar injection, GitOps and Terraform workflows — full lifecycle automation from creation and rotation to revocation, with self-service instead of tickets.
“Developers consume secure key operations without understanding HSM complexity.”
The full surface, condensed — from cryptographic assurance to the ecosystem it plugs into.
3D encryption (in use, at rest, in transit), HSM-backed unsealing and randomness, secure key generation, tamper-resistant operations, protection against privileged administrators, attestation-based key release.
Creation, rotation, expiration, revocation, versioning, backup and recovery — with policy-based lifecycle automation across environments.
RBAC authentication, fine-grained authorization policies, workload and service identity integration — only authorized users and attested workloads use keys.
Immutable audit logs, key-usage tracking, administrative activity logging, compliance reporting, policy enforcement, evidence generation, SIEM integration.
AWS, Azure, Google Cloud, IONOS, STACKIT and OVH, plus private cloud and on-prem — one cloud-agnostic KMS abstraction with consistent controls everywhere.
REST and gRPC APIs, SDK and CLI, Kubernetes secrets and CSI driver integration, sidecar injection, service-catalog self-service, Docker/Helm/Terraform deployment.
HSM-vendor-agnostic integration via PKCS#11, TLS 1.3, enterprise PKI compatibility, RSA/ECC/AES and DH — with post-quantum cryptoagility built into the roadmap of every key.
High availability, clustering and replication, monitoring, telemetry and metrics, automated upgrades, patching and backup.
Deploy where you run
Install via Docker, Helm or Terraform — on any supported cloud, private cloud or your own hardware.
Define identities and policy
Model who and what may use which keys: RBAC for people, workload identities for systems.
Keys flow only to proven workloads
Applications receive keys only after authentication, authorization and workload attestation.
Attested release
Built to join your estate, not replace it on day one
Most enterprises arrive with HSM appliances under depreciation, cloud KMS in production and a PKI that took years to build. vHSM is designed for that reality: standard interfaces in, gradual migration when the numbers say so.
Custody is three jobs, not one
vHSM holds the cryptographic root of trust. Two companion layers make it usable: Vault governs the application secrets built on top of those keys, and Nitride decides which workloads are allowed to have them.
Workload starts
Code, config and platform state measured by the CPU
Evidence produced
Hardware-rooted attestation report, signed
Policy checked
Nitride verifies the measurement against your policy
Keys released
vHSM and vault unseal — only now, only to this workload
Workload starts
Tampered image, injected container or rogue host
Evidence produced
Measurement does not match what you approved
Policy rejects
Mismatch logged with its reason, for the audit file
Nothing released
No keys, no secrets — the data stays ciphertext
What evaluators ask
Is a software HSM really HSM-grade?
The protection boundary is hardware — just not an appliance. Keys live inside trusted execution environments where memory is encrypted by the CPU during use, generation happens in sealed environments with HSM-backed randomness, and operations are tamper-resistant by construction. What you give up is the physical box; what you gain is elasticity, multi-cloud reach and appliance-free economics.
Does this replace AWS KMS, Azure Key Vault and Google Cloud KMS?
It can, but it doesn't have to on day one. The realistic pattern: crown-jewel and regulated keys move to vHSM for custody outside any provider's reach, while cloud KMS keeps serving commodity workloads. The abstraction layer means applications stop caring which is underneath — and the migration is a policy decision, not a re-architecture.
What happens to the physical HSMs we already own?
They keep working. PKCS#11 keeps HSM-dependent applications running, and coexistence is the designed starting state — consolidation follows your depreciation schedule and your risk appetite, not a vendor's timeline.
How does attestation-gated release work in practice?
A workload requests a key; before release, vHSM verifies its identity and — where configured — its attestation: cryptographic proof that it's genuine, unmodified code in a genuine trusted environment. A stolen credential without a valid runtime gets nothing. The result is that key access is governed by cryptographic policy rather than administrative privilege.
Is it ready for post-quantum cryptography?
Cryptoagility is designed in: algorithm support spans RSA, ECC, AES and DH today, with post-quantum readiness as a first-class roadmap property — so the migration to PQC becomes a key-lifecycle operation rather than a platform replacement.
What does performance look like for high-volume operations?
Clustering and replication scale throughput horizontally, and the honest per-operation numbers should come measured, not marketed.
Take your keys back_
Tell us where your keys live today — appliances, cloud KMS or both. We'll show you what custody outside the provider's reach looks like, and what it takes to get there without a re-architecture.
Want the deeper technical picture first? Read the docs or browse the reference architectures.
.png)
