Data Rooms Providers Find a data room
VDR glossary · Security

What is a hardware security module (HSM)?

Definition

Hardware security module (HSM): A tamper-resistant physical device, or a cloud service built on such devices, that generates and stores cryptographic keys and performs encryption so the keys never leave protected hardware.

How it works in a data room

Files in a data room are encrypted with data keys, and those data keys are themselves wrapped by a master key. An HSM holds the master key inside hardened hardware that erases its secrets if someone tries to open it. Software asks the module to wrap or unwrap a key, and the module answers without ever revealing the master key itself. Many providers use a cloud key service backed by HSMs rather than running their own appliances. Validation against FIPS 140-3 is the usual proof that the module meets a recognized standard.

Why it matters in a deal

Encryption at rest is only as strong as the protection around the keys. If keys sit in an ordinary database next to the files, one breach can expose both. HSM-backed key storage is also what makes customer-managed keys practical, because the customer’s key can be held and revoked in hardware the provider cannot read. Banks, defense suppliers and public bodies often list HSM-backed keys as a procurement requirement; see the government and public sector guide.

Example

A state-owned utility selling a minority stake asks bidders’ preferred providers how keys are protected. One provider shows that its master keys sit in FIPS-validated hardware modules in two regions, with key access logged separately from file access. That answer clears the utility’s security review in a single round of questions.

Related terms