How it works in a data room
Files in a data room are encrypted with data keys, and those data keys are themselves wrapped by a master key. An HSM holds the master key inside hardened hardware that erases its secrets if someone tries to open it. Software asks the module to wrap or unwrap a key, and the module answers without ever revealing the master key itself. Many providers use a cloud key service backed by HSMs rather than running their own appliances. Validation against FIPS 140-3 is the usual proof that the module meets a recognized standard.
Why it matters in a deal
Encryption at rest is only as strong as the protection around the keys. If keys sit in an ordinary database next to the files, one breach can expose both. HSM-backed key storage is also what makes customer-managed keys practical, because the customer’s key can be held and revoked in hardware the provider cannot read. Banks, defense suppliers and public bodies often list HSM-backed keys as a procurement requirement; see the government and public sector guide.
Example
A state-owned utility selling a minority stake asks bidders’ preferred providers how keys are protected. One provider shows that its master keys sit in FIPS-validated hardware modules in two regions, with key access logged separately from file access. That answer clears the utility’s security review in a single round of questions.