Security, privacy and audit requirements · C0896
Where would root and master keys be kept?
Designed, not yet built
Short answer
How would it be tested? The specification says key export from HSM fails. That is the check for REQ-4602: root and master keys must be in an HSM or equivalent secure element; large tier requires FIPS 140-validated HSM (to be verified); small tier may use a TPM-sealed or smartcard-based custody. Not yet. It is designed in the specification and not built in the pilot.
This is designed, not built.
- Specification item
- REQ-4602
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How are encryption keys arranged, from the root key down to the data key? Designed
- How would key ceremonies be run and recorded? Designed
- How often would encryption keys be rotated? Designed
See it in context: Key management · Search the help center · Ask a question