QNSI

QNSI platform

What is BYOH?

Also known as Bring Your Own HSM.

Deployment model in which a capability-qualified customer HSM becomes the root of trust for QNSI KMS. Only after qualification may sign / wrap / unwrap operations be represented as executing inside the customer boundary. 6 connector implementations use PKCS#11 (AWS CloudHSM, Azure Dedicated HSM, Thales Luna, Entrust nShield, Utimaco CryptoServer, Marvell LiquidSecurity) and 2 use REST (HashiCorp Vault Transit, Fortanix DSM).

Decision context

Why BYOH matters

Bring-your-own-HSM designs can place root-key operations inside a customer-controlled hardware boundary, supporting custody and separation requirements. The control exists only for operations the qualified device actually performs; a stored handle or connector configuration does not prove hardware execution.

How to evaluate BYOH

Qualify the exact model, firmware, interface, mechanism set, tenancy and operational mode. Execute sign, wrap and unwrap probes and verify their effects independently through device audit evidence. Document fallback, outage, backup, quorum, rotation and recovery behaviour before making customer-custody claims.

QNSI platform

QNSI platform evidence boundary

QNSI platform terms describe intended control or evidence boundaries. Their presence in documentation is not proof that a customer deployment executed them. Verify the selected service path, tenant policy, custody provider, production record, and independent evidence before relying on the term in an assurance decision.

FAQ

Common questions

What is BYOH?

Deployment model in which a capability-qualified customer HSM becomes the root of trust for QNSI KMS. Only after qualification may sign / wrap / unwrap operations be represented as executing inside the customer boundary. 6 connector implementations use PKCS#11 (AWS CloudHSM, Azure Dedicated HSM, Thales Luna, Entrust nShield, Utimaco CryptoServer, Marvell LiquidSecurity) and 2 use REST (HashiCorp Vault Transit, Fortanix DSM).

Why does BYOH matter?

Bring-your-own-HSM designs can place root-key operations inside a customer-controlled hardware boundary, supporting custody and separation requirements. The control exists only for operations the qualified device actually performs; a stored handle or connector configuration does not prove hardware execution.

How should BYOH be evaluated?

Qualify the exact model, firmware, interface, mechanism set, tenancy and operational mode. Execute sign, wrap and unwrap probes and verify their effects independently through device audit evidence. Document fallback, outage, backup, quorum, rotation and recovery behaviour before making customer-custody claims.

What is BYOH also known as?

BYOH is also known as Bring Your Own HSM. Deployment model in which a capability-qualified customer HSM becomes the root of trust for QNSI KMS. Only after qualification may sign / wrap / unwrap operations be represented as executing inside the customer boundary. 6 connector implementations use PKCS#11 (AWS CloudHSM, Azure Dedicated HSM, Thales Luna, Entrust nShield, Utimaco CryptoServer, Marvell LiquidSecurity) and 2 use REST (HashiCorp Vault Transit, Fortanix DSM).

More

Keep exploring