KEYRA sovereign trust

hsm.keyrakey.com

hsm.keyrakey.com operations

Deep operational surfaces for fleet, signing, authorization, attestation, clusters, firmware, threats, supply chain, AI governance, and recovery.

Operational modules

25

Attested devices

18,432

Policy decisions

42.7K/s

Audit integrity

100%

Live telemetry stream

SSE reconnecting

waiting for stream...

Signing throughput (D3)

Trust mesh (Three.js)

HSM Fleet + KEYRA CORE

Hardware estate, CORE modules, topology, thermals, attestation, and replication.

EDGE-1U-ATL-0442

KEYRA HSM Edge - Atlanta POP

verified

Zone US-COMM - 42C - live

SMB-1U-FRA-1881

KEYRA HSM SMB - Frankfurt

verified

Zone EU-ENT - 39C - warm

ENT-2U-SIN-9017

KEYRA HSM Enterprise - Singapore DC4

verified

Zone APAC-SOV - 44C - live

SOV-2U-ZRH-4100

Sovereign Cluster - Zurich

ceremony locked

Zone CH-AIRGAP - 37C - windowed

Distributed Signing Fabric

Queues, tenant isolation, rate limits, audit stamping, and cross-site execution.

Tenant A banking

1,280 queued - p99 9.4 ms

PTP sealed

hardware partition isolation

Sovereign CA

342 queued - p99 14.2 ms

ceremony stamped

air-gap window isolation

Telecom SIM auth

8,910 queued - p99 6.7 ms

streaming SIEM

POP local isolation

AI workload grants

628 queued - p99 12.1 ms

lineage linked

model-bound key isolation

Authorization Fabric + Policy

RBAC, ABAC, Zero Trust, geo/time controls, AI boundaries, and deterministic enforcement.

RBAC operator role

18.2K/s - 3.1 ms

0 conflicts

enterprise

ABAC geo/time lock

9.8K/s - 4.6 ms

2 conflicts

sovereign

Zero Trust mTLS grant

14.7K/s - 5.2 ms

1 conflicts

telecom

AI execution boundary

1.9K/s - 8.4 ms

0 conflicts

AI governance

Hardware Attestation Registry

TPM EKs, serial mappings, firmware manifests, clone detection, quarantine, and revocation.

ENT-2U-SIN-9017

EK-91B7 - fw-ent-4.8.2

trusted

factory sealed

CORE-SOV-ZRH-441

EK-44A1 - fw-core-sov-2.1.0

trusted

M-of-N locked

EDGE-ATL-0442

EK-18C4 - fw-edge-3.9.8

trusted

shipment attested

SMB-FRA-1881

EK-77F2 - fw-smb-3.4.1

watched

clone scan clean

Cluster Orchestration + DR

Quorum, leader election, update waves, replication latency, and failover readiness.

US-COMM-Q7

Quorum 7/9 - leader ATL-0442

ready

22 ms replication - ring 2

EU-ENT-Q5

Quorum 5/5 - leader FRA-1881

ready

31 ms replication - ring 1

APAC-SOV-Q9

Quorum 8/9 - leader SIN-9017

ceremony

windowed replication - frozen

CH-AIRGAP-Q3

Quorum 3/3 - leader ZRH-4100

sealed

offline replication - manual

Firmware Lifecycle

Signed firmware, rollout rings, A/B partitions, attestation gates, and rollback prevention.

fw-ent-4.8.2

6,210 devices - ring 3

blocked

gated

fw-core-sov-2.1.0

918 devices - ring 1

fused

ceremony

fw-edge-3.9.8

8,221 devices - ring 4

counter locked

continuous

Secure Manufacturing Chain

Signed evidence from sourcing to firmware injection, ceremonies, burn-in, tamper validation, and shipment.

Component sourcing

SIG-EVIDENCE-01

sealed

PCB manufacturing

SIG-EVIDENCE-02

sealed

Secure receiving

SIG-EVIDENCE-03

sealed

Firmware injection

SIG-EVIDENCE-04

sealed

M-of-N ceremony

SIG-EVIDENCE-05

sealed

Burn-in testing

SIG-EVIDENCE-06

sealed

Tamper validation

SIG-EVIDENCE-07

sealed

Shipment attestation

SIG-EVIDENCE-08

in transit

Threat Intelligence Center

Anomaly overlays, firmware drift, unauthorized devices, supply-chain risk, and forensic playback states.

Firmware drift

EU-ENT - manifest mismatch

watched

rollout paused

Signing anomaly

Telecom POP - queue burst

medium

rate limited

Supply-chain exposure

BOM NIC - geopolitical risk

low

alternate vendor

Unauthorized device

US-COMM - unknown EK

blocked

quarantined

Deployment Topology

Rack, telecom, vault, and air-gap deployment operating modes.

42U sovereign rack

7.8 kW - cold aisle nominal

rack

segmented

Telecom 5G edge POP

-48V DC redundant - NEBS envelope

edge

subscriber-local

Enterprise vault zone

A/B feed - quiet acoustic

vault

tenant isolated

Air-gapped ceremony room

offline UPS - manual review

sovereign

export controlled

Supply Chain + Procurement

BOM exposure, supplier scorecards, RFP state, and lifecycle forecasting.

CPU - Vendor Alpha

US/EU - lead 18 weeks

low

Buffer 22 weeks

NVMe - Vendor Delta

JP/KR - lead 14 weeks

medium

Buffer 16 weeks

PCB - Sovereign PCB Line

EU - lead 10 weeks

low

Buffer 20 weeks

HSM Enterprise Gen-2 chassis

4 vendors

92/100

engineering qualification

Sovereign rack deployment kit

3 vendors

88/100

compliance review

AI Authorization Governance

Hardware-bound AI identity, policy constraints, auditability, and execution lineage.

Keyra Ops Copilot

AI-MDL-OPS-01 - hardware bound

full

read-only recommend

Threat Interpreter

AI-MDL-THREAT-04 - attested enclave

full

analyst approval

Procurement Risk Agent

AI-MDL-SUPPLY-02 - tenant bound

full

no autonomous purchase

Sovereign operations mode

Government, central-bank, telecom, export-controlled, and air-gapped workflows are represented as isolated operating modes.

North America

enterprise + telecom

8 ms

European Union

GDPR sovereign

12 ms

Gulf Region

central bank

18 ms

APAC

hybrid telecom

15 ms

Air-Gapped Estates

offline ceremony

windowed