Thales announced on September 14 a UK-hosted version of Luna Cloud HSM, its hardware-security-module capability delivered as a cloud service. The company says customer keys can be generated, stored, used, backed up and destroyed within UK-hosted infrastructure.
Two UK instances are intended to support availability and disaster recovery within the country. The service is positioned for organizations that need to separate the location of application data from control of the cryptographic keys used to protect it.
Claims about service architecture and compliance originate with Thales and should be treated as vendor statements unless checked against the relevant independent validation records and customer-specific configuration. UK hosting also does not remove the need for access governance, backup policy and key-lifecycle controls.
Why it matters
Data residency answers where data is stored; key sovereignty asks who can authorize decryption and under which jurisdiction. Regulated organizations increasingly need evidence for both questions when evaluating cloud security architecture.
For wider context, see SectechMedia’s related technical coverage.
