Skip to content

Key Management

Key management services are used to securely store and manage cryptographic signing keys for Decentralized Identifiers (DIDs) in Governance Studio. When the platform creates DIDs for users and organizations, cryptographic keys are generated and stored in a managed key vault for secure signing operations.

Governance Studio supports the following cloud key management services:

  • Azure Key Vault – Microsoft Azure’s managed key vault service
  • AWS KMS (AWS Key Management Service) – Amazon’s managed encryption and key management service

Select a key management provider based on your organization’s cloud infrastructure:

  • Azure Key Vault: Best for organizations using Azure cloud services or Microsoft Entra ID for authentication
  • AWS KMS: Ideal for organizations with AWS infrastructure or using AWS S3 for storage

Both providers offer:

  • FIPS 140-2 validated hardware security modules (HSMs)
  • Centralized key lifecycle management
  • Audit logging and compliance features
  • Automatic key generation and rotation capabilities