Konubinix' opinionated web of thoughts

Is Vault a Software HSM?


Is vault a software HSM?

Vault is a software that stores keys with on-disk encryption and provides transit mechanism to manipulate the keys without getting them out of vault.

In a sense, it provides features that look similar to a HSM. But remember, the H in HSM means hardware. The whole point of a HSM is that it is a separate piece of hardware.

Saying that vault is a software HSM makes things ambiguous because it requires people to be clear about the fact the security model of vault is totally different.