Skip to main content
Home > MyID Product Family > MyID SecureVault

MyID SecureVault

Enterprise key escrow, recovery and biometric data storage, independent of any Certificate Authority. Optional HSM-backed key generation, OAuth2 or mutual TLS authentication, full audit logging, and a dual-CMS key escrow model that separates key recovery from day-to-day operations. The secure foundation for enterprise key escrow, credential recovery and cryptographic data protection.

What MyID SecureVault does

Secure Credential Vault

MyID® SecureVault is a CA-independent secure key archival and biometric data store. Generate, store and recover RSA and ECC private keys with optional HSM-backed hardware protection, or store encrypted biometric data for downstream identity workflows. Full REST API with Swagger documentation.

Why teams choose MyID SecureVault
CA-independent key escrow
Generate, import and recover keys without depending on a specific CA or PKI vendor. RSA 2048/3072/4096 and ECC P256/P384/P521 supported.
Hardware-backed keys and biometric storage
Optional HSM integration for hardware-protected key generation and storage (Entrust nShield Connect and Solo, Thales Luna), plus encrypted storage for fingerprint (including 10-slap), facial and iris biometrics, serving identity verification and credential issuance workflows across the MyID suite.
Key recovery beyond CA end-of-life
Certificate Authorities have a limited lifetime, yet archived private keys are expected to remain recoverable well beyond the operational life of the CA. SecureVault lets you migrate archived private keys out of a CA, so keys can still be recovered even after the CA is end-of-life and no longer running.
Data Sovereignty
When private keys are archived within a third-party Certificate Authority environment, control of key recovery remains dependent upon that CA's infrastructure and operational availability. SecureVault keeps key escrow under your direct control, preserving data sovereignty and operational independence.
Cryptographic Vault
MyID SecureVault
RSA & ECC
Key Algorithms
RSA 2048/3072/4096 and ECC P256/P384/P521
Encryption
AES-256
TLS-protected in transit (TLS 1.3 supported), HSM-resident AES-256 key at rest (HSM mode)
Key management
Supported HSMs
Entrust nShield Connect & Solo, Thales Luna
Access control
OAuth2 + mTLS
Scoped OAuth2 tokens or two-way TLS client certificates
Standards & compliance
RFC 5652 REST API SWAGGER DOCS UP TO 10 INSTANCES

AES-256 Encryption

Stored private keys and biometric data are encrypted at rest - in HSM mode by an HSM-resident AES-256 key - and all connections require TLS, with TLS 1.3 supported. A software-only mode using a self-signed encryption certificate is also available.

HSM-Backed Key Management

With an HSM configured (Entrust nShield Connect or Solo, Thales Luna), end-entity private keys are generated on the HSM and protected by an HSM-resident AES-256 key. Organisations can deploy initially in software mode and migrate to HSM-backed protection later, while maintaining access to previously archived keys.

Role-Based Access Control

OAuth2 scopes control access to key creation, key recovery and biometric operations, enforcing separation of duties for sensitive key recovery.

Full Audit Trail

Every key and biometric operation is recorded in the SecureVault audit database (maintained in a dedicated audit database by default). The ExternalLinkID field ties each operation to the identifier supplied by the calling system - for example, a per-person GUID from MyID CMS.

REST API Integration

Access key archival and recovery operations programmatically via REST API. Full Swagger documentation. OAuth2 or mutual TLS authentication.

MyID Suite Integration

Deep integration with MyID CMS: configure certificate policies to archive keys in SecureVault, recover keys through MyID CMS, and monitor activity with the built-in SecureVault Usage and Biometric Usage reports in the MyID Operator Client. MyID CMS can issue and recover archived keys from SecureVault, and an additional MyID CMS instance can optionally be deployed as a key escrow recovery portal, separate from the issuance CMS.

Deployment

Deploy the way you need to

On-Premise

Deploy the vault within your perimeter, with optional HSM hardware connecting directly for maximum key security.

  • Windows Server 2019 / 2022
  • Deploy the vault within your perimeter, with optional HSM hardware for maximum key security
  • SQL Server 2019 / 2022
  • IIS + ASP.NET Core Runtime 8.0

Cloud Database

Host the SecureVault databases in the cloud while the web service runs on Windows Server / IIS.

  • Microsoft Azure SQL
  • Amazon RDS for SQL Server
  • TLS required for all connections
  • Same or separate key and audit databases
Compliance

Key Storage Designed for Regulatory Compliance

MyID SecureVault provides HSM-backed key archival and biometric storage that meets the strictest regulatory requirements for cryptographic material handling.

Encryption & Key Protection

In HSM mode, end-entity keys are generated on the HSM and protected by an HSM-resident AES-256 key, with support for FIPS 140-3 Level 3 certified HSMs. In software mode, keys are generated by the Windows provider (certified to FIPS 140-2 Level 1) and stored encrypted in CMS (RFC 5652) format.

  • HSM mode: FIPS 140-3 Level 3 certified HSMs supported; keys generated and wrapped on the HSM
  • Software mode: Windows provider, FIPS 140-2 Level 1
  • AES-256 HSM-resident wrapping key
  • RSA 4096 self-signed encryption certificate (software mode)

US Federal

Supports FIPS 201 PIV credential lifecycle workflows, including secure key escrow, controlled key recovery and biometric data storage.

  • Key archival and recovery via MyID CMS
  • Dual-CMS key escrow with restricted recovery
  • Biometric storage: fingerprint (incl. 10-slap), facial, iris, requires MyID CMS PIV 12.17+
  • On-premise deployment on your own infrastructure

Audit and Governance

Every key and biometric operation is recorded in the SecureVault audit database (separate by default), supporting regulatory audit requirements across all sectors.

  • Dedicated audit database (default; can be combined)
  • Key and biometric operations logged
  • ExternalLinkID links every operation to the calling system’s identifier (e.g. per-person GUID from MyID CMS)
  • Query the audit database with your own reporting tools
Specifications

Technical specifications

Platform

  • Windows Server 2019 / 2022
  • ASP.NET Core Runtime 8.0
  • IIS (web service hosting)
  • TLS required for all connections
  • REST API with Swagger documentation

Key Algorithms

  • RSA 2048, 3072, 4096
  • ECC P256, P384, P521
  • Generate, import, sign, recover
  • CMS (RFC 5652) encrypted storage
  • Batch operations (default 50 per call, configurable)
  • RSA 1024: import, store and recover only (not generate)

HSM Support

  • Entrust nShield Connect
  • Entrust nShield Solo
  • Thales Luna
  • AES-256 HSM-resident wrapping key
  • Configurable concurrent sessions

Database

  • SQL Server 2019 / 2022
  • Azure SQL
  • Amazon RDS for SQL Server
  • Key and audit databases (same or separate)

Authentication

  • OAuth2 (via MyID CMS web.oauth2)
  • Two-way TLS (client certificate)
  • TLS 1.3 supported
  • CORS configurable

CMS Integration

  • MyID CMS 12.13+ (key escrow & ECC from 12.14; multiple instances from 12.16, or 12.13/12.14 with updates)
  • Up to 10 SecureVault instances (CMS 12.16+)
  • Key Escrow (dual CMS system)
  • Biometric storage from CMS PIV 12.17
Key Management

Enterprise key escrow and recovery

Centralised escrow of certificate private keys, with recovery restricted to authorised operators and every operation audited.

Key Escrow

Securely store and manage encryption keys and certificate private keys in a central vault.

Access Controls

Role-based permissions ensure only authorised personnel can access escrowed keys. Full audit trail for compliance.

Controlled Recovery

Recover keys through the SecureVault REST API or MyID CMS, with recovery rights restricted to authorised operators and every recovery logged.

Frequently Asked Questions

Common questions

Everything you need to know. Can't find the answer? Contact our team →

MyID SecureVault is a key archival and biometric data storage module, with optional HSM backing (Entrust nShield Connect and Solo, Thales Luna). It provides secure storage and recovery of private keys and biometric data, with OAuth2 or mutual TLS authentication, full audit logging and CA-independent key management.

MyID SecureVault is a key archival and biometric data storage service, not a PAM tool. It provides CA-independent private key storage and recovery, which complements PAM solutions by ensuring the underlying cryptographic keys are always recoverable regardless of CA vendor.

SecureVault stores and recovers private keys (RSA 2048/3072/4096, ECC P256/P384/P521) and encrypted biometric data. It provides CA-independent key archival with HSM-protected storage, ensuring keys can be recovered even when changing certificate authority vendors. RSA 1024-bit keys can be imported, stored and recovered (but not generated).

MyID SecureVault is on-premise software: the web service, databases and supported HSMs (Entrust nShield, Thales Luna) all run on your own infrastructure. For guidance on operating SecureVault in classified or air-gapped environments, contact Intercede.

Why Intercede

Trusted at every scale, in every environment

Our Expertise
25+ Years in Identity Security

Intercede has specialised in digital identity management since 2001. Our engineering team holds deep expertise in PKI, FIDO2 , smart card systems, and credential lifecycle management across government, defence, and enterprise environments.

Standards & Compliance
Built for Regulated Environments

MyID is deployed in environments requiring FIPS 201, NIS2 , DORA , NIST SP 800-63B, HIPAA, and ISO 27001 compliance. Intercede itself holds ISO 27001 and Cyber Essentials Plus certification.

Proven in Defence
SecureVault in National Defence

A national Ministry of Defence advisory body in Asia Pacific deployed MyID CMS and MyID SecureVault across multiple air-gapped environments, managing tens of thousands of devices - with CA-independent key storage and biometric Match-on-Card authentication.

MyID SecureVault

Maintain control of your cryptographic assets for the full credential lifecycle.

MyID SecureVault gives you encrypted, optionally HSM-backed storage and recovery for private keys and biometric data - with the full audit trail needed for compliance. Book a demo.