MyID SecureVault
Enterprise key escrow, recovery and biometric data storage, independent of any Certificate Authority. Optional HSM-backed key generation, OAuth2 or mutual TLS authentication, full audit logging, and a dual-CMS key escrow model that separates key recovery from day-to-day operations. The secure foundation for enterprise key escrow, credential recovery and cryptographic data protection.
Secure Credential Vault
MyID® SecureVault is a CA-independent secure key archival and biometric data store. Generate, store and recover RSA and ECC private keys with optional HSM-backed hardware protection, or store encrypted biometric data for downstream identity workflows. Full REST API with Swagger documentation.
AES-256 Encryption
Stored private keys and biometric data are encrypted at rest - in HSM mode by an HSM-resident AES-256 key - and all connections require TLS, with TLS 1.3 supported. A software-only mode using a self-signed encryption certificate is also available.
HSM-Backed Key Management
With an HSM configured (Entrust nShield Connect or Solo, Thales Luna), end-entity private keys are generated on the HSM and protected by an HSM-resident AES-256 key. Organisations can deploy initially in software mode and migrate to HSM-backed protection later, while maintaining access to previously archived keys.
Role-Based Access Control
OAuth2 scopes control access to key creation, key recovery and biometric operations, enforcing separation of duties for sensitive key recovery.
Full Audit Trail
Every key and biometric operation is recorded in the SecureVault audit database (maintained in a dedicated audit database by default). The ExternalLinkID field ties each operation to the identifier supplied by the calling system - for example, a per-person GUID from MyID CMS.
REST API Integration
Access key archival and recovery operations programmatically via REST API. Full Swagger documentation. OAuth2 or mutual TLS authentication.
MyID Suite Integration
Deep integration with MyID CMS: configure certificate policies to archive keys in SecureVault, recover keys through MyID CMS, and monitor activity with the built-in SecureVault Usage and Biometric Usage reports in the MyID Operator Client. MyID CMS can issue and recover archived keys from SecureVault, and an additional MyID CMS instance can optionally be deployed as a key escrow recovery portal, separate from the issuance CMS.
Deploy the way you need to
On-Premise
Deploy the vault within your perimeter, with optional HSM hardware connecting directly for maximum key security.
- Windows Server 2019 / 2022
- Deploy the vault within your perimeter, with optional HSM hardware for maximum key security
- SQL Server 2019 / 2022
- IIS + ASP.NET Core Runtime 8.0
Cloud Database
Host the SecureVault databases in the cloud while the web service runs on Windows Server / IIS.
- Microsoft Azure SQL
- Amazon RDS for SQL Server
- TLS required for all connections
- Same or separate key and audit databases
Key Storage Designed for Regulatory Compliance
MyID SecureVault provides HSM-backed key archival and biometric storage that meets the strictest regulatory requirements for cryptographic material handling.
Encryption & Key Protection
In HSM mode, end-entity keys are generated on the HSM and protected by an HSM-resident AES-256 key, with support for FIPS 140-3 Level 3 certified HSMs. In software mode, keys are generated by the Windows provider (certified to FIPS 140-2 Level 1) and stored encrypted in CMS (RFC 5652) format.
- HSM mode: FIPS 140-3 Level 3 certified HSMs supported; keys generated and wrapped on the HSM
- Software mode: Windows provider, FIPS 140-2 Level 1
- AES-256 HSM-resident wrapping key
- RSA 4096 self-signed encryption certificate (software mode)
US Federal
Supports FIPS 201 PIV credential lifecycle workflows, including secure key escrow, controlled key recovery and biometric data storage.
- Key archival and recovery via MyID CMS
- Dual-CMS key escrow with restricted recovery
- Biometric storage: fingerprint (incl. 10-slap), facial, iris, requires MyID CMS PIV 12.17+
- On-premise deployment on your own infrastructure
Audit and Governance
Every key and biometric operation is recorded in the SecureVault audit database (separate by default), supporting regulatory audit requirements across all sectors.
- Dedicated audit database (default; can be combined)
- Key and biometric operations logged
- ExternalLinkID links every operation to the calling system’s identifier (e.g. per-person GUID from MyID CMS)
- Query the audit database with your own reporting tools
Technical specifications
Platform
- Windows Server 2019 / 2022
- ASP.NET Core Runtime 8.0
- IIS (web service hosting)
- TLS required for all connections
- REST API with Swagger documentation
Key Algorithms
- RSA 2048, 3072, 4096
- ECC P256, P384, P521
- Generate, import, sign, recover
- CMS (RFC 5652) encrypted storage
- Batch operations (default 50 per call, configurable)
- RSA 1024: import, store and recover only (not generate)
HSM Support
- Entrust nShield Connect
- Entrust nShield Solo
- Thales Luna
- AES-256 HSM-resident wrapping key
- Configurable concurrent sessions
Database
- SQL Server 2019 / 2022
- Azure SQL
- Amazon RDS for SQL Server
- Key and audit databases (same or separate)
Authentication
- OAuth2 (via MyID CMS web.oauth2)
- Two-way TLS (client certificate)
- TLS 1.3 supported
- CORS configurable
CMS Integration
- MyID CMS 12.13+ (key escrow & ECC from 12.14; multiple instances from 12.16, or 12.13/12.14 with updates)
- Up to 10 SecureVault instances (CMS 12.16+)
- Key Escrow (dual CMS system)
- Biometric storage from CMS PIV 12.17
Enterprise key escrow and recovery
Centralised escrow of certificate private keys, with recovery restricted to authorised operators and every operation audited.
Securely store and manage encryption keys and certificate private keys in a central vault.
Role-based permissions ensure only authorised personnel can access escrowed keys. Full audit trail for compliance.
Recover keys through the SecureVault REST API or MyID CMS, with recovery rights restricted to authorised operators and every recovery logged.
Common questions
Everything you need to know. Can't find the answer? Contact our team →
MyID SecureVault is a key archival and biometric data storage module, with optional HSM backing (Entrust nShield Connect and Solo, Thales Luna). It provides secure storage and recovery of private keys and biometric data, with OAuth2 or mutual TLS authentication, full audit logging and CA-independent key management.
MyID SecureVault is a key archival and biometric data storage service, not a PAM tool. It provides CA-independent private key storage and recovery, which complements PAM solutions by ensuring the underlying cryptographic keys are always recoverable regardless of CA vendor.
SecureVault stores and recovers private keys (RSA 2048/3072/4096, ECC P256/P384/P521) and encrypted biometric data. It provides CA-independent key archival with HSM-protected storage, ensuring keys can be recovered even when changing certificate authority vendors. RSA 1024-bit keys can be imported, stored and recovered (but not generated).
MyID SecureVault is on-premise software: the web service, databases and supported HSMs (Entrust nShield, Thales Luna) all run on your own infrastructure. For guidance on operating SecureVault in classified or air-gapped environments, contact Intercede.
Trusted at every scale, in every environment
Intercede has specialised in digital identity management since 2001. Our engineering team holds deep expertise in PKI, FIDO2 , smart card systems, and credential lifecycle management across government, defence, and enterprise environments.
MyID is deployed in environments requiring FIPS 201, NIS2 , DORA , NIST SP 800-63B, HIPAA, and ISO 27001 compliance. Intercede itself holds ISO 27001 and Cyber Essentials Plus certification.
A national Ministry of Defence advisory body in Asia Pacific deployed MyID CMS and MyID SecureVault across multiple air-gapped environments, managing tens of thousands of devices - with CA-independent key storage and biometric Match-on-Card authentication.