Managed key, secret, and certificate store — Azure Key Vault running under Bleu's sovereign operator, with keys backed by French-jurisdiction HSMs. Root-of-trust does not leave the Bleu perimeter, addressing the specific CLOUD Act concern that a Microsoft-operated Key Vault could be compelled to disclose keys.
Jurisdictional exposure
Sub-services (2)
Keys
HSM-backed encryption keys under sovereign operator
Secrets
Secret management with sovereign audit trail
Compliance & Certifications
This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.
Where this runs
Sovereign regions (2)
- ParisBleu Cloud de Confiance
- MarseilleBleu Cloud de Confiance
Tags
Equivalent services on other platforms
Create and manage cryptographic keys for encryption at rest and in transit with AWS-managed, customer-managed, and imported keys, automatic rotation, and FIPS 140-2 validated HSMs
Centralised vault for cryptographic keys, secrets, and certificates with HSM-backed keys, managed certificate renewal, and RBAC or access-policy enforcement
Cryptographic key management with HSM-backed key material, ANSSI-cleared envelope-encryption workflow, and integration with block storage, object storage, and managed databases for at-rest encryption
Cloud-hosted key management for encryption at rest with symmetric and asymmetric keys, customer-supplied keys, HSM-backed keys, and automatic rotation
Centralised key and secret management service with HSM-backed symmetric and asymmetric keys, automatic rotation, and envelope encryption for OCI resources
Managed encryption key store — Google Cloud KMS operating under S3NS's French sovereign boundary, with keys backed by French-jurisdiction HSMs. Root-of-trust does not leave the S3NS perimeter, addressing the specific CLOUD Act concern that a Google-operated Cloud KMS could be compelled to disclose keys.