Many cloud providers can tell you where data is stored.
Few can prove who controls the cryptographic keys protecting it.
For regulated UK organisations, key control is often the difference between meeting sovereignty requirements and simply meeting residency requirements.
UK-hosted Luna Cloud HSMs ensure cryptographic keys are generated, stored, backed up, used, and destroyed entirely within the UK, providing a clear and defensible control boundary.
A UK region tells you where the service runs. It does not always tell you who controls the trust boundary.
Which laws apply to the provider running the infrastructure?
Who on the provider side can access operational systems?
Where are keys generated, used, backed up and destroyed?
For regulated workloads, those details matter. With UK-hosted Luna Cloud HSMs on the Thales DPoD cloud marketplace, customer keys for the UK-based service are generated, used, backed up and destroyed in the UK in customer-controlled partitions. A cloud HSM control boundary you can point to.
Provide evidence to regulators, auditors and risk committees that the full key lifecycle sits under UK jurisdiction
Give security, risk and compliance teams a defensible answer to the "who controls the keys?" question
Move sensitive services into cloud without redesigning your trust model
Separate cryptographic control from your cloud provider's control plane
Build a clear key-control model today that makes post-quantum migration significantly more manageable tomorrow
No dedicated hardware to procure, deploy or operate for each new use case
Sovereignty is now a boardroom issue, while cross-border data access laws, concentration risk and national resilience concerns mean UK organisations must evidence control over their keys, not just assert it.
UK-hosted Luna Cloud HSMs are built for this moment: proven technology, brought under UK sovereign control — and aligned with UK GDPR, NCSC Cloud Security Principles, TSA, FCA/PRA, DORA and NIS.


Application encryption, database key protection, sensitive data protection

PKI, certificate authorities, digital and device identities

Digital signing, code signing, software supply chain, high-value transactions

Consistent key management across on-premises, cloud and SaaS
On-Premises - Luna HSM
Maximum control. Your hardware, your data centre, your rules.
Cloud - UK-Hosted Luna Cloud HSM on DPoD
HSM-as-a-Service. Dedicated HSM resources with simplified operations and sovereign key lifecycle management in the UK.
Hybrid - Hybrid Luna HSM
Combine on-premises and cloud HSMs for greater flexibility, resilience, and sovereignty.
Choose the deployment model that fits your business, while maintaining consistent security and crypto agility across environments.

“Cloud adoption has moved beyond questions of where services are hosted. Organisations increasingly need to know who controls the cryptographic keys protecting their most valuable applications, identities and data,”
Paul Hampton
Data Protection Cloud Services Owner

Or start your free trial HERE
Talk with a Thales expert about maintaining control of encryption keys, meeting regulatory requirements, and reducing sovereignty risk.
Copyright © 2026 Thales. All Rights Reserved