Hardware Security Module
Protects eSeal/TSA keys with multi-person control and operation logs.
Cryptographic, identity, time, certificate-status, evidence and preservation components supporting Trusted Delivery.
The design separates identity, delivery, evidence generation, cryptographic keys, trusted time and audit preservation.
Production endpoints and certificates are published only after security review and approval.
Protects eSeal/TSA keys with multi-person control and operation logs.
Attaches trusted time to events and evidence packages.
Signs evidence and manages certificate chains and key rollover.
Checks certificate status at verification time.
Identifies policies, profiles and evidence types.
Immutable storage, retention, legal hold and integrity checks.
Version 3 provides the structure without inventing endpoints, certificates or OIDs.