Thales Launches UK-Hosted Cloud Security Service for Key Control

French cybersecurity firm Thales has introduced a UK-based cloud service that allows organizations to manage cryptographic keys locally, addressing growing concerns about digital sovereignty and data protection.
French technology group Thales has launched a UK-hosted version of its Luna Cloud HSM, a service that provides hardware security capabilities via the cloud. The key distinction of this offering is that the entire lifecycle of cryptographic keys, from generation to destruction, remains within the United Kingdom. This move responds to a specific need in the market: ensuring that sensitive systems not only store data in local data centers but also keep the keys that unlock that data under domestic jurisdiction.
The service, announced on September 14, addresses a critical gap in traditional cloud adoption. While many organizations have moved their data to UK servers, they often rely on cryptographic keys managed by foreign-headquartered providers or tied to specific cloud ecosystems. Thales argues that data residency alone is insufficient if the underlying security infrastructure is controlled abroad. By keeping key management strictly within the UK, the company aims to offer a higher level of sovereign control for sensitive applications and digital identity systems.
Shifting from Hardware to Service
Traditionally, organizations seeking robust key control had to purchase, install, and maintain their own physical hardware security modules. This approach provided maximum control but came with significant costs and operational complexity, including the need for specialized maintenance and scaling infrastructure. Thales’ new offering changes this model by providing these capabilities as a service through its Data Protection on Demand marketplace. This allows customers to consume cryptographic functions without the burden of managing the underlying hardware.
For UK customers, the primary benefit is localization. Thales states that keys will be generated, stored, used, backed up, and destroyed exclusively within the country. The service utilizes two UK-based instances to ensure high availability and disaster recovery, meaning that even in the event of a failure, the security infrastructure remains geographically and legally within the UK. This setup is designed to meet the strict requirements of organizations that cannot afford downtime or loss of control over their security assets.
Independence From Major Cloud Providers
Thales is not the first to offer key management services, as major cloud providers like Microsoft, Amazon, and Google also provide similar tools. However, these native services are typically tied to their respective cloud environments. Thales’ model is delivered independently of any single hyperscaler, allowing organizations to separate their choice of cryptographic infrastructure from the cloud platform hosting their applications. This independence is a significant trade-off for customers who want to avoid dependence on a single foreign-headquartered cloud provider.
This distinction is particularly relevant for organizations concerned about jurisdictional risks. By decoupling the security layer from the hosting layer, Thales offers a path for entities that wish to maintain domestic control over their security keys regardless of where their data is hosted. This approach aligns with broader European concerns about technology sovereignty, where reliance on foreign-controlled infrastructure is seen as a potential risk to national security and privacy.
Sovereignty Implications for Digital Identity
The importance of key sovereignty is most acute in the realm of digital identity, where cryptographic keys underpin credential signing, authentication, and trusted transactions. Recent European cases highlight how these concerns can influence major policy and investment decisions. For instance, the Dutch government blocked a US-based acquisition of a Dutch cloud provider that supported the national authentication system, citing risks to critical infrastructure. Similarly, Switzerland faced controversy over plans involving foreign cloud infrastructure for its electronic identity ecosystem.
These examples demonstrate that physical data residency is no longer the sole criterion for security. Organizations must now consider who controls the keys, where backups are stored, and which legal jurisdiction applies to the infrastructure provider. Thales’ UK-based service positions itself as a solution to these compounded risks, offering a way to consume modern cloud benefits while retaining domestic oversight of the most sensitive security elements. This reflects a broader shift in the industry toward prioritizing sovereignty alongside convenience.






