Mapping security boundaries and failure behavior
The architecture separates applications, administration, backup and key custody. A partition is a logical separation, but it does not replace every organizational or physical separation. We clarify which keys may be replicated, who can extend a cluster and what dependencies exist between sites. If the HSM fails, an application must not silently fall back to unprotected key files. Certificate status and Security Policy are checked for the specific module; a product name or an algorithm validation is not enough.


