Cryptographic key protection

FIPS 140-2 Level 3 key protection

The private key that seals every finalized BeeSign document is generated and stored inside Google Cloud HSM — a hardware security module validated to FIPS 140-2 Level 3. The key is non-exportable and never leaves the hardware.

What is FIPS 140-2 Level 3?

FIPS 140-2 is a US government standard (from NIST) that specifies security requirements for cryptographic modules — the hardware and software that protect and use cryptographic keys. It defines four increasing levels of assurance, from Level 1 to Level 4.

Level 3 adds physical tamper-resistance and tamper-response: if the device is physically attacked, it is designed to detect the intrusion and zeroize (erase) the keys it holds. It also requires identity-based authentication and a strong separation between the interfaces that input/output keys and those that don’t.

Importantly, FIPS 140-2 validates the cryptographic module itself. An application does not become "FIPS certified" — it uses a validated module. BeeSign uses one to protect its signing keys.

How BeeSign uses a FIPS 140-2 Level 3 module

Keys generated in the HSM

The document-signing key is created inside Google Cloud HSM, whose HSMs are validated to FIPS 140-2 Level 3. The private key never exists in plaintext outside the module.

Non-exportable by design

The key cannot be exported from the HSM. Even certificate and CSR creation are performed by having the HSM sign, so the private key stays inside the hardware throughout its life.

Signing happens inside the boundary

To seal a document, BeeSign sends only the digest to the HSM; the HSM returns the signature. The application never handles the private key material.

Foundation for AATL trust

Strong key protection underpins the AATL-trusted seal — the certificate authority can attest that the signing key is held in a hardware module meeting the required assurance.

How the signing key is protected

  • FIPS 140-2 Level 3 validated HSM (Google Cloud HSM)
  • Key generated inside the hardware boundary
  • Non-exportable private key
  • Physical tamper-resistance and tamper-response
  • Signing performed inside the HSM
  • Only digests leave the application — never the key

Frequently asked questions

Is BeeSign "FIPS 140-2 certified"?

FIPS 140-2 validates a cryptographic module, not an application, so no software product is itself "FIPS certified." BeeSign’s signing keys are protected by Google Cloud HSM, which is validated to FIPS 140-2 Level 3 — that is the accurate statement.

Can the signing key be stolen or exported?

No. The key is generated inside the HSM and is non-exportable. It never exists in plaintext outside the hardware, and the module is designed to erase its keys if it detects a physical attack.

What does Level 3 add over lower levels?

Level 3 adds physical tamper-resistance and tamper-response (detecting intrusion and zeroizing keys), identity-based authentication, and stricter separation of the module’s key-handling interfaces — a meaningfully higher bar than Level 1 or 2.

How does this relate to the Adobe-trusted seal?

The hardware-protected key is what signs each finalized document. Because the key lives in a validated HSM, the SSL.com certificate on the Adobe Approved Trust List can be issued against it — combining strong key protection with automatic trust in Adobe.

Compliant from your first document

Every BeeSign plan includes legally binding signatures, tamper-evident audit trails, and a certificate of completion. Start your free trial today.