
Keep signing keys inside your own infrastructure while Ledger manages governance, orchestration and blockchain connectivity. Designed for financial institutions with strict data residency and sovereignty requirements.
Before you dive in:
For institutions operating under strict data residency or sovereignty requirements, many custody architectures still require compromises in where signing infrastructure is deployed or how it is operated. Cloud, co-location, third-party HSM’s - the architecture works, but the key material still isn’t on site or even in country.
For a global bank under a national data-residency mandate, that is not a footnote, it's a blocker. For a central bank piloting a CBDC reserve program, or a stablecoin issuer navigating new and evolving regulatory regimes, the answer to "where do your keys live?" has to have one answer: locally.
Until now, institutions that needed that answer could not also have high-performance custody infrastructure. They built proprietary signing stacks, accepted operational risk, or stayed on the sidelines.
Ledger Enterprise HSM On-Premise separates the problem in two.
Many custody platforms couple signing, governance, and orchestration into a single cloud environment - one where the vendor can, in principle, access any of it. Ledger Enterprise HSM On-Premise decouples them and anchors each in hardware.
The signer layer - the physical HSM, the Master Seed, the cryptographic operations - runs inside your data center. You or your chosen System Integrator manages the hardware and network configuration. Keys are generated locally. Control stays with the institution.
The governance layer runs inside HSMs operated by Ledger - but Ledger has no access to it. Governance rules, approval workflows, and transaction policies are enforced by hardware and controlled exclusively by your PSDs (Personal Security Devices). Ledger operates the surrounding platform: API connectivity, blockchain synchronization, orchestration. Ledger operates the platform. You retain control over signing and governance. This is the architectural difference. Competitors host governance in software, in their cloud - which means in principle, operators can access it.
.png)
We consistently hear the same requirement from banks and regulated custodians: "We cannot put our keys in someone else's cloud."
That is the constraint we hear from financial institutions entering digital asset custody under regulated frameworks.
These requirements are becoming increasingly common as banks, custodians, and sovereign institutions move from pilots into product deployments. Financial institutions share the same requirement: signing infrastructure that remains under their control without sacrificing the operational capabilities of a managed custody platform.
Every transaction in the HSM On-Premise model moves through three hardware-anchored layers.
It begins on a Personal Security Device. An operator, or an authorised API workflow, initiates the transaction and verifies exactly what will be signed. The approval is authenticated on hardware before any request travels further.
From there, the transaction reaches the governance layer, where policy - spending limits, whitelists, approval quorums time-locks - is enforced inside HSMs. Governance is not code running in a cloud environment. It is hardware, controlled exclusively by your Personal Security Devices. Ledger operates the surrounding service, but has no access to the rules themselves. That distinction is where the model departs from cloud-hosted custody, and it is deliberate.
Only after governance is satisfied does the transaction move to the signing HSMs inside your data center. Private keys never leave that environment. Every signature is generated locally, under hardware-enforced policy.
The pattern here matters. Hardware verification runs at initiation, not only at signing — a defence against operational error and multi-stage attack chains, whether a human operator or an automated flow initiates the transaction. And because policy enforcement sits at the hardware boundary rather than at every keystroke, approval flows can be fully automated at scale. Institutions do not have to choose between operational efficiency and the security guarantees hardware provides.
You keep full control. Ledger handles everything operational.
Client integrations for HSM On-Premise begin this month. We are working with global banks, regulated custodians, sovereign entities, and stablecoin issuers to scope their specific deployment requirements, including data-residency mandates, existing HSM infrastructure, jurisdictional constraints, and integration timelines.
If you are navigating strict data-residency requirements or looking to connect existing HSM hardware to the Ledger Enterprise ecosystem, our security team can walk through what an integration looks like for your environment.
Contact us today to get started with Ledger Enterprise