A stronger custody model for business-critical information
Owner-led businesses often need to assess how sensitive files and communications are handled without taking on enterprise key-management infrastructure. PrimiDS is in early access: a physical ToughKey HSM key designed to pair with software for encrypted storage and secure communications. Recovery, permissions, and audit run as live systems.
Encrypted cloud storage is a category; the right choice depends on the questions you answer.
Encrypted cloud storage is storage where information is protected with encryption while it is stored or transmitted through a provider’s service. For a small business, the practical evaluation is not only “is it encrypted?” but:
- Who controls keys
- How users obtain access
- How recovery works
- What data and systems are in scope
- What assurance evidence supports the claims
Compare approaches by custody, recovery, sharing needs, administration, integrations, data location, cost, and evidence—not by a generic “secure” label. PrimiDS is intended for owner-led businesses evaluating hardware-backed key custody alongside encrypted storage and secure communications; it is not positioned as a compliance programme or a finished replacement for every current tool. An owner can use the checklist to identify questions that must be answered before a change is considered.
Store information and share information are related—but they are not the same workflow.
Encrypted storage concerns how a business keeps information in a service and how its protection and custody model are evaluated. Secure file sharing concerns how a business sends or gives access to information to another person or organisation. A business may need to evaluate both, alongside access, recovery, and administration needs.
PrimiDS is designed around encrypted storage and secure communications. Permissions and audit are live parts of the system. Sharing model, recipient access, supported systems, and communications workflow are not yet published. Do not infer those mechanics from the category description. Use a pilot conversation to identify what a client-sharing workflow would need to prove before it is relied upon. Until then, the category distinction should not be read as confirmation of a PrimiDS sharing or recipient process. A responsible review keeps the business’s own access and handover requirements separate from an unconfirmed product workflow.
Start with the required safeguards, then confirm whether a product supports them.
A business that shares sensitive files with clients should define:
- Who needs access
- How recipients are identified
- What information is appropriate to share
- How access changes or ends
- What recovery or recordkeeping requirements apply
Those are evaluation criteria, not a description of a confirmed PrimiDS workflow.
PrimiDS may be relevant when an owner wants to explore a combined hardware-and-software custody model without assuming that enterprise HSM infrastructure is the right fit. Permissions and audit are live. The product build, sharing model, administration, integrations, onboarding, support, and communications scope are refined as early access opens. The relevant question is whether the model can meet the business’s actual requirements, not whether a broad category label sounds suitable.
Confirm the operating details before you decide.
For security, recovery, and certification boundaries, use Security & Trust. For small-business pricing, use Pricing. The pilot conversation should assess fit and open requirements, not assume a demonstration, deployment date, or supported integration. It should surface unanswered operating details that would prevent a responsible evaluation, including decision points that would make a pilot unsuitable, incomplete, or premature.
| Designed framing | Questions to confirm in a pilot |
|---|---|
| PrimiDS is in early access, pairing a physical ToughKey key with software for encrypted storage and secure communications. | Which systems, devices, files, communications, integrations, and business workflows are in scope? |
| The root cryptographic secret is designed to be held in physical hardware rather than as a cloud-recoverable credential. | How are sharing, staff changes, replacement commercial terms, and support handled? Recovery, permissions, and audit are live; confirm operating fit in a pilot. |
| Primi is not currently FIPS 140-2/140-3 or Common Criteria certified. | What assurance evidence, pilot terms, pricing, billing, tax, availability, and follow-up process apply? |
Choose an approach by custody, recovery, and operating fit.
Software-only tools, built-in encryption, and enterprise key infrastructure can each be appropriate in different environments. PrimiDS is being developed as another category to evaluate: a physical root-key model paired with encrypted storage and secure communications.
Use compare encrypted-storage approaches to review key custody, recovery, sharing, administration, assurance evidence, data location, and cost questions. For broader context, see small-business data-protection guidance.
Confirm, don't presume
Use the comparison to identify what must be confirmed rather than presume that a category fits.
Relevance is not fit
A category can be relevant without being the right operating model for a particular team.
Trade-offs made explicit
A neutral comparison makes trade-offs explicit before an owner changes an existing practice.
Assess the questions before you plan a rollout.
PrimiDS is in early access. Request a pilot conversation to discuss the custody model, your requirements, and the questions that must be answered before any pilot or implementation decision. This is not a promise of a demo, deployment date, user capacity, or supported integration. It is a structured conversation about fit. Bring the files, communications, access, recovery, and assurance questions that matter to your business so the discussion can identify open requirements.
Continue your evaluation
Explore how hardware-backed key custody works, security and assurance details, small-business pricing, compare encrypted-storage approaches, broader small-business security guidance, and the FAQ. These are evaluation links, not alternative conversion actions or a statement of present availability. They help an owner compare assurance boundaries, terms, and category alternatives without confirming a product workflow or availability.


