Nextcloud Introducing Native Integrated End-to-end Encryption

Regarding the statement "The design supports a Hardware Security Module for enterprise environments which enables securely issuing new keys to users " , I am not clear on which keys/certificates are stored in the HSM ?