HSMs

A hardware security module keeps a key inside a tamper-resistant box so that it cannot be copied out.

Applications ask the box to perform operations rather than receiving the key. That stops theft of the key itself and does nothing about an application that has been compromised and is simply asking the box to sign whatever the attacker wants. It protects the key, not the authority to use it.

Checked against the primary source.

More on Cryptography