We don't have the requirement to use an external secure store, but for that custom terminator component we were thinking to use an external secure store (Vault or something along those lines) to make sure that the the private keys and session ticket keys never hit persistent storage.