mean that the host should have control over private key material. The key management and store of the Web Cryptography API
should be implemented in such a way that it should be possible for
secret key material to be stored in such a way that the server does
not, if the application is built correctly, control the keys of the user.