We shipped an application recently where groups of users use hardware keys to unlock sensitive information.
We were able to use FortifyApp (from PeculiarVentures) in conjunction with "regular" Yubikeys acting in PIV (smart card) mode. We seriously considered the YubiHSM instead with different shim software but it was really quite expensive when you need 1 per operator.
The other thing which would be a "must" for commercial uses (I think, anyway) would be supporting standard PKCS11 APIs. The API is... not that great, but it's the only thing that saves you from rewrites every hardware generation.
Would that be on the roadmap? If not, what's the interface between host(s) & hsm?