This white paper describes the unique Thales CodeSafe capability, which enables application code to run within the protected confines of a tamper-resistant nShield Hardware Security Module (HSM).  CodeSafe enables users to develop application code to run inside the HSM, providing protection against Advanced Persistent Threats  (APTs) as well as insider attacks and hacking.  The paper describes the associated toolkit, bundled utilities, and management, and additionally details multiple usage examples where CodeSafe provides high value.