> There's no reason why they cannot relatively securely store a private key and the associated certificates.

The big ones have supported this for two decades: https://www.digicert.com/managing-client-certificates.htm

Hardly anywhere uses it.