Skip to main content

Service Packages

Securosys CloudHSM offers a variety of services tailored to different needs, ensuring flexibility and scalability for your organization. Choose from dedicated or shared HSM options, tailored to your requirements, including flexible solutions for production, testing, and hosted environments.

HSM as a Service (HSMaaS)

Shared HSMs

Your own partition on a physical Hardware Security Module (HSM) in the cloud. A cluster consists of two active HSMs located in two active datacenters and a third HSM in a NATO Zone 2 Electromagnetic Pulse-protected bunker in the Alps, which serves as a backup and disaster recovery facility.

Dedicated HSMs

  • CloudHSM Platinum exclusively owned and operated by Securosys, ensuring your keys and data remain isolated.

Customer-owner HSMs

What is a HSM partition?

A partition is defined as the amount of user space in megabytes (MB) allocated on each HSM in the cluster for storing objects and partition logs.

Service Package Comparison

Economy
(ECO)
Economy Certified
(ECO CC)
Sandbox
(SBX)
PlatinumHSM Operation Service (HOS)Bring Your Own Key
(BYOK)
Subscription Type
Multi-tenant HSM subscription
Multi-tenant HSM subscription
Multi-tenant HSM subscription
Dedicated HSM subscription
Dedicated HSM purchased (customer owned)
Multi-tenant HSM subscription
Platform
2x1 +1
3 HSM in 3 data centers
2x1 +1
3 HSM in 3 data centers
2x1
2 HSM in 2 data centers
(Testing)
Dedicated HSMs hosted in data centers
Dedicated HSMs hosted in data centers
2x1 +1
3 HSM in 3 data centers
Performance (Sig./Min)
Up to 600
Up to 600
Best available
Up to 12`000
Up to 120`000
-
Capacity
10 MB
10 MB
10 MB
120 MB
30 GB
3/10/200
key objects
Support
Availability
Response time
(critical/major/minor)
24 x 7 x 365
2/8/24h
24 x 7 x 365
2/8/24h
24 x 7 x 365
8/12/24h
24 x 7 x 365
2/8/24h
24 x 7 x 365
2/8/24h
24 x 7 x 365
2/8/24h
Platform

High Availability (HA) cluster with synchronized data available in active/active mode and in case of ECO, ECO CC or BYOK, a 3rd HSM that is located in a Business Continutity Data Center.

Performance

A consistent performance on ECO and ECO CC packages is garanteed, measured as the average number of RSA4096/ECC512 signatures processed per minute over a 24-hour window. No hard rate limit is imposed. Performance fluctuations may be observed in short intervals.

API Integration Options

CloudHSM offers a REST API and a selection of Primus API Providers (client API software / libraries), installed on your application server. These ensure secure communication with the HSM, along with automatic failover and load balancing.

Learn more about REST-API

Configuration Options

All CloudHSM service packages can be individually configured with regards to the required API integration and optional packages for Cryptocurrencies, Smart Key Attributes (SKA), Post-Quantum Cryptographic (PQC) Algorithms and Transaction Security Broker (TSB).

Furthermore, in the Partition Security Policy, you can configure policy settings for Key Import, Key Export and Key Invalidation. Additionally, access to the CloudHSM partition can be restricted to a list of whitelisted source IP addresses.

Partition Remote Administration

By default, Securosys provides support to perform any changes you request on your HSM.

However, with our Decanus Terminal’s Partition Administration you also have the option to fully control access to your HSM partition. This includes making configuration changes, downloading backups, and even disabling HSM administrators' access to your partition. This way, you benefit from the security advantages of your own HSM without the usual headaches and costs.

More content