Skip to main content

CyberVault KMS Release Notes

EULA: https://www.securosys.com/eula

1.1.0 (2026-08-13)

First public available release of CyberVault KMS.

KMIP:

  • The HSM Partition configuration page now supports KMIP multi-tenancy: additional partitions (from the same HSM cluster) can be registered on the KMIP Server.
  • Added support for issuing KMIP mTLS client certificates via: generating the key pair directly in the HSM, signing an externally submitted CSR (the CSR is signed with the kms.kmip.user.ca issuing CA), and importing an existing certificate.
  • Added kmip-server property configuration on the KMIP dashboard.

TSB (on-premise deployments):

  • Deployment of TSB is now set to mTLS by default.
  • KMS creates an issuing CA key that is in the HSM (kms.tsb.user.ca). It signs the mTLS client certificates or CSR's for an on-prem TSB.

Keys & Certificates:

  • KMS raises an alert when key material leaves the HSM.
  • System keys are only visible to administrators, and deleting a system object asks for an explicit confirmation.
  • The Keys and Certificates tables can now be sorted and refreshed, and the certificate details view shows more.

Administration:

  • Reworked Settings and Secrets pages.

Component versions:

  • HSM v3.2.13 (Support for HSM User sub-roles)
  • JCE v2.6.5
  • KMIP v1.1.0
  • TSB v2.8.16
  • Key Manager UI v1.1.0

1.0.0 (2026-07-07)

Initial release of CyberVault KMS.

Highlights:

  • Unified key management for HSM-backed keys, certificates, and password-protected keys, with improved metadata handling, filtering, lifecycle actions, and audit visibility.
  • Integrated KMIP, BYOK, and MCP, including KMIP-managed objects, provider-specific BYOK import and export flows, and built-in MCP server support for MCP-aware clients.
  • Built-in security and operations features such as HSM-native sealing and unsealing, role-based access control, alerting, audit logs, compliance reporting, and stronger validation across admin and authentication flows.
  • Support for post-quantum and crypto-agility use cases, including PQC certificate workflows, readiness tracking, and self-test capabilities.
  • Simplified deployment and day-2 operations with improved installers, Kubernetes and Helm deployment presets, optional TSB integration, and safer upgrade and uninstall behavior.

Component versions:

  • HSM v3.2.11
  • JCE v2.6.3
  • KMIP v1.0.0
  • TSB v2.8.12
  • Key Manager UI v1.0.0
Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?