Security Stack Logo
Primus HSM logo

Hardware Security

Primus HSM

FIPS 140-2 Level 3 and CC EAL4+ HSMs with multi-tenant partitioning and post-quantum crypto support.

Hardware Security Modules (HSM)

Primus HSM Overview

What it does

Primus HSM is a line of Hardware Security Modules (HSMs) from Securosys that generate, store, and use cryptographic keys inside tamper-resistant hardware, keeping private keys isolated from the applications that call them. What distinguishes the line is its partition model: a single CyberVault unit hosts up to 1,000 independent, isolated partitions, letting one appliance serve many tenants or applications, alongside firmware crypto-agility that adds NIST post-quantum algorithms without replacing hardware.

How it works

The hardware performs key generation, encryption, signing, and TLS session operations internally, exposing them through PKCS#11, Microsoft CNG, Java (JCE), and REST interfaces so applications never handle raw key material. Models span the entry-level E-Series for PKI key management through X-Series and CyberVault units rated above 50,000 transactions per second, with clustering for geo-redundant high availability. Post-quantum support covers ML-KEM, ML-DSA, SLH-DSA, HSS-LMS, and XMSS, and a hybrid mode pairs classical RSA or ECC keys with post-quantum signatures and key exchange for a phased migration.

Credentials and traction

Primus HSM is validated to FIPS 140-2 Level 3 (CMVP certificates 4583 and 3430) and certified Common Criteria EAL4+ (augmented AVA_VAN.5) against the eIDAS protection profile EN 419221-5, with EN 419241-2 qualified server-signing support on firmware 3.1.0; FIPS 140-3 Level 3 validation is in progress and the CloudHSM service carries ISO/IEC 27001. The HSMs secure the Swiss Interbank Clearing (SIC) payment system under a contract renewed for ten years in 2024. Customers span financial institutions, trust service providers, and blockchain custodians.

Key Capabilities

mapped to solution categories
Hardware Security Modules (HSM)

Hardware validated to FIPS 140-3 Level 3 with identity-based authentication, tamper-resistant housing, environmental failure protection, and zeroization on intrusion.

Custodies keys in provider-managed cloud HSM, customer on-premises hardware, or hybrid deployments, determining physical custody and module boundary for sovereignty compliance.

Manages cryptographic key generation, rotation, escrow, and destruction with tamper-evident audit logging, supporting key custodian workflows and compliance evidence.

Stores CA signing keys in HSM-protected hardware, ensuring that certificate issuance operations require physical or logical HSM access and that private keys cannot be extracted.

Supports NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) in hardware, with firmware crypto-agility to add new algorithms, so keys and signing operations remain protected against future quantum attacks.

Moves TLS private key operations and session key generation from application servers to the HSM, isolating private key material from application processes and improving throughput.

Compliance

certifications
Common Criteria EAL4+eIDASFIPS 140-2FIPS 140-3ISO 27001

Integrations

compatible tools
AkeylessAWSCloudflareCyberArkDelinea Secret ServerEJBCAF5 BIG-IPFireblocksFortinet FortiGateHashiCorp VaultKeyfactorMariaDBMicrosoft Active Directory Certificate ServicesMicrosoft AzureMicrosoft SQL ServerOpenBaoOracle DatabaseSalesforceServiceNowVenafi

Implementation & support

Deployment model
CloudHybridNetwork ApplianceOn-Premises
Pricing structure
Custom / Enterprise
Support channels
DocumentationEmail SupportPhone SupportTicketing PortalTraining / Academy

Info last updated on June 27, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.