Security Stack Logo
Primus HSM logo

Hardware Security

Primus HSM

FIPS 140-2 Level 3 and Common Criteria EAL4+ hardware security modules with multi-tenant partitioning and NIST post-quantum cryptography support.

Hardware Security Modules (HSM)

Primus HSM Overview

Primus HSM is a line of Hardware Security Modules (HSMs) from Securosys that generate, store, and use cryptographic keys inside tamper-resistant hardware, keeping private keys isolated from the applications that call them. What distinguishes the line is its partition model: a single CyberVault unit hosts up to 1,000 independent, isolated partitions, letting one appliance serve many tenants or applications, alongside firmware crypto-agility that adds NIST post-quantum algorithms without replacing hardware.

The hardware performs key generation, encryption, signing, and TLS session operations internally, exposing them through PKCS#11, Microsoft CNG, Java (JCE), and REST interfaces so applications never handle raw key material. Models span the entry-level E-Series for PKI key management through X-Series and CyberVault units rated above 50,000 transactions per second, with clustering for geo-redundant high availability. Post-quantum support covers ML-KEM, ML-DSA, SLH-DSA, HSS-LMS, and XMSS, and a hybrid mode pairs classical RSA or ECC keys with post-quantum signatures and key exchange for a phased migration.

Primus HSM is validated to FIPS 140-2 Level 3 (CMVP certificates 4583 and 3430) and certified Common Criteria EAL4+ against the eIDAS protection profile EN 419221-5, with EN 419241-2 qualified server-signing support on firmware 3.1.0. Securosys produces and maintains the HSMs behind the Swiss Interbank Clearing (SIC) payment system under a contract renewed in 2024, and serves financial institutions, trust service providers, and blockchain custodians from offices in Switzerland, Germany, Hong Kong, and the United States.

Key Capabilities

mapped to solution categories
Hardware Security Modules (HSM)

Hardware validated to FIPS 140-3 Level 3 with identity-based authentication, tamper-resistant housing, environmental failure protection, and zeroization on intrusion.

Custodies keys in provider-managed cloud HSM, customer on-premises hardware, or hybrid deployments, determining physical custody and module boundary for sovereignty compliance.

Manages cryptographic key generation, rotation, escrow, and destruction with tamper-evident audit logging, supporting key custodian workflows and compliance evidence.

Stores CA signing keys in HSM-protected hardware, ensuring that certificate issuance operations require physical or logical HSM access and that private keys cannot be extracted.

Supports NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) in hardware, with firmware crypto-agility to add new algorithms, so keys and signing operations remain protected against future quantum attacks.

Moves TLS private key operations and session key generation from application servers to the HSM, isolating private key material from application processes and improving throughput.

Compliance

certifications
Common Criteria EAL4+eIDASFIPS 140-2FIPS 140-3ISO 27001

Integrations

compatible tools
AkeylessAWSCloudflareCyberArkDelinea Secret ServerEJBCAF5 BIG-IPFireblocksFortinet FortiGateHashiCorp VaultKeyfactorMariaDBMicrosoft Active Directory Certificate ServicesMicrosoft AzureMicrosoft SQL ServerOpenBaoOracle DatabaseSalesforceServiceNowVenafi

Implementation & support

Deployment model
CloudHybridNetwork ApplianceOn-Premises
Pricing structure
Custom / Enterprise
Support channels
DocumentationEmail SupportPhone SupportTicketing PortalTraining / Academy

Info last updated on June 27, 2026