Thales Trusted Cyber Technologies
Hardware-backed encryption that protects keys, and data that protects itself.
Protecting classified data demands more than encryption—it demands certainty about where your keys live. Even with robust attribute-based access control and policy enforcement, encrypted data is only as secure as the cryptographic keys protecting it. Software-based key storage leaves those keys vulnerable. For agencies handling classified information, hardware-backed key protection isn’t optional—it’s mandated by FedRAMP, FISMA, and NIST standards. The challenge extends further: agencies must also enable cross-domain collaboration while meeting intelligence community requirements for metadata handling and classification markings.
Virtru Data Security Platform with Thales Trusted Cyber Technologies (TCT) Luna T-Series HSMs delivers end-to-end data protection with hardware-backed key security. The integration ensures cryptographic keys are generated and protected within FIPS 140 Level 3 validated hardware—eliminating software key exposure while enabling secure collaboration across classification boundaries and coalition partners.
Key Capabilities
- Hardware-based secure key storage
- Flexible key protection modes to balance operational requirements with maximum security assurance. FIPS-validated cryptographic operations
- ACP 240 ZTDF compliance with hardware key security
- Cross-domain collaboration through attribute-based access control with hardware-backed keys to enable secure data sharing
- Meet FedRAMP, FISMA, NIST 800-53, and Intelligence Community Directive requirements
- Trusted U.S. supply chain
- High availability architecture
- Flexible deployment models with support for cloud, on-premises, and hybrid environments
Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S.-based source for cybersecurity solutions for the U.S. Federal Government. Thales TCT’s solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled. For more information, visit thalestct.com.
Better Together: Thales Luna HSMs + Virtru Data Security Platform
Luna HSMs solve the hardest part of encryption: ensuring keys never leave a certified hardware boundary. The Virtru Data Security Platform extends Luna HSMs' hardware security boundary into a persistent, object-level enforcement model. The private keys are protected inside a Luna HSM — in either envelope or delegated mode — the Virtru platform uses those hardware-backed keys to encrypt every data object using TDF, the Trusted Data Format. TDF wraps attribute-based access policy directly inside each encrypted file, so the object carries its own access controls wherever it travels. Every decryption request is evaluated in real time against the embedded policy and the requester's current entitlements, whether that request comes from inside the organization, from a cloud service, from a partner network, or from an AI agent. The HSM provides hardware-grade certainty about the keys; the platform provides persistent, policy-driven certainty about the data. The result is first-mile to last-mile protection — hardware-anchored at the key, policy-enforced at every subsequent access.
Two integration points make this unique to the Luna partnership. First, the Virtru Key Access Service integrates directly with Luna HSMs in either envelope or delegated mode, meaning the entire Virtru cryptographic chain runs through the same hardware boundary that regulated industries already rely on for key custody compliance. Second, TDF-protected objects inherit their access policy from the same attribute-based policy plane that governs Luna key operations — so the policy that decides who can unwrap a key is the same policy that decides who can open a file, across every cloud, application, and partner network the data touches.
- Agency-Controlled Key Custody for Every Object grounds each TDF-protected object in U.S.-built silicon by generating and storing the Key Access Service private keys inside the FIPS 140-3 Level 3 validated Luna T-Series HSM over PKCS#11, rather than in a software keystore or an external service.
- Delegated-Mode Key Isolation keeps Key Access Service private keys permanently inside the Luna T-Series HSM, executing all wrap and unwrap operations within the hardware boundary so key material is never exposed outside the agency's accreditation boundary.
- Envelope-Mode Operational Flexibility uses the Luna T-Series HSM to wrap Key Access Service private keys before they are stored in the self-managed platform database, delivering hardware-backed protection while preserving performance for high-volume mission workloads.
- Quantum-Ready Chain of Custody roots the platform's data protection in an HSM that already supports ML-DSA, ML-KEM, and LMS/HSS, so agencies can migrate toward CNSA 2.0 without re-architecting how their data is encrypted and governed.
- Cross-Domain Persistent Control pairs hardware-protected keys with TDF objects that carry their own ABAC policy, so classified data stays governed — and access can be re-evaluated and revoked in seconds — after it crosses a classification boundary or reaches a coalition partner.
- Standards-Based Coalition Sharing enforces ACP-240 ZTDF-aligned policy against a single central decision point, letting agencies share protected data with mission partners while retaining cryptographic control and complete auditability.
- Sovereign, Air-Gap-Ready Deployment runs the entire integration — Key Access Service and Luna T-Series HSM — inside the agency's own on-premises, government-cloud, or air-gapped boundary, with no dependency on an external or vendor-hosted service.
Deploying the self-managed Virtru Data Security Platform with the Thales TCT Luna T-Series Network HSM to root persistent, object-level protection in U.S.-built hardware requires active deployments of both platforms within the agency's accreditation boundary and an identity provider to source the attributes that govern access decisions.
- Thales TCT Luna T-Series Network HSM — model T-2000 (standard) or T-5000 (enterprise) deployed within the agency's boundary; load-balanced, high-availability configurations supported
- Virtru Data Security Platform (self-managed deployment) — Key Access Service hosted inside the agency's own accreditation boundary (on-premises, government cloud, or air-gapped) and configured for HSM-backed key protection; the Thales TCT Luna integration requires the self-managed deployment (not the Virtru-hosted SaaS offering)
- PKCS#11 connectivity — between the platform's Key Access Service and the Luna T-Series Network HSM
- Deployment mode selection — envelope mode (HSM-wrapped keys in the database) or delegated mode (keys never leave the HSM), matched to the agency's mission and compliance posture
- Authoritative Identity Provider — any OIDC/OAuth2-compatible identity system to source the attributes evaluated in ABAC policy
- Network connectivity — between the Virtru Data Security Platform and the Luna T-Series HSM within the agency's deployment boundary
Security Architecture
The joint solution establishes a clear separation between key custody and policy enforcement, entirely within the agency's own boundary. The Thales TCT Luna T-Series Network HSM serves as the U.S.-built hardware root of trust, generating and protecting the Key Access Service private keys within a tamper-resistant, FIPS 140-3 Level 3 validated boundary. The self-managed Virtru Data Security Platform — with its Key Access Service running inside the agency's accreditation boundary — binds attribute-based access policy to each data object and evaluates every request against one central decision point. The two integrate over PKCS#11 in either of two modes: in delegated mode, private keys never leave the HSM and all cryptographic operations execute inside it; in envelope mode, the HSM wraps the private keys before they are stored in the platform database. In both modes, key material is isolated from software keystores and never leaves the agency's control.
Compliance & Standards
The Luna T-Series Network HSM is validated to FIPS 140-3 Level 3 (and FIPS 140-2 Level 3) and is approved by the CNSS for use in National Security Systems PKI, with full support for CNSA Suites 1.0 and 2.0 and NIST-standardized PQC algorithms. The Virtru Data Security Platform is built on the OpenTDF open standard, is FedRAMP Moderate authorized, holds SOC 2 Type II, is validated against FIPS-grade key management requirements, and supports ACP-240 (the Five Eyes-ratified Zero Trust standard for coalition operations) along with IC-TDF and NATO STANAG 5636. Together the solution supports agencies in meeting FedRAMP, FISMA, NIST 800-53, and Intelligence Community Directive requirements. HSM-generated cryptographic logs and the platform's decision-level audit trails provide the evidence oversight and assessors ask for, built in rather than bolted on.
Privacy & Data Sovereignty
Cryptographic control never leaves the agency. Keys are generated, stored, and used exclusively within the agency-controlled, U.S.-built Luna T-Series HSM, and the Key Access Service runs inside the agency's own accreditation boundary — on-premises, in a government cloud, or air-gapped. Because policy is authored once and enforced against a single source of truth, agencies retain equal agency over shared data across every domain and mission partner, with protection that holds even in disconnected and forward-deployed environments.
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.