<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Thales Trusted Cyber Technologies

Hardware-backed encryption that protects keys, and data that protects itself.

Protecting classified data demands more than encryption—it demands certainty about where your keys live. Even with robust attribute-based access control and policy enforcement, encrypted data is only as secure as the cryptographic keys protecting it. Software-based key storage leaves those keys vulnerable. For agencies handling classified information, hardware-backed key protection isn’t optional—it’s mandated by FedRAMP, FISMA, and NIST standards. The challenge extends further: agencies must also enable cross-domain collaboration while meeting intelligence community requirements for metadata handling and classification markings.

Virtru Data Security Platform with Thales Trusted Cyber Technologies (TCT) Luna T-Series HSMs delivers end-to-end data protection with hardware-backed key security. The integration ensures cryptographic keys are generated and protected within FIPS 140 Level 3 validated hardware—eliminating software key exposure while enabling secure collaboration across classification boundaries and coalition partners.

Key Capabilities

  • Hardware-based secure key storage
  • Flexible key protection modes to balance operational requirements with maximum security assurance. FIPS-validated cryptographic operations
  • ACP 240 ZTDF compliance with hardware key security
  • Cross-domain collaboration through attribute-based access control with hardware-backed keys to enable secure data sharing
  • Meet FedRAMP, FISMA, NIST 800-53, and Intelligence Community Directive requirements
  • Trusted U.S. supply chain
  • High availability architecture
  • Flexible deployment models with support for cloud, on-premises, and hybrid environments

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S.-based source for cybersecurity solutions for the U.S. Federal Government. Thales TCT’s solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled. For more information, visit thalestct.com.


Better Together: Thales Luna HSMs + Virtru Data Security Platform

Luna HSMs solve the hardest part of encryption: ensuring keys never leave a certified hardware boundary. The Virtru Data Security Platform extends Luna HSMs' hardware security boundary into a persistent, object-level enforcement model. The private keys are protected inside a Luna HSM — in either envelope or delegated mode — the Virtru platform uses those hardware-backed keys to encrypt every data object using TDF, the Trusted Data Format. TDF wraps attribute-based access policy directly inside each encrypted file, so the object carries its own access controls wherever it travels. Every decryption request is evaluated in real time against the embedded policy and the requester's current entitlements, whether that request comes from inside the organization, from a cloud service, from a partner network, or from an AI agent. The HSM provides hardware-grade certainty about the keys; the platform provides persistent, policy-driven certainty about the data. The result is first-mile to last-mile protection — hardware-anchored at the key, policy-enforced at every subsequent access.

Two integration points make this unique to the Luna partnership. First, the Virtru Key Access Service integrates directly with Luna HSMs in either envelope or delegated mode, meaning the entire Virtru cryptographic chain runs through the same hardware boundary that regulated industries already rely on for key custody compliance. Second, TDF-protected objects inherit their access policy from the same attribute-based policy plane that governs Luna key operations — so the policy that decides who can unwrap a key is the same policy that decides who can open a file, across every cloud, application, and partner network the data touches.