<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Thales Cloud Protection & Licensing

Hardware-backed encryption that protects keys, and data that protects itself.

 

Thales Luna HSMs deliver tamper-resistant, FIPS 140-3 Level 3 validated hardware security modules that protect cryptographic keys at the foundation of enterprise security. For organizations that rely on encryption to meet PCI-DSS, GDPR, HIPAA, FISMA, and FedRAMP requirements, Luna HSMs ensure that master keys are generated, stored, and operated exclusively within a certified hardware boundary — eliminating the software-based exposure risks that cloud keystores and general-purpose servers cannot close. Deployable on-premises, in the cloud, as a service through Thales Data Protection on Demand, or in hybrid configurations, Luna HSMs have served as the cryptographic anchor for the world's largest financial institutions, healthcare organizations, telecommunications providers, and government agencies for over thirty years.

Thales Luna HSMs protect cryptographic keys inside FIPS 140-3 Level 3 validated hardware, ensuring master keys are never accessible to a cloud provider or exposed on a general-purpose server. Two key protection modes — envelope and delegated — let organizations match hardware custody requirements to their compliance posture without sacrificing operational agility. Luna HSMs deploy consistently across AWS, Azure, Google Cloud, and on-premises environments through Thales Data Protection on Demand, eliminating cloud vendor lock-in while maintaining a single, hardware-anchored key management layer. Multiple HSMs can be deployed in high-availability, load-balanced configurations to ensure uninterrupted cryptographic service at enterprise scale. Backed by thirty years of market leadership, Thales Luna HSMs are the hardware security foundation trusted by the world's most regulated industries.


Better Together: Thales Luna Network HSMs + Virtru Data Security Platform

The Virtru Data Security Platform extends the Luna HSM solution so protection travels with the data itself — persisting as information moves across email, file sharing, cloud storage, and analytics pipelines, with a single central policy governing every access decision throughout the data's lifecycle. Cryptographic keys remain secured within tamper-resistant hardware, while governance travels with the object by encapsulating it in the Trusted Data Format (TDF) and applying embedded attribute-based access control (ABAC) policies. The combined solution offers both HSM deployment modes, so organizations can match key custody to their compliance posture without sacrificing operational flexibility.

Hardware Custody Extended to the Data Itself: Virtru extends Thales Luna's hardware key security by adding a persistent, object-level enforcement layer, allowing organizations to keep their existing key management and cloud workflows while the protection travels with the data. The Luna 7 Network HSM generates and stores the Key Access Service private keys that protect every encrypted object. Those keys are then evaluated against one central policy at every access attempt, so the same tamper-resistant hardware that proves custody of the key also proves custody of the data — wherever it travels. PCI key-custody evidence and GDPR technical safeguards stop being two separate audits and become a single chain of custody.