Thales Cloud Protection & Licensing
Hardware-backed encryption that protects keys, and data that protects itself.
Thales Luna HSMs deliver tamper-resistant, FIPS 140-3 Level 3 validated hardware security modules that protect cryptographic keys at the foundation of enterprise security. For organizations that rely on encryption to meet PCI-DSS, GDPR, HIPAA, FISMA, and FedRAMP requirements, Luna HSMs ensure that master keys are generated, stored, and operated exclusively within a certified hardware boundary — eliminating the software-based exposure risks that cloud keystores and general-purpose servers cannot close. Deployable on-premises, in the cloud, as a service through Thales Data Protection on Demand, or in hybrid configurations, Luna HSMs have served as the cryptographic anchor for the world's largest financial institutions, healthcare organizations, telecommunications providers, and government agencies for over thirty years.
Thales Luna HSMs protect cryptographic keys inside FIPS 140-3 Level 3 validated hardware, ensuring master keys are never accessible to a cloud provider or exposed on a general-purpose server. Two key protection modes — envelope and delegated — let organizations match hardware custody requirements to their compliance posture without sacrificing operational agility. Luna HSMs deploy consistently across AWS, Azure, Google Cloud, and on-premises environments through Thales Data Protection on Demand, eliminating cloud vendor lock-in while maintaining a single, hardware-anchored key management layer. Multiple HSMs can be deployed in high-availability, load-balanced configurations to ensure uninterrupted cryptographic service at enterprise scale. Backed by thirty years of market leadership, Thales Luna HSMs are the hardware security foundation trusted by the world's most regulated industries.
Better Together: Thales Luna Network HSMs + Virtru Data Security Platform
The Virtru Data Security Platform extends the Luna HSM solution so protection travels with the data itself — persisting as information moves across email, file sharing, cloud storage, and analytics pipelines, with a single central policy governing every access decision throughout the data's lifecycle. Cryptographic keys remain secured within tamper-resistant hardware, while governance travels with the object by encapsulating it in the Trusted Data Format (TDF) and applying embedded attribute-based access control (ABAC) policies. The combined solution offers both HSM deployment modes, so organizations can match key custody to their compliance posture without sacrificing operational flexibility.
Hardware Custody Extended to the Data Itself: Virtru extends Thales Luna's hardware key security by adding a persistent, object-level enforcement layer, allowing organizations to keep their existing key management and cloud workflows while the protection travels with the data. The Luna 7 Network HSM generates and stores the Key Access Service private keys that protect every encrypted object. Those keys are then evaluated against one central policy at every access attempt, so the same tamper-resistant hardware that proves custody of the key also proves custody of the data — wherever it travels. PCI key-custody evidence and GDPR technical safeguards stop being two separate audits and become a single chain of custody.
- Persistent Control Beyond the Key Boundary pairs hardware-protected keys with TDF objects that carry their own ABAC policy, so access can be re-evaluated and revoked in seconds— extending Luna's at-rest custody to data in motion and in use.
- Hardware-Rooted Key Custody for Every Object grounds each TDF-protected object in tamper-resistant silicon by generating and storing the Key Access Service private keys inside the FIPS 140-3 Level 3 validated Luna 7 Network HSM over PKCS#11, rather than in a software keystore.
- Consistent Governance Across Every Deployment evaluates every request against a single central policy keeping key custody and access control aligned across hybrid and multi-cloud estates.
- Customer-Held Decryption Authority keeps decryption keys inside customer-controlled Luna hardware and never hands them to a cloud service provider, so the data owner retains cryptographic control.
- Delegated-Mode Key Isolation keeps Key Access Service private keys permanently inside the Luna HSM, executing all wrap and unwrap operations within the hardware boundary so key material is never exposed to general-purpose servers or cloud providers.
- Envelope-Mode Operational Flexibility uses the Luna HSM to wrap Key Access Service private keys before they are stored in the platform database, delivering hardware-backed protection while preserving performance and scale for high-volume workloads.
- Unified Chain of Custody for Audits combines HSM-generated cryptographic logs with the platform's decision-level access logs into one evidence trail, so PCI DSS Requirement 3.5 key custody and GDPR Article 32 safeguards are documented together instead of as two disconnected audits.
Deploying the Virtru Data Security Platform with Thales Luna Network HSMs requires active deployments of both platforms and an identity provider to source the attributes that govern access decisions.
- Thales Luna Network HSM (Luna 7) — deployed on-premises, as a cloud-hosted HSM, or as a service through Thales Data Protection on Demand; load-balanced, high-availability configurations supported
- Virtru Data Security Platform — Key Access Service hosted in the customer's own customer VPC or on-premises environment and configured for HSM-backed key protection)
- PKCS#11 connectivity — between the platform's Key Access Service and the Luna Network HSM
- Deployment mode selection — envelope mode (HSM-wrapped keys in the database) or delegated mode (keys never leave the HSM), matched to the organization's compliance posture
- Authoritative Identity Provider — any OIDC/OAuth2-compatible identity system to source the attributes evaluated in ABAC policy
- Network connectivity — between the Virtru Data Security Platform and Luna HSM services within the deployment boundary
Security & Compliance
Security Architecture
The joint solution establishes a clear separation between key custody and policy enforcement. The Thales Luna Network HSM serves as the hardware root of trust, generating and protecting the Key Access Service private keys within a tamper-resistant, FIPS 140-3 Level 3 validated boundary. The Virtru Data Security Platform — with its Key Access Service running in the customer's own VPC or on-premises environment — binds attribute-based access policy to each data object and evaluates every request against one central decision point. The two integrate over PKCS#11 in either of two modes: in delegated mode, private keys never leave the HSM and all cryptographic operations execute inside it; in envelope mode, the HSM wraps the private keys before they are stored in the platform database. In both modes, key material is isolated from software keystores and from cloud service providers.
Compliance & Standards
The Luna 7 Network HSM is validated to FIPS 140-3 Level 3 and certified under eIDAS as a Qualified Signature and Qualified Seal Creation Device (QSCD). The Virtru Data Security Platform is built on the OpenTDF open standard, is FedRAMP Moderate authorized, holds SOC 2 Type II, and is validated against FIPS-grade key management requirements. Together the solution supports compliance with GDPR Article 32 technical safeguards, PCI DSS Requirement 3.5 key-custody evidence, and HIPAA — Virtru offers a standard Business Associate Agreement. HSM-generated cryptographic logs and the platform's decision-level audit trails provide the evidence SOC 2, HIPAA, and PCI DSS assessors ask for, built in rather than bolted on.
Privacy & Data Sovereignty
Decryption authority stays in the data owner's hands. Master keys are generated, stored, and used exclusively within customer-controlled Luna hardware and are never handed to a cloud service provider, so enterprises retain cryptographic control whether workloads run on AWS, Microsoft Azure, Google Cloud, or on-premises. Because policy is authored once and enforced against a single source of truth, control over shared data stays with the customer wherever the data resides.
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.