Thales Luna HSMs
Hardware-backed encryption that protects keys, and data that protects itself.
Thales Luna HSMs deliver tamper-resistant, FIPS 140-3 Level 3 validated hardware security modules that protect cryptographic keys at the foundation of enterprise security. For organizations that rely on encryption to meet PCI-DSS, GDPR, HIPAA, FISMA, and FedRAMP requirements, Luna HSMs ensure that master keys are generated, stored, and operated exclusively within a certified hardware boundary — eliminating the software-based exposure risks that cloud keystores and general-purpose servers cannot close. Deployable on-premises, in the cloud, as a service through Thales Data Protection on Demand, or in hybrid configurations, Luna HSMs have served as the cryptographic anchor for the world's largest financial institutions, healthcare organizations, telecommunications providers, and government agencies for over thirty years.
Thales Luna HSMs protect cryptographic keys inside FIPS 140-3 Level 3 validated hardware, ensuring master keys are never accessible to a cloud provider or exposed on a general-purpose server. Two key protection modes — envelope and delegated — let organizations match hardware custody requirements to their compliance posture without sacrificing operational agility. Luna HSMs deploy consistently across AWS, Azure, Google Cloud, and on-premises environments through Thales Data Protection on Demand, eliminating cloud vendor lock-in while maintaining a single, hardware-anchored key management layer. Multiple HSMs can be deployed in high-availability, load-balanced configurations to ensure uninterrupted cryptographic service at enterprise scale. Backed by thirty years of market leadership, Thales Luna HSMs are the hardware security foundation trusted by the world's most regulated industries.
Better Together: Thales Luna HSMs + Virtru Data Security Platform
Luna HSMs solve the hardest part of encryption: ensuring keys never leave a certified hardware boundary. What they cannot do is follow the data after it has been decrypted and released — and that is where most breaches occur. Once a file leaves a protected storage environment, crosses an organizational boundary, or is shared with a partner, the HSM's boundary ends. The keys are safe. The data is not.
The Virtru Data Security Platform closes that gap by extending Luna HSMs' hardware security boundary into a persistent, object-level enforcement model. When the Key Access Service private keys are protected inside a Luna HSM — in either envelope or delegated mode — the platform uses those hardware-backed keys to encrypt every data object using TDF, the Trusted Data Format. TDF wraps attribute-based access policy directly inside each encrypted file, so the object carries its own access controls wherever it travels. Every decryption request is evaluated in real time against the embedded policy and the requester's current entitlements, whether that request comes from inside the organization, from a cloud service, from a partner network, or from an AI agent. The HSM provides hardware-grade certainty about the keys; the platform provides persistent, policy-driven certainty about the data. The result is first-mile to last-mile protection — hardware-anchored at the key, policy-enforced at every subsequent access.
Two integration points make this specific to the Luna partnership. First, the Virtru Key Access Service integrates directly with Luna HSMs in either envelope or delegated mode, meaning the entire Virtru cryptographic chain runs through the same hardware boundary that regulated industries already rely on for key custody compliance. Second, TDF-protected objects inherit their access policy from the same attribute-based policy plane that governs Luna key operations — so the policy that decides who can unwrap a key is the same policy that decides who can open a file, across every cloud, application, and partner network the data touches.
- Hardware-Anchored Key Access Service roots the Virtru Key Access Service private keys inside a Luna HSM in either envelope or delegated mode, ensuring every cryptographic operation that governs data access runs through FIPS 140-3 Level 3 validated hardware — not a software keystore.
- TDF Objects Inherit Hardware-Grade Key Custody so that every file encrypted by the platform carries a policy that is only resolvable through keys held in the Luna HSM, extending hardware assurance from the key boundary to the data object itself.
- Delegated Mode Eliminates Key Exposure at the Platform Layer by ensuring Key Access Service private keys never leave the HSM boundary — all RSA key generation, wrapping, and unwrapping execute inside the hardware, closing the attack surface that software-based platforms leave open.
- Policy Travels After Decryption because TDF embeds attribute-based access control directly inside each encrypted object, so protection persists when data crosses organizational boundaries, enters partner networks, or moves between clouds — even after the Luna HSM has released the key.
- Real-Time Entitlement Re-evaluation at Every Access means each decryption request is checked against the requester's current attributes, whether a person, service account, or AI agent, so access changes and revocations take effect instantly without re-encrypting data.
- Unified Audit Trail Across Hardware and Data Layers combines Luna HSM cryptographic operation logs with Virtru's decision-level access audit, giving compliance teams a continuous, tamper-evident record from key generation to every downstream data access — in a single defensible evidentiary chain.
- CSP-Independent Key Custody Across Multi-Cloud Deployments uses Luna HSMs deployed on-premises, in the cloud, or via Thales Data Protection on Demand to anchor Virtru key operations outside any cloud provider's trust boundary, satisfying GDPR Article 32 and PCI-DSS key custody requirements regardless of where workloads run.
Deploying the Virtru Data Security Platform with Thales Luna HSMs requires active deployments of both platforms, network connectivity between the Key Access Service and the HSM, and a configured key protection mode matched to the organization's compliance posture.
- Thales Luna HSM — on-premises hardware (Luna Network HSM), cloud-hosted, or Thales Data Protection on Demand; FIPS 140-3 Level 3 validated; supported algorithms include RSA (2048/3072/4096 bit) and AES
- Virtru Data Security Platform — deployed in the customer's VPC or on-premises; Key Access Service configured to reference the Luna HSM for key wrapping or delegated operations
- Key Protection Mode Selection — envelope mode (HSM wraps KAS private keys stored in platform database) or delegated mode (all cryptographic operations execute inside the HSM; no key material leaves the hardware boundary)
- Network Connectivity — between the Virtru Key Access Service and the Luna HSM, within the organization's security boundary; low-latency connection recommended for delegated mode at enterprise request volumes
- Luna HSM Client Software — installed and configured on the Virtru Key Access Service host; Thales Luna HSM client drivers and PKCS#11 libraries required
- High-Availability Configuration (recommended for production) — two or more Luna HSMs in load-balanced configuration to ensure continuous cryptographic service availability
Security Architecture
The joint solution establishes a layered hardware-to-data protection chain in which no single component holds both the keys and the data in cleartext simultaneously. The Thales Luna HSM serves as the hardware root of trust: key material is generated inside the tamper-resistant boundary and never leaves it in unencrypted form. In delegated mode, the Luna HSM performs all cryptographic operations — there is no software path to the keys. In envelope mode, a root symmetric key held in the HSM wraps the Key Access Service private keys before they are persisted, so even if the platform database were compromised, key material would remain protected.
Above the hardware layer, the Virtru Data Security Platform embeds access policy inside every encrypted object using TDF. Each object carries its own ABAC policy evaluated at the moment of every access request — not at the moment of encryption. This means revocations, clearance changes, and policy updates take effect in real time without re-encryption, across every environment where the data has traveled. The hardware boundary protects the keys; the platform's object model protects the data after the keys have done their job.
Compliance & Standards
Thales Luna HSMs are FIPS 140-3 Level 3 validated, providing the hardware assurance evidence required by PCI-DSS Requirement 3.5 (key custody), GDPR Article 32 (technical safeguards), SOC 2, and HIPAA. HSM-generated audit logs capture every cryptographic operation within the hardware boundary, producing audit-defensible documentation that satisfies assessor requirements without additional instrumentation.
The Virtru Data Security Platform is FedRAMP Moderate authorized and built on OpenTDF, an open standard. Combined, the integrated solution supports NIST SP 800-57 (key management), NIST SP 800-53r5 audit and access control requirements, and NIST SP 800-207 Zero Trust Architecture. Organizations subject to GDPR Article 28/32 benefit from CSP-independent key custody: Luna HSMs ensure cloud providers never have access to key material, satisfying Schrems II and equivalent data sovereignty requirements.
Privacy & Data Sovereignty
Key material never transits a cloud provider's infrastructure when Luna HSMs are deployed on-premises or via Thales Data Protection on Demand. The Virtru Data Security Platform enforces decryption decisions through the Key Access Service, which references the Luna HSM — meaning cloud providers cannot compel or construct decryption without the customer's participation. Data subjects' information is protected by a combination of hardware-grade key custody and persistent object-level policy, so regulatory access requests, breaches at the storage layer, and CSP-side compelled disclosures do not result in cleartext exposure of protected content.
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.