<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Thales Luna HSMs

Hardware-backed encryption that protects keys, and data that protects itself.

luna-7-hsm-by-thales

Thales Luna HSMs deliver tamper-resistant, FIPS 140-3 Level 3 validated hardware security modules that protect cryptographic keys at the foundation of enterprise security. For organizations that rely on encryption to meet PCI-DSS, GDPR, HIPAA, FISMA, and FedRAMP requirements, Luna HSMs ensure that master keys are generated, stored, and operated exclusively within a certified hardware boundary — eliminating the software-based exposure risks that cloud keystores and general-purpose servers cannot close. Deployable on-premises, in the cloud, as a service through Thales Data Protection on Demand, or in hybrid configurations, Luna HSMs have served as the cryptographic anchor for the world's largest financial institutions, healthcare organizations, telecommunications providers, and government agencies for over thirty years.

Thales Luna HSMs protect cryptographic keys inside FIPS 140-3 Level 3 validated hardware, ensuring master keys are never accessible to a cloud provider or exposed on a general-purpose server. Two key protection modes — envelope and delegated — let organizations match hardware custody requirements to their compliance posture without sacrificing operational agility. Luna HSMs deploy consistently across AWS, Azure, Google Cloud, and on-premises environments through Thales Data Protection on Demand, eliminating cloud vendor lock-in while maintaining a single, hardware-anchored key management layer. Multiple HSMs can be deployed in high-availability, load-balanced configurations to ensure uninterrupted cryptographic service at enterprise scale. Backed by thirty years of market leadership, Thales Luna HSMs are the hardware security foundation trusted by the world's most regulated industries.


 

Better Together: Thales Luna HSMs + Virtru Data Security Platform

Luna HSMs solve the hardest part of encryption: ensuring keys never leave a certified hardware boundary. What they cannot do is follow the data after it has been decrypted and released — and that is where most breaches occur. Once a file leaves a protected storage environment, crosses an organizational boundary, or is shared with a partner, the HSM's boundary ends. The keys are safe. The data is not.

The Virtru Data Security Platform closes that gap by extending Luna HSMs' hardware security boundary into a persistent, object-level enforcement model. When the Key Access Service private keys are protected inside a Luna HSM — in either envelope or delegated mode — the platform uses those hardware-backed keys to encrypt every data object using TDF, the Trusted Data Format. TDF wraps attribute-based access policy directly inside each encrypted file, so the object carries its own access controls wherever it travels. Every decryption request is evaluated in real time against the embedded policy and the requester's current entitlements, whether that request comes from inside the organization, from a cloud service, from a partner network, or from an AI agent. The HSM provides hardware-grade certainty about the keys; the platform provides persistent, policy-driven certainty about the data. The result is first-mile to last-mile protection — hardware-anchored at the key, policy-enforced at every subsequent access.

Two integration points make this specific to the Luna partnership. First, the Virtru Key Access Service integrates directly with Luna HSMs in either envelope or delegated mode, meaning the entire Virtru cryptographic chain runs through the same hardware boundary that regulated industries already rely on for key custody compliance. Second, TDF-protected objects inherit their access policy from the same attribute-based policy plane that governs Luna key operations — so the policy that decides who can unwrap a key is the same policy that decides who can open a file, across every cloud, application, and partner network the data touches.