<img alt="" src="https://secure.weed6tape.com/193471.png" style="display:none;">
Join us at SUDC 2026 – Discover the latest in cybersecurity, cryptography, and digital trust. Secure your place.

Register now

About
About
Learn more about our mission, explore career opportunities, and access our resources. Discover how we’re shaping the future of cybersecurity and how you can be part of it.
Contact us
  • There are no suggestions because the search field is empty.

Challenge

For some enterprises, securing sensitive cryptographic keys and executing critical security functions requires an HSM that meets the highest security standards while aligning with their operational needs. Traditional enterprise-grade HSMs often come with significant costs and infrastructure requirements, making them difficult to implement for organizations with budget constraints.

Many enterprises also struggle with the complexity of integrating HSMs into their existing infrastructure, managing cryptographic operations efficiently, and ensuring seamless scalability. Finding a solution that delivers uncompromising security, high performance, and adaptability is essential.

 

Solution

Solution

The Securosys Primus HSM CyberVault Core (E2-Series) addresses these challenges with an enterprise-grade security solution that combines high performance, cost efficiency, and ease of use. It provides a standalone network appliance design that eliminates PCIe-based limitations, a high-performance cryptographic engine with scalable in-field upgrades, comprehensive support for industry-standard APIs to ensure seamless integration, advanced security measures including active tamper and transport protection, and secure remote management capabilities for streamlined administration.

Solution

Key Benefits

API-circle-b&w
Seamless Integration
Offers broad compatibility through fully documented APIs, including PKCS#11, CNG/KSP, Java, and REST. It features two dedicated partitions, each with 120MB storage space, ensuring secure, parallel access for multiple applications within any network environment.
shield-b&w
Optical Interface for High-Speed Connectivity
For enhanced networking flexibility, the CyberVault Core offers an optional optical interface with speeds of up to 10 Gbps, ensuring high-speed cryptographic operations in demanding environments.
locket-circle-blocks-b&w
Rapid Deployment & Low Maintenance
Quick setup with an intuitive wizard, reducing installation time, complexity, and maintenance efforts.
decanus-b&w+red
Secure & Efficient Remote Management
Decanus enables secure remote administration of HSMs and partitions, reducing operational effort.
vault-b&w
Advanced Tamper & Transport Protection
Exceeds FIPS and Common Criteria standards with active tamper sensors, protecting even when unpowered.
Key Differentiators
Primus-HSM-E2-face-top-view

Unbeatable Price/ Performance ratio

The CyberVault Core delivers full network appliance functionality at a PCIe card price level, eliminating embedded HSM limitations.

Comprehensive Cryptographic Support

Supports RSA, ECC, EdDSA, and optionally supports all NIST-selected post-quantum cryptographic algorithms, including ML-DSA, SLH-DSA, ML-KEM,HSS-LMS, and XMSS, ensuring future-proof encryption.

Swiss Made

Crafted entirely in Switzerland, Securosys Primus CyberVault Core embodies unmatched quality and reliability. Free from external influences, our Swiss-made HSMs guarantee the highest standards from development to production, ensuring unparalleled security solutions.

Technical Specifications

01
Security Features
02
Networking Features
03
Technical Data
01
Security Features
Security Architecture
  • Multi-barrier software and hardware architecture with supervision mechanisms
  • Secure supply-chain 
Encryption / Authentication (extract)
  • Post-Quantum Cryptographic (PQC) algorithms (optional)
    ML-DSA, SLH-DSA, ML-KEM, HSS-LMS, XMSS 
  • RSA 1024-8192, DSA 1024-8192 
  • ECDSA 224-521, GF(P) arbitrary curves (NIST, Brainpool, ...) 
  • ED25519, Curve25519, Ed448, BIP-0340, BIP-0341, SLIP-10 
  • Diffie-Hellman 1024, 2048, 4096, ECDH, X448
  • SHA-3/SHA-2 (224 - 512), SHA-1, RIPEMD-160, SHAKE
  • HMAC, CMAC, GMAC, Poly 1305 
  • 128/192/256-Bit AES with GCM-, CTR-, ECB-, CBC-, MAC Mode 
  • Camellia, ChaCha20-Poly1305, ECIES 
Key Generation
  • Two hardware true random number generators (TRNG)
  • NIST SP800-90 compatible random number generator
Key Management
  • 2 partitions and 240MB total storage, fixed 
Operation
  • Number of client connections not restricted
  • Unlimited number of backups, automated backup
Anti-Tamper Mechanisms
  • Several sensors to detect unauthorized access
  • Active destruction of key material and sensitive data on tamper
  • Transport and multi-year storage tamper protection by digital seal
Attestation and Audit Features
  • Cryptographic evidence of audit relevant parameters (keys, configuration, hardware, states, logs, time-stamping)
Identity-based Authentication
  • Multiple security officers (m-out-of-n)
  • Identification based on smart card and PIN
02
Networking Features
03
Technical Data

FAQ

What is the Primus HSM CyberVault Core?
The Primus HSM CyberVault Core is an enterprise-grade Hardware Security Module (HSM) that combines strong cryptographic security with an outstanding performance-to-price ratio. Designed as a standalone network appliance, it provides secure key management, encryption, digital signing, and authentication without the complexity or hardware dependencies of PCIe-based HSMs.
Why choose the CyberVault Core over a PCIe HSM?
Unlike PCIe HSMs that depend on a host server, the CyberVault Core is a standalone network appliance that can be shared across multiple applications and servers. This simplifies deployment, improves resilience, enables remote management, and delivers enterprise HSM capabilities at a price comparable to PCIe solutions.
Which applications can the CyberVault Core secure?
The CyberVault Core is designed to protect cryptographic keys for applications including PKI, certificate authorities, digital signatures, TLS, encryption, authentication, cloud security, code signing, blockchain, and general enterprise key management. It provides a secure foundation for organizations that require trusted cryptographic operations.
Is the Primus HSM CyberVault Core ready for post-quantum cryptography?
Yes it can. The CyberVault Core optionally supports NIST-standardized post-quantum cryptographic algorithms, including ML-KEM, ML-DSA, SLH-DSA, HSS-LMS, and XMSS. Together with classical algorithms such as RSA and ECC, it enables organizations to prepare for a gradual migration to post-quantum cryptography.
Which APIs and integrations are supported?
The CyberVault Core supports industry-standard interfaces including PKCS#11, Microsoft CNG/KSP, JCE/JCA, REST, and OpenSSL. These APIs enable seamless integration with existing PKI solutions, enterprise applications, cloud services, authentication systems, and other cryptographic infrastructures.
Does the CyberVault Core support high availability?
Yes. Multiple CyberVault Core HSMs can operate in an active cluster to provide load balancing and automatic failover. This helps ensure business continuity while allowing cryptographic capacity to grow as your requirements evolve.
Can the CyberVault Core grow with my business?
Yes. The CyberVault Core supports in-field software upgrades, allowing performance and functionality to evolve as your security requirements grow. Optional 10 Gbps optical networking also provides additional scalability for demanding environments. 
Which certifications does the CyberVault Core have?
The CyberVault Core is certified to Common Criteria EAL4+, including EN 419221-5 for cryptographic modules and EN 419241-2 for Signature Activation Modules (SAM). It is also undergoing FIPS 140-3 Level 3 certification, making it suitable for regulated industries. 
How many applications can the CyberVault Core support?
The CyberVault Core includes two dedicated HSM partitions with 120 MB of secure storage each. These isolated partitions allow different applications or environments to securely share the same HSM while keeping cryptographic keys and operations separated.
Can the CyberVault Core be used with cloud services?
Yes. The CyberVault Core integrates with public cloud environments through Bring Your Own Key (BYOK) and external key management solutions, allowing organizations to maintain control of their cryptographic keys while using cloud-based services.