<img alt="" src="https://secure.weed6tape.com/193471.png" style="display:none;">
The transition to PQC is accelerating. Test NIST-approved algorithms in our CloudHSM PQC Sandbox.

Get started with your free trial

About
About
Learn more about our mission, explore career opportunities, and access our resources. Discover how we’re shaping the future of cybersecurity and how you can be part of it.
Contact us
  • There are no suggestions because the search field is empty.

Challenge

As digital security demands grow, businesses must balance high performance, resilience, and future-proof encryption. The rise of quantum computing necessitates a seamless transition to post-quantum cryptography (PQC) while maintaining existing cryptographic standards. At the same time, organizations require cryptographic solutions that can process millions of transactions per second without compromising security or compliance.

Ensuring uninterrupted operations is critical, making high availability, clustering, and failover mechanisms essential for mission-critical systems. Scalability is another key concern, as security infrastructures must evolve alongside business growth without requiring costly system overhauls. Finally, complexity in cryptographic management remains a challenge, requiring intuitive solutions that integrate seamlessly and simplify deployment.

3D-hsm-colourful

Solution

The Securosys Primus HSM CyberVault Series provides the perfect blend of cutting-edge security, scalability, and performance, enabling businesses to stay ahead of emerging threats and technological shifts.

Designed for businesses of all sizes, from small enterprises to large financial institutions, it ensures seamless integration, uninterrupted operation, and a smooth transition to post-quantum cryptography (PQC). Built for mission-critical applications, our Primus CyberVault HSMs support clustering, load balancing, and failover mechanisms, guaranteeing reliability and performance even in the most demanding environments.

 

3D-hsm-colourful

Which CyberVault model is right for you?

4850037 CyberVault Pro The Pro edition – like all models from the series – is equipped with a 2FA authentication mechanism and a user interface for intuitive management. Performance and storage are fixed, making it a cost-efficient and reliable solution for small to midsized businesses that require secure key management and encryption without the need for extensive scalability.
giorgio-trovato-H8X-2bchJI8-unsplash CyberVault Enterprise The Enterprise edition provides the highest flexibility in the CyberVault series to best fit a company’s need. It offers upgrade options for enhanced performance, additional storage, or increased number of partitions, allowing businesses to scale as their security infrastructure evolves. Designed for blockchain infrastructures or organizations requiring adaptability, the Enterprise model ensures long-term investment protection.
annie-spratt-s1N_aVIviqA-unsplash CyberVault Max The Max edition stands out as one of the fastest HSMs on the market, handling over 50’000 transactions per second (TPS). Designed for high-performance environments, it can scale up to 1,000 partitions and over 1’000’000 TPS in clustered setups, delivering unmatched speed, security, and reliability. This makes it the ideal choice for financial institutions, or for anyone requiring demanding cryptographic workloads.
freepik_white-background-with-squares-coming-out-wall-creating-3d-effect CyberVault Max Plus The Max Plus edition pushes the limits of hybrid performance for PQC and classical algorithms combined, and an impressive 30GB off-the-shelf storage. This model is tailored for organizations requiring high-speed cryptographic processing, and large-scale key storage. It is the ultimate solution for businesses operating in highly regulated industries, large-scale cloud environments, or national security applications.
Key Differentiators
image (1)-1

Hybrid PQC and Classical Cryptography

Primus CyberVault (X2 models) ensures a smooth transition to post-quantum cryptography (PQC) by integrating hybrid signatures that combine classical algorithms (RSA, ECC/ED) with NIST-selected PQC algorithms (ML-DSA, SLH-DSA, ML-KEM, HSS-LMS, XMSS).

Seamless Integration & Effortless Management

Designed for plug-and-play deployment, CyberVault X2 models fit into existing infrastructures without disruption, featuring intuitive user interfaces and 2FA authentication for simplified secure operation.

Market-Leading Performance & Scalability

From small businesses to enterprise-level cryptographic workloads, CyberVault X2 models offer fixed, upgradeable, or extreme-speed performance handling up to 1 million transactions per second in clustered setups.

Unmatched Reliability & Availability

With load balancing, clustering, and automatic failover, CyberVault X2 series ensures continuous operation, even in the most demanding environments.

Swiss-Engineered Security

Developed, manufactured, and maintained in Switzerland, CyberVault is built to meet the highest security and compliance standards, ensuring trust and regulatory adherence.

Technical Specifications

01
Security Features
02
Networking Features
03
Technical Data
01
Security Features
Security Architecture
  • Multi-barrier software and hardware architecture with supervision mechanisms
  • Secure runtime environment for VaultContainers. Enables the hosting of Securosys-supplied loadable modules, providing APIs, TSB (Transaction Security Broker) and/or VaultCode containers for secure execution of customer-defined attested logic.
Encryption /
Authentication (extract)
  • Post-Quantum Cryptographic (PQC) algorithms
    ML-DSA, SLH-DSA, ML-KEM, HSS-LMS, XMSS
  • RSA 1024-8192, DSA 1024-8192
  • ECDSA 224-521, GF(P) arbitrary curves (NIST, Brainpool, ...)
  • ED25519, Curve25519, Ed448, BIP-0340, BIP-0341, SLIP-10
  • Diffie-Hellman 1024, 2048, 4096, ECDH, X448
  • SHA-3/SHA-2 (224 - 512), SHA-1, RIPEMD-160, SHAKE
  • HMAC, CMAC, GMAC, Poly 1305
  • 128/192/256-Bit AES with GCM-, CTR-, ECB-, CBC-, MAC Mode
  • Camellia, ChaCha20-Poly1305, ECIES
Key Generation
  • Two hardware true random number generators (TRNG)
  • NIST SP800-90 compatible random number generator
Key Management
      Upgradeable to
Model Partition Total Storage Partitions Total Storage
Pro 5 600MB fixed
Enterprise 10 2.4GB 250 30GB
Max 20 4.8GB 1000 30GB
Max Plus 100 30GB 1000 fixed

 

Operation
  • Number of client connections not restricted
  • Unlimited number of backups, automated backup
Anti-Tamper Mechanisms
  • Several sensors to detect unauthorized access
  • Active destruction of key material and sensitive data on tamper
  • Transport and multi-year storage tamper protection by digital seal
Attestation and Audit Features
  • Cryptographic evidence of audit relevant parameters (keys, configuration, hardware, states, logs, time-stamping)
Identity-based Authentication
  • Multiple security officers (m-out-of-n)
  • Identification based on smart card and PIN
02
Networking Features
03
Technical Data

FAQ

What is the difference between the CyberVault Pro, Enterprise, Max, and Max Plus?
All CyberVault models share the same certified security architecture, cryptographic capabilities, and APIs. They differ in performance, secure storage capacity, and scalability. The Pro model is ideal for smaller deployments, while Enterprise, Max, and Max Plus offer increasing throughput and storage for larger, business-critical environments. Because the hardware platform is identical, performance and storage can be upgraded through software licenses without replacing the appliance.
Which CyberVault model should I choose?

The CyberVault Series includes Pro, Enterprise, Max, and Max Plus models with different performance and storage capacities. All models share the same security architecture, allowing organizations to choose the right balance of throughput, scalability, and key storage for their requirements.

Is the Primus HSM CyberVault ready for post-quantum cryptography?
Yes. All CyberVault models support NIST-standardized post-quantum algorithms, including ML-KEM, ML-DSA, and SLH-DSA, alongside classical algorithms such as RSA and ECC. Hybrid cryptography allows organizations to begin their migration to quantum-resistant security while maintaining compatibility with existing applications.
Can I upgrade the performance of my CyberVault HSM without replacing the hardware?
Yes. The CyberVault Series is designed to grow with your requirements. Performance, secure storage, and available features can be expanded through software licenses, allowing organizations to increase cryptographic capacity without replacing their HSM infrastructure.
How does built-in clustering improve availability?
The CyberVault Series supports native clustering for high availability and scalability. Multiple HSMs can operate as a single logical system with automatic failover, load balancing, and synchronized key storage, ensuring uninterrupted cryptographic services even if one appliance becomes unavailable.
Does the CyberVault Series support hybrid cloud deployments?
Yes. The CyberVault Series can be deployed on premises while integrating with cloud services such as AWS, Microsoft Azure, Salesforce, and Google Cloud through external key management and BYOK solutions. This enables organizations to retain full control of their cryptographic keys while using cloud-native services.
Which APIs and integrations are supported?
The CyberVault Series supports industry-standard interfaces including PKCS#11, JCE/JCA, Microsoft CNG/KSP, REST, KMIP, and OpenSSL. It integrates with a wide range of applications, including PKI, certificate authorities, code signing, authentication systems, cloud key management, databases, blockchain platforms, and enterprise security solutions.
Which certifications does the CyberVault Series have?

The CyberVault Series is certified to Common Criteria EAL4+ (EN 419221-5 for cryptographic modules and EN 419241-2 for Signature Activation Modules (SAM)) and is currently undergoing FIPS 140-3 Level 3 certification, making it suitable for highly regulated industries.

How many partitions and cryptographic keys does the CyberVault Series support?
The CyberVault Series supports up to 1,000 isolated partitions and provides up to 30 GB of secure key storage, depending on the model. This allows organizations to securely separate applications, customers, or business units while managing millions of cryptographic key objects on a single platform.