Luna General Purpose HSMs

Market-leading quantum-safe foundation of cryptographic trust

What is a general purpose HSM?

A general purpose hardware security module, or HSM, securely generates, stores, and uses cryptographic keys while supporting encryption, decryption, digital signing, and verification across multiple applications and workloads. Designed for enterprise environments, it protects cryptographic infrastructure inside hardened, tamper-resistant hardware and helps support strong security and regulatory compliance.

Meet the Next-Generation Luna 8

Luna HSMs secure the technologies you use every day and are shaping the future of digital trust

Designed to meet FIPS 140-3 Level 3 and Common Criteria certification requirements, Luna HSMs deliver a strong, quantum-safe root of trust across PKI, digital assets, AI, digital IDs, IoT, DevOps, code signing, TLS, mobile networks, and more, ensuring resilience and compliance in the face of today’s security challenges, evolving regulatory landscape and tomorrow’s digital demands.

Built to answer the evolving needs of cryptographic security

Quantum-Safe from the Ground Up

Quantum-Safe from the Ground Up

Transition to quantum-safe cryptography with PQC algorithms and quantum-safe root of trust

 
Thales-Designed Crypto Processor

Thales-Designed Crypto Processor

Optimize for high-volume PQC operations with a Thales-designed cryptographic processor

 
Crypto Agility

Crypto Agility

Use a modern architecture built for faster updates and new cryptographic mechanisms

 
Automation & Scalability

Automation & Scalability

Automate administration & integrate IT infrastructure tools for easy deployment & scalability

 
Seamless Migration

Seamless Migration

Migrate from Luna 7 with compatible APIs and a key migration solution

 

Find the Right HSM for Your Environment

“The new quantum-safe HSM from Thales enables us to support multiple secure environments while simplifying operations and making more efficient use of our infrastructure. [It gives us] the flexibility to support multiple use cases, applications and business needs over time helps us maximize hardware investments. The combination of predictable performance and high availability gives our IT and security teams the assurance they need to operate efficiently to deliver consistent service to our stakeholders.”
Jack Zhou CIO HKVAX

Common General Purpose HSM Use Cases

    Post-Quantum Crypto

    Protect next-generation keys with quantum-safe algorithms, enable crypto agility and PQC readiness.

    Learn more

    Secure Digital Signing & PKI

    Protect PKI, signing, and code-signing keys with trusted hardware for digital trust workflows.

    Learn more

    Digital Assets & Crypto Custody

    Protect wallet keys, secure digital assets, and support trusted transaction-signing workflows.

    Learn more

    5G & Telecom Security

    Protect subscriber identities, authentication, and network trust with hardware-backed cryptographic security.

    Learn more

    IoT Device Security

    Protect device identities, manufacturing workflows, and lifecycle trust with hardware-backed key security.

    Learn more

    Cloud Data Security

    Protect cloud and on-premises keys with HSM-backed control for BYOK, HYOK, and hybrid trust architectures.

    Learn more

    A New Era of HSM Technology from Thales

    Your digital security depends on cryptographic keys that encrypt and decrypt data. Thales Luna HSMs help secure devices, identities, transactions, and applications with a flexible, scalable solution designed for strong security, high performance, and easier integration.

    Built for the Post-Quantum Future: The next-generation Luna 8 combines a Thales designed cryptographic processor with a crypto-agile architecture to deliver a quantum-safe root of trust. Protect critical keys in certified hardware today while enabling a seamless transition to post-quantum cryptography (PQC) with high-volume performance, faster updates, and support for new cryptographic mechanisms.

    Luna 8

    Luna HSM Features and Benefits

      With a wide range of APIs, flexible deployment options, and superior performance, Luna HSMs help you quickly secure hundreds of applications through an expansive ecosystem of out-of-the-box technology partner integrations.

      Cryptographic keys remain inside tamper-resistant hardware for the highest level of security and tighter control over trust-critical operations.

      Central key and policy management, broad encryption support, and PQC-safe PKI readiness help organizations guard against evolving threats and capture new opportunities.

      Thales prioritizes third-party security assurance schemes. Luna Network 8 HSMs have FIPS 140-3 Level 3 and EU Common Criteria certifications underway. The Luna 7 HSM portfolio (Luna 7 Network, PCIe, USB and Backup HSMs are FIPS 140-3 Level 3 validated. Luna HSM 7 has also received eIDAS certification as both a Qualified Signature and Qualified Seal Creation Device (QSCD).

      Support secure administration, activation, and operational control across distributed environments and modern cryptographic infrastructures.

      Deploy Luna HSMs on premises, in the cloud, as a service, or across multiple environments to support compliance, backup, cloning, scaling, and future migration needs.

      Use a flexible crypto foundation designed to support long-term efficiency, scalability, and operational value as requirements evolve.

      Explore the Luna HSM portfolio

      Flexible deployment for every need across Luna HSM products and related services.

      Luna 8

      Luna 8 Network HSM

      Meet the next generation of general purpose HSM innovation on the Thales HSM platform.

      Learn More
      Luna Network HSM

      Luna 7 Network HSM

      High-assurance, network-attached HSMs for scalable enterprise and cloud security workloads.

      Learn More
      PCIe HSM

      Luna 7 PCIe HSM

      Embedded, high-performance HSMs for dedicated cryptographic acceleration and application security.

      Learn More
      Luna USB HSM

      Luna 7 USB HSM

      Portable HSMs ideal for offline key storage and root-key protection use cases.

      Learn More
      Luna Backup HSM Solutions

      Luna 7 Backup HSM Solutions

      Protect and recover high-value cryptographic material with secure backup workflows.

      Learn More
      Luna Cloud HSM Services

      Luna Cloud HSM Services

      Extend Luna HSM security through cloud-delivered HSM services.

      Learn More

      Thales HSMs Play Well with Others

      A broad ecosystem of partners and integrations extends trusted Luna HSM security across enterprise and cloud environments.

      Featured resource

      HSM Buyer’s Guide

      Learn how to evaluate HSM vendors, compare deployment models, and assess certifications, integrations, scalability, operational control, and future readiness.

      Common questions about General Purpose HSMs

        A general purpose HSM is a hardware security module that protects cryptographic keys and supports encryption, decryption, signing, and verification across many applications and workloads rather than a single proprietary function.

        Organizations typically use a general purpose HSM when they need a high-assurance hardware root of trust for PKI, code signing, TLS, digital identity, encryption, or other trust-critical cryptographic operations.

        General purpose HSMs support broad enterprise cryptographic use cases such as PKI, code signing, TLS, and data encryption. Payment HSMs are purpose-built for card, PIN, EMV, and transaction-security workflows in the payments ecosystem.

        General Purpose HSMs can support post-quantum readiness by helping organizations protect next-generation keys, enable crypto agility, and prepare cryptographic infrastructure for evolving standards and migration requirements.

        Luna HSMs can be deployed on premises, in the cloud, as a service, or across hybrid environments, helping organizations align key control and cryptographic protection with business and compliance needs.

        Common use cases include PKI, secure digital signing, code signing, post-quantum cryptography, digital assets, IoT security, 5G security, TLS, and cloud data security.