What is a general purpose HSM?
A general purpose hardware security module, or HSM, securely generates, stores, and uses cryptographic keys while supporting encryption, decryption, digital signing, and verification across multiple applications and workloads. Designed for enterprise environments, it protects cryptographic infrastructure inside hardened, tamper-resistant hardware and helps support strong security and regulatory compliance.
Meet the Next-Generation Luna 8
Luna HSMs secure the technologies you use every day and are shaping the future of digital trust
Designed to meet FIPS 140-3 Level 3 and Common Criteria certification requirements, Luna HSMs deliver a strong, quantum-safe root of trust across PKI, digital assets, AI, digital IDs, IoT, DevOps, code signing, TLS, mobile networks, and more, ensuring resilience and compliance in the face of today’s security challenges, evolving regulatory landscape and tomorrow’s digital demands.
Built to answer the evolving needs of cryptographic security
Quantum-Safe from the Ground Up
Transition to quantum-safe cryptography with PQC algorithms and quantum-safe root of trust
Thales-Designed Crypto Processor
Optimize for high-volume PQC operations with a Thales-designed cryptographic processor
Crypto Agility
Use a modern architecture built for faster updates and new cryptographic mechanisms
Automation & Scalability
Automate administration & integrate IT infrastructure tools for easy deployment & scalability
Seamless Migration
Migrate from Luna 7 with compatible APIs and a key migration solution
Find the Right HSM for Your Environment
“The new quantum-safe HSM from Thales enables us to support multiple secure environments while simplifying operations and making more efficient use of our infrastructure. [It gives us] the flexibility to support multiple use cases, applications and business needs over time helps us maximize hardware investments. The combination of predictable performance and high availability gives our IT and security teams the assurance they need to operate efficiently to deliver consistent service to our stakeholders.”
Common General Purpose HSM Use Cases
Post-Quantum Crypto
Protect next-generation keys with quantum-safe algorithms, enable crypto agility and PQC readiness.
Secure Digital Signing & PKI
Protect PKI, signing, and code-signing keys with trusted hardware for digital trust workflows.
Digital Assets & Crypto Custody
Protect wallet keys, secure digital assets, and support trusted transaction-signing workflows.
5G & Telecom Security
Protect subscriber identities, authentication, and network trust with hardware-backed cryptographic security.
IoT Device Security
Protect device identities, manufacturing workflows, and lifecycle trust with hardware-backed key security.
Cloud Data Security
Protect cloud and on-premises keys with HSM-backed control for BYOK, HYOK, and hybrid trust architectures.
A New Era of HSM Technology from Thales
Your digital security depends on cryptographic keys that encrypt and decrypt data. Thales Luna HSMs help secure devices, identities, transactions, and applications with a flexible, scalable solution designed for strong security, high performance, and easier integration.
Built for the Post-Quantum Future: The next-generation Luna 8 combines a Thales designed cryptographic processor with a crypto-agile architecture to deliver a quantum-safe root of trust. Protect critical keys in certified hardware today while enabling a seamless transition to post-quantum cryptography (PQC) with high-volume performance, faster updates, and support for new cryptographic mechanisms.
Luna HSM Features and Benefits
With a wide range of APIs, flexible deployment options, and superior performance, Luna HSMs help you quickly secure hundreds of applications through an expansive ecosystem of out-of-the-box technology partner integrations.
Cryptographic keys remain inside tamper-resistant hardware for the highest level of security and tighter control over trust-critical operations.
Central key and policy management, broad encryption support, and PQC-safe PKI readiness help organizations guard against evolving threats and capture new opportunities.
Thales prioritizes third-party security assurance schemes. Luna Network 8 HSMs have FIPS 140-3 Level 3 and EU Common Criteria certifications underway. The Luna 7 HSM portfolio (Luna 7 Network, PCIe, USB and Backup HSMs are FIPS 140-3 Level 3 validated. Luna HSM 7 has also received eIDAS certification as both a Qualified Signature and Qualified Seal Creation Device (QSCD).
Support secure administration, activation, and operational control across distributed environments and modern cryptographic infrastructures.
Deploy Luna HSMs on premises, in the cloud, as a service, or across multiple environments to support compliance, backup, cloning, scaling, and future migration needs.
Use a flexible crypto foundation designed to support long-term efficiency, scalability, and operational value as requirements evolve.
Explore the Luna HSM portfolio
Flexible deployment for every need across Luna HSM products and related services.
Thales HSMs Play Well with Others
A broad ecosystem of partners and integrations extends trusted Luna HSM security across enterprise and cloud environments.
Featured resource
HSM Buyer’s Guide
Learn how to evaluate HSM vendors, compare deployment models, and assess certifications, integrations, scalability, operational control, and future readiness.
Related resources
Common questions about General Purpose HSMs
A general purpose HSM is a hardware security module that protects cryptographic keys and supports encryption, decryption, signing, and verification across many applications and workloads rather than a single proprietary function.
Organizations typically use a general purpose HSM when they need a high-assurance hardware root of trust for PKI, code signing, TLS, digital identity, encryption, or other trust-critical cryptographic operations.
General purpose HSMs support broad enterprise cryptographic use cases such as PKI, code signing, TLS, and data encryption. Payment HSMs are purpose-built for card, PIN, EMV, and transaction-security workflows in the payments ecosystem.
General Purpose HSMs can support post-quantum readiness by helping organizations protect next-generation keys, enable crypto agility, and prepare cryptographic infrastructure for evolving standards and migration requirements.
Luna HSMs can be deployed on premises, in the cloud, as a service, or across hybrid environments, helping organizations align key control and cryptographic protection with business and compliance needs.
Common use cases include PKI, secure digital signing, code signing, post-quantum cryptography, digital assets, IoT security, 5G security, TLS, and cloud data security.






















