As regulated digital asset platforms face increasing cybersecurity threats and evolving compliance requirements, protecting cryptographic keys has become a foundational security priority. This case study explores how HKVAX integrated Thales Luna Hardware Security Modules (HSMs) into its digital asset custody architecture to strengthen key management, support regulatory compliance, and improve operational resilience.
Learn how HKVAX centralized cryptographic key generation, storage, and signing within FIPS 140-3 Level 3 certified hardware, reduced operational risk, streamlined audit readiness, and built a secure foundation for future innovations including AI-driven security and post-quantum cryptography.
Operating within the SFC’s rigorous regulatory framework, HKVAX needed to address increasingly complex threats, including risks to private cryptographic keys, smart contracts, and custodial infrastructure. HKVAX also recognized that future digital asset security depends on robust standards and a core architecture grounded in HSM-backed controls. To operate within this environment, HKVAX required security controls that support auditability, operational resilience, and the secure adoption of evolving blockchain technologies.
As HKVAX’s digital asset services matured, technical complexity increased. Blockchain-related algorithms continue to evolve, requiring custom integrations. HKVAX needed a solution that integrated into its custody architecture while maintaining compliance and long-term scalability.
To meet SFC requirements and protect client assets, HKVAX integrated Thales Luna Hardware Security Modules (HSMs) as the cryptographic foundation of its key management and custody framework. Thales Luna HSMs were selected based on Federal Information Processing Standards (FIPS) 140-3 certifications, industry reputation, and the ability to support regulatory-grade deployments.
“Thales Luna HSMs stood out because it is among the first vendors to achieve FIPS 140-3 Level 3 validation and has an excellent reputation in the industry for reliability and security,” said Jack Zhou, CIO at HKVAX.
Thales Luna HSMs provide a trusted hardware foundation for securing cryptographic keys used in digital asset custody and transaction processing environments. Backed by independently validated security (including FIPS 140-3 Level 3 and Common Criteria EAL 4+), Luna HSMs help keep key operations within tamper-resistant hardware, supporting governance and audit readiness in regulated custody environments. With more than 30 years of HSM expertise, Thales is trusted by leading financial institutions worldwide to protect cryptographic keys in environments where confidentiality, integrity, and availability are critical.
HKVAX uses Thales Luna HSMs within its custody architecture to support secure key management, including key generation, storage, and usage, and to enable secure transaction signing. The deployment also supports the company’s multi-tier wallet architecture, incorporating cold and hot wallet separation, rolebased access control, and disaster-recovery protocols.
During implementation, Thales local teams provided technical guidance and demonstrations that helped HKVAX accelerate development and seamlessly integrate Luna HSMs into its existing infrastructure.
Since implementing Thales Luna HSMs, HKVAX has centralized private key generation, storage, and signing operations within certified hardware. This hardware-backed approach reduces operational risk by isolating cryptographic keys from software and privileged access, while providing the audit evidence required to meet regulatory expectations. HKVAX successfully passed independent security audits and strengthened its operational resilience as a regulated digital asset provider.
“Thales has a strong track record in securing critical systems for financial institutions and government organizations. Its Luna HSM solution offers high performance, flexibility, and readiness that aligns with HKVAX’s technical and regulatory needs,” said Zhou.
The deployment also increases confidence among customers and partners in the security of HKVAX’s platform. “As a licensed VATP in Hong Kong, safeguarding client assets is our top priority. Using Thales Luna HSM gives both us and our clients strong confidence in the security of our platform,” said Zhou.
In addition to meeting regulatory requirements, the deployment has improved day-to-day operational efficiency within HKVAX’s environment. Since going live, the company has automated key management processes, reduced manual intervention, and strengthened auditability across its custody operations. These improvements have helped enable HKVAX to pass independent security audits while maintaining the flexibility required to support evolving blockchain technologies.
With Thales Luna HSMs serving as the foundational layer of its custody architecture, HKVAX has been able to focus on expanding its digital asset services without compromising security or compliance.
As the digital asset landscape continues to evolve, HKVAX is preparing for emerging cybersecurity challenges, including AI-driven threats and post-quantum cryptography (PQC) readiness. Through its partnership with Thales, the company is positioned to maintain leadership in secure and compliant digital-asset infrastructure as new technologies and regulatory expectations emerge.
HKVAX is one of the pioneering Virtual Asset Trading Platforms (VATPs) licensed by the Hong Kong Securities and Futures Commission (SFC). The company provides regulated digital asset trading, off-platform transactions, stablecoins, tokenization of real-world assets, and Web3 infrastructure services. HKVAX is committed to building a secure, compliant, and scalable digital asset ecosystem that connects traditional finance with decentralized innovation.