Excrypt Hardware Security Modules (HSMs)
Modern cryptography, built for what’s next.
Table of Contents
Excrypt Hardware Security Modules
One HSM. Any Environment. Zero Compromise.
Table of Contents
Excrypt HSMs: Unified Cryptography, Ready for What's Next
Futurex’s Excrypt hardware security modules (HSMs) deliver unified cryptography for payment and general-purpose use cases on a scalable, future-ready platform. Each deployment supports up to 75 virtual HSMs, performs up to 100,000 operations per second, and includes validated post-quantum algorithms. The result is a consistent, proven cryptographic foundation you can deploy on-premises, in the cloud, or across hybrid environments
Excrypt HSMs: Flexible HSM Deployment Models
The Excrypt HSM platform offers unified cryptographic performance across every form factor: network (rack-mount) appliance, PCIe card, or cloud. Your team standardizes on one platform and manages cryptography consistently across environments.

Payment Use cases:
- PIN translation & verification
- CVV generation & validation
- EMV validation
- Message authentication code (MAC) generation & verification
- Apple, Google, Samsung tokens
- PIN & offset generation
- Mobile & web PIN management
- EMV key generation & derivation
- Cardholder data decryption (FPE & DUKPT)
- Cardholder data translation
- P2PE key management
- ...more
General-Purpose Use cases:
- Data encryption
- Data privacy and confidentiality
- Database encryption
- Data integrity
- PKI and certificate authority
- IoT device authentication
- 5G subscriber authentication
- Blockchain and distributed ledger
- Digital signatures
- Code signing
- IoT provisioning and 5G
- AI weight & model integrity
- ...more
Cryptography Built for Data Protection Teams
Managing multiple HSMs for different workloads slows teams and complicates compliance. Excrypt HSMs replace that sprawl with a single platform that handles any payment and general-purpose cryptography use case without requiring code changes or new integrations.

Advanced Multitenancy - Deploy up to 75 virtual Excrypt HSMs per device, with full cryptographic segmentation for any use case. True multitenancy means you scale environments, not hardware.
Modern User Interface – Futurex’s Excrypt HSMs are managed through an interface designed by operational teams. Intuitive workflows, real-time monitoring, and task automation that reduces configuration time from hours to minutes.
Multi-Cloud Support - Deploy Excrypt Cloud HSMs across Futurex’s 16+ global data centers, with native integration with your applications running inside AWS, Azure, and Google Cloud. True multi-cloud support means you control where workloads run, not your HSM vendor.
Post-Quantum Ready – Futurex’s HSM platform is the first to support post-quantum cryptography (PQC) that has been PCI HSM validated. As quantum-safe migration accelerates, Excrypt HSMs are already certified and ready, with no hardware refresh required.
CryptoHub Integration - Excrypt HSMs integrate directly into Futurex's CryptoHub platform, transforming individual HSMs into a unified cryptographic estate with centralized key management, multi-cloud orchestration, data protection, and enterprise PKI. CryptoHub streamlines your HSM estate across every environment that relies on encryption, with validated integrations spanning AWS, Microsoft, Oracle, and hundreds of application partners.
| Use Cases | What It Covers | Business Outcome |
|---|---|---|
| Payment & PIN Security | • EMV, mag-stripe, contactless NFC • 3-D Secure, mobile wallets HCE • PIN translation, PIN-block formatting, ATM RKL |
Compliance with global payment processes and faster transaction authorizations |
| General Purpose | • Format-Preserving Encryption (FPE) • PCI P2PE |
Protects PII/PAN at rest, in motion, and in analytics without schema rewrites |
| Key Lifecycle & Partitioning | • TR-31, AKB, OBKM • 250 isolated key domains per device • Live key mirroring across sites |
Centralized control, zero-downtime rotations, audit-ready segregation |
| Virtual & Cloud-Native | • Up to 75 virtual HSMs per chassis • Hybrid clustering with VirtuCrypt Cloud • REST / PKCS #11 / JCE APIs |
Spin up cryptographic capacity and solutions in minutes and burst to the cloud on demand |
| High-Speed & Elastic Scale | • Up to100K TPS • CryptoHub platform for load balancing |
Match capacity to peak season volumes without forklift upgrades |
| PQC-Ready | • NIST PQC algorithms (ML-KEM, ML-DSA) pre-loaded • Dual-stack RSA + PQC keypairs |
Future-proof keys and certificates, protect against HNDL (harvest now decrypt later) |
| Custom & General-Purpose Crypto | • AES-GCM, SHA-3, ECC curves, RSA-4K • Customer-defined algorithms via firmware |
Supports proprietary protocols and emerging standards without new hardware |
Excrypt HSMs: Performance That Scales
Excrypt HSMs process up to 100,000 transactions per second and 40,000 signatures per second, making them the highest-performing HSMs on the market. But raw speed is only part of the story. Excrypt HSMs scale cryptographic capacity as your operations grow, with flexible performance tiers tailored to your workloads.
This level of enterprise-class throughput supports the consolidation of high-volume operations, such as payment processing, tokenization, PKI, and certificate generation at scale, as well as application security across distributed architectures, all within a single platform.
Migration from Legacy HSM Platforms: No Rip-and-Replace
Most organizations never plan to become multi-vendor cryptographic shops. However, over time, environments fragment, costs escalate, hardware proliferates, integrations break, and teams are left maintaining an increasingly fragile estate that no one ever intended to build.
Legacy HSMs scatter your cryptography. Excrypt HSMs unify them by design.
- No code rewrites required
- No vendor lock-in
- Replace legacy HSMs without changing your software stack
Why it matters: De-risk migration projects, protect existing investments, and maintain business continuity during transitions.
Secure Code Environment: Run Your Logic Inside the Excrypt HSM platform
Run custom code inside a FIPS-compliant boundary. Execute custom cryptographic operations, proprietary algorithms, or application-specific logic within the HSM's tamper-resistant environment. Excrypt HSMs give you the flexibility to support specialized workloads without compromising security or compliance.
- Run proprietary algorithms and custom cryptographic operations
- Application-specific logic within a tamper-resistant environment
- Confidential computing capabilities
Why it matters: If your use case demands it, Excrypt supports it with unique compliance requirements, specialized workflows, and proprietary integrations that legacy HSM vendors often promise on a roadmap.
Excrypt HSM Technical Specs: FIPS 140-3 (in progress), PCI HSM, and More
| Category | Detail | Why It Matters |
|---|---|---|
| Cryptography Support | 3DES, AES-128, AES-256, RSA-2048, RSA-4096, RSA-8192, ECC P-521, SHA2, SHA3, FPE, TR-31/TR-34, DUKPT, PQC (ML-KEM, ML-DSA), X9.117/X9.31, X.509, ECDSA, ECDH, additional regional and proprietary schemes supported; contact Futurex for the complete list | Full payment + data-protection coverage, future-proof for quantum |
| Throughput On-demand | Up to 100K TPS and up to 40K SPS | One platform, upgrade performance as needs grow |
| Virtual HSMs | Up to 75 per physical HSM | Multitenant, hybrid, Dev/Test isolation |
| Partitions | 250 with policy-level API blocking | Audit-ready key segregation |
| Interfaces | Excrypt API, PKCS #11, Java JCA/JCE, OpenSSL, Microsoft CNG/CAPI/EKM RESTful | Drop-in for existing payment hosts and new apps |
| Compliance | FIPS 140-3 Level 3 (in progress), PCI PTS HSM v4, Common Criteria, Cartes Bancaires, Bancontact, AS2805 AusPayNet, GBIC, ASC X9.24, and other standards | Meets global regulatory mandates |
| PCIe Card | PCIe standard height: 111.15 mm / 4.376 in -length: 312 mm / 12.283 in | Flexibility for any enterprise infrastructure |
| 1U appliance weight | 34 pounds (15.42 kg) | Standard data-center envelope |
| Environmental | Operating temperature range: 10°C to 50°C with 55 CFM air flow rate. Storage temperature range: -20°C to 65°C | Standard data-center envelope |
When you need performance under pressure, Excrypt HSMs keep going.


Get Started For Free – Secure Your Encryption Strategy Now
- Book a 30-Minute Consultation → Get a custom security roadmap.
- Validate Performance with a Proof-of-Concept (PoC) → See real-world results in your environment.
- Deploy Quickly and Easily → On-premises, cloud, or hybrid - whatever fits your security needs.
- Download Integration Guides
Talk to a Security Expert
.png?width=2000&height=244&name=awards%20(1).png)
.png)
