Excrypt Plus Payment HSM

Versatile HSM for payments and general-purpose

hardware security module (HSM) vectera plus
From SMBs to Tier 1 enterprises

A powerful payment HSM for any industry

The Excrypt Plus is a hardware security module (HSM) for both payment and general-purpose use. It supports every major encryption algorithm and API to deliver excellent security and smooth integration with host applications, and complies with strict standards such as FIPS 140-2 Level 3 and PCI PTS HSM v3. The Excrypt Plus leads the industry in scalable functionality and endless utility.

Sales brochureTalk to an expert

Transaction acquiring

  • CVV generation and validation
  • EMV validation
  • Mobile payment acceptance
  • PIN translation and verification
  • Payment key management
  • MAC generation and verification

Card and mobile issuing

  • EMV key generation and derivation
  • Online and mobile PIN management
  • Mobile token issuance (Apple Pay, Google Pay, Samsung Pay, and host card emulation tokens)
  • PIN and offset generation

Point-to-point encryption

  • Cardholder data decryption
  • Cardholder data translation
  • Symmetric encryption algorithms
  • Point-to-point encryption key management

Testing and development

Perform testing, development, and rapid prototyping within a secure code environment (SCE).
hardware security module (HSM) vectera plus

Scale Excrypt Plus deployment according to transaction processing speed, redundancy, and remote access

Support cryptographic processing for multiple applications at once with hundreds of application partitions

Integrate the Excrypt Plus with host payment applications with extensive support for all common APIs

Why choose the Excrypt Plus Payment HSM?

Like every Futurex solution, the Excrypt Plus is the first payment HSM designed with the user in mind. To that end, it supports all major APIs, payment types, and algorithms, as well as near-universal compliance with international standards. With highly scalable processing power and cryptographic functionality, as well as powerful virtualization capabilities, the Excrypt Plus is a transaction processing powerhouse for organizations of any size, in any industry.


Support for all common interfaces enables fast integration with payment applications.

Application partitioning

Multiple applications can simultaneously connect to and use Excrypt resources through key storage table segmentation.

HSM virtualization

Logically partition Excrypt Plus resources to gain the functionality of multiple independent virtual HSMs

High availability and disaster recovery

Combine the Excrypt Plus with Futurex's Guardian Series 3 to manage device clusters for HA and DR architecture with synchronous peering.
Related: Excrypt SSP Enterprise v.2

Check out the world’s fastest payment HSM.

See it now

Related: Payment industry solutions

Learn more about Futurex solutions for the payments industry.

See it now

Universal compatibility

The Excrypt Universal Interface is an API that communicates with host transaction processing applications for easy integration

Versatile cryptographic functionality

The Excrypt Plus performs cryptographic processing and key management for payment and general-purpose use cases

Easy scripting and automation

The Futurex Client Library (FXCL) and interface-based wrapper (FXCLI) enable easy scripting and automation of management and operational tasks

Disaster recovery and high availability

The Excrypt Plus integrates with the Futurex Guardian Series 3 to achieve automatic synchronization and data backup functionality

Strategic integration

Integrating the Excrypt Plus with other Futurex products amplifies speed, availability, and range of functionality to meet any cryptographic requirement


Futurex solutions comply with current and emerging regulatory requirements including PCI DSS, FIPS 140-2 Level 3, ANSI X9.24 part 1 and 2 – TR-39, and FCC part 15 – class B

Excrypt Plus Payment HSM specifications

Hardware features

  • Dual control-enabled, tamper-responsive
  • Smart card reader for M-of-N key fragmentation and dual-factor authentication
  • Dual, redundant gigabit Ethernet ports
  • Dual, redundant, hot-swappable power supplies
  • Secure Cryptographic Device (SCD) with tamper responsive barrier to protect sensitive data

Operating conditions

  • Power: 100 – 240 VAC 50/60 Hz. 225 Watts
  • Operating temp: -40° to 140°F (-40° to 60°C)
  • Storage temp: -40° to 140°F (-40° to 60°C)
  • Operating humidity: 20% to 80% non-condensing
  • Storage humidity: 5% to 95% non-condensing

Dimensions and weight

  • Weight: 36 lbs (16.33 kg)
  • Width: 19 inches (48.26 cm)
  • Height: 1U – 1.72 inches (4.37 cm)
  • Depth: 19.4 inches (49.38 cm)

Powering the VirtuCrypt cloud

VirtuCrypt cloud HSM services are backed by the Excrypt Plus with hardened, FIPS 140-2 Level 3 validated technology. Whether an organization requires complete infrastructure management or more functionality for current infrastructure, VirtuCrypt can meet any security requirement.

VirtuCrypt services
virtucrypt cloud hsm

Industry compliance standards

  • FIPS 140-2 Level 3
  • ASC X9.24 Part 1 and Part 2 – TR-39
  • RoHS
  • FCC Part 15 – Class B

Supported cryptographic functionality

  • EMV
  • DES
  • Triple-DES
  • Master/Session
  • AES
  • RSA
  • Tokenization
  • Point-to-Point Encryption (P2PE)
  • PKCS #11

Frequently asked questions

Payment and general-purpose HSMs are optimized for different IT environments. A payment HSM might be designed to handle hundreds or even thousands of payment transactions per second. On the other hand, a general-purpose HSM might specialize in use cases outside of payments. This could be encrypting files and applications, creating and signing encryption keys, acting as a certificate authority (CA), and authenticating client devices across a network. In summary, the use cases an HSM must fulfill are determined by the environment in which it will be deployed.

Your processing throughput (in transactions per second, or TPS) will depend on several factors, such as the scale of your operation, number of customers and partners, and how your infrastructure is setup. Small and mid-range organizations typically start with between 250-500 TPS and scale upward. Larger organizations tend to base their estimated processing needs on their previous needs as well as any planned expansions. The Excrypt Plus offers highly scalable transaction processing speeds, from a few hundred TPS up to several thousand.

A payment HSM is a physically and logically secure device that performs cryptographic operations. Payment HSMs are often used to encrypt payment transactions and manage payment keys. The descriptor “payment” refers to the payment processing environments in which they are commonly deployed. They can be integrated into a wide variety of different environments and customized for diverse use cases.

Payment and general-purpose HSMs have several things in common. They both protect sensitive data by carrying out cryptographic functions. For example, payment and general-purpose HSMs might run encryption algorithms, create keys, or manage sensitive data. The key difference is what kind of IT environment they’ll be deployed in, and which use cases that will entail.

Rapidly encrypt & decrypt sensitive payment data in a PCI-DSS compliant HSM

Electronic payment networks need data security solutions that scale in speed and can expand over time to support emerging payment types and algorithms. The Excrypt Plus meets and exceed those needs, offering complete and robust transaction security at speeds of up to 5,000 transactions per second (TPS). With integrated disaster recover and redundancy features to ensure rock-solid reliability, the device complies with key management best practices and contains some of the industry’s most advanced security features.

Strategic integration

Strategically integrating the Excrypt Plus with other Futurex products paves the way for even faster speeds, higher availability, and fuller functionality to meet the most demanding requirements. It is compatible with Futurex solutions including the Guardian Series 3 and the Excrypt Touch, to create a fully redundant, remotely managed cryptographic infrastructure.

Available Excypt Plus functionality
  • Card/PIN issuance & validation
  • Mobile payments
  • P2PE & tokenization
  • ATM remote key loading
  • EMV issuance & validation
  • MAC & hashing
  • General purpose crypto

The Excrypt Plus is available in varying models, providing the transaction speeds your organization needs. Need to expand more? Increase speeds in the field to 5,000 TPS and beyond—or upgrade to the Excrypt SSP Enterprise v.2 to achieve speeds of 20,000 TPS and beyond.

Supports wide-ranging crypto functionality
  • Magnetic Stripe and EMV Card
  • Issuance and Verification
  • MAC and Hashing
  • Point-to-Point Encryption
  • Format-Preserving Encryption
  • ATM Remote Key Loading
  • HCE and Cloud Payments
  • Digital Signing
  • General-Purpose Cryptography
  • Mobile Payments
  • PIN Management and Printing
  • Tokenization
  • Contactless/NFC
  • 3-D Secure
  • PCI Data Protection
  • On Behalf Key Management (OBKM)
  • Custom Functionality
Hardened Enterprise Security Platform integration

The Excrypt Plus integrates directly with Futurex’s full solution suite, the Hardened Enterprise Security Platform, for centralized configuration, management, monitoring, alerting, load balancing, scalability, cloud-based services, and more.

Disaster recovery and high availability
  • Contains hot-swappable power supplies and dual Ethernet ports
  • Integrates with VirtuCrypt Plus Monitoring and Alerting and Disaster Recovery services for increased infrastructure visibility and uptime
  • Can be peered and configured into functional groups using the Guardian Series 3 centralized management platform for load balancing and failover support
Application partitioning
  • Use application partitioning to segregate key storage locations, giving individual applications control over their own keys and security policies through API function blocking
  • Up to 250 application partitions are supported with a single Excrypt Plus
  • Each partition has its own unique identity, key storage, and API function blocking
Universal compatibility

Turnkey compatibility with all major financial host application software sold around the world, as well as support for standardsbased interfaces like PKCS #11 and Java for general purpose cryptographic processing.

HSM management tools
  • Excrypt Manager: Dedicated, GUI-based application for secure HSM configuration, management, and key loading
  • Web Portal: A secure, web-based application for configuring virtually all aspects of the Excrypt Plus, monitoring logs, and more
Industry compliance standards
  • FIPS 140-2 level 3 compliant
  • ANSI X9.24 part 1 and part 2 – TR-39
  • Payment card industry data security standard (PCI DSS)
  • FCC part 15 – class B
Available functions & interface
  • RSA
  • AES
  • ECC
  • Excrypt API
  • Java JCA/JCE
  • PKCS #11
  • And more
Key block formats
  • TR-31
  • Cryptograms
  • AKB

Yes, the general payment HSM integration guide for the Excrypt Plus may be viewed here. A PDF version of the integration guide may be downloaded from here.

Want to learn more?

Contact a Solutions Architect today or request a demo.

Give us a call

Futurex HSM customers