Excrypt SSP Enterprise v.2

The most feature-rich payment HSM available

Robust and ultra-powerful

The industry’s leading payment HSM

The Excrypt SSP Enterprise v.2 is the world’s fastest hardware security module (HSM). Its main use case is payment transaction processing. The Excrypt SSP v.2 offers vast cryptographic functionality and is highly scalable. It can reach speeds over 50,000 TPS. It is backward-compatible with the Excrypt SSP Series of HSMs and comes in a 1U rackmount, tamper-proof chassis.

  • Create virtual HSMs with unique firmware versions, users, key storage space, and security policies
  • Access the Excrypt SSP v.2 by using a web portal, APIs, the Guardian Series 3, and VirtuCrypt
  • Test new firmware on independent virtual instances
Sales brochureTalk to an expert

Fastest payment HSM on the market

This device provides full redundancy, superior performance, and platform virtualization. The Excrypt SSP v.2 is the fastest payment HSM in the world, scalable to over 50,000 transactions per second.

Universal compatibility

The Excrypt SSP v.2 offers turnkey compatibility with all major financial host application software sold around the world. It also supports standards-based interfaces like PKCS #11 and Java for general-purpose cryptographic processing.

Scripting and automation

You can create and deploy virtual HSMs with the Futurex Client Library (FXCL) and the Futurex Command Line Interface (FXCLI). This involves a standardized process that you can script and automate.

Disaster recovery and redundancy

The Excrypt SSP v.2 contains integrated disaster recovery and redundancy features. The device complies with all major key management best practices and features physical and logical security controls.

HSM powerhouse

The Excrypt SSP Enterprise v.2 excels in high throughput environments where reliability and functionality are crucial.

Diverse use cases

Use PKCS #11 for host application integration and RSA asymmetric key loading to connected payment devices.

HSM virtualization

Create logically independent HSMs in a host device for separate transaction processing environments.

Process over 50,000 transactions per second in an efficient 1U device

The Excrypt SSP Enterprise v.2 excels in enterprise environments with high throughput. The Excrypt SSP Enterprise v.2 provides full system redundancy and platform virtualization, making it a cornerstone of security infrastructure. It happens to be the fastest payment HSM in the world, capable of processing over 50,000 transactions per second (TPS), all in an efficient 1U form factor device. However, you can scale its power and range of functions according to need.


Click diagram to enlarge

Multi-tenancy to support Crypto-as-a-Service

With Crypto-as-a-Service, organizations maintain a pool of cryptographic resources for their applications. Enterprise resources are shared, but critical data and keys are segregated between applications and business units.

Prevent vendor-lock

Our user-friendly GUI offers turnkey compatibility with all major financial host applications. Vendor-neutral APIs prevent vendor lock. It includes support for standards-based interfaces like PKCS #11 and Java.

Highly available enterprise infrastructure

You can pair the Excrypt SSP Enterprise v.2 with other Futurex devices, such as the Guardian Series 3. Doing so increases the power of your infrastructure. The Guardian can redistribute processing loads to backup devices to prevent the loss of functionality in the event of a disaster.

HSM virtualization

Create logically independent HSMs in a host device for separate transaction processing environments by using the Excrypt's powerful virtualization abilities.
Related: VirtuCrypt cloud

The first fully compliant HSM built for the cloud and backed by VirtuCrypt.

See it now

Related: USB Backup HSM

Infrastructure backup with the FIPS 140-2 Level 3 validated USB device

See it now

Vaultless tokenization

Futurex uses an advanced form of tokenization called vaultless tokenization. This performs tokenization without token vaults, reducing exposure of clear-text data. 

Point-to-point encryption (P2PE)

The Excrypt SSP Enterprise v.2 encrypts data from the point of capture to storage. This ensures that data is never transmitted in the clear.

EMV data preparation and transaction processing

Take advantage of highly scalable payment transaction processing speeds of over 25,000 TPS. Maintain separate, virtual instances of the HSM within a host device.

RSA for asymmetric key loading to ATMs

Generate asymmetric key pairs using the RSA public-key encryption algorithm. This works with public-key cryptography to load asymmetric keys into connected devices such as ATMs.

PKCS #11 for host application integration

The Excrypt SSP Enterprise v.2 connects with standards-based interfaces like PKCS #11 or Java to maximize integration with external applications.

Integrated smart card reader

The integrated smart card reader complies with key management best practices for loading and distributing key components.

Expand what’s possible

HSM virtualization

Excrypt SSP Enterprise v.2 specifications

Hardware features

  • Dual control-enabled, tamper-responsive
  • Smart card reader for M-of-N key fragmentation and dual-factor authentication
  • Dual, redundant gigabit Ethernet ports
  • Dual, redundant, hot-swappable power supplies
  • Secure Cryptographic Device (SCD) with tamper responsive barrier to protect sensitive data

Operating conditions

  • Power: 100 – 240 VAC 50/60 Hz. 225 Watts
  • Operating temp: -40° to 140°F (-40° to 60°C)
  • Storage temp: -40° to 140°F (-40° to 60°C)
  • Operating humidity: 20% to 80% non-condensing
  • Storage humidity: 5% to 95% non-condensing

Dimensions and weight

  • Weight: 36 lbs (16.33 kg)
  • Width: 19 inches (48.26 cm)
  • Height: 1U – 1.72 inches (4.37 cm)
  • Depth: 19.4 inches (49.38 cm)

Powering the VirtuCrypt cloud

VirtuCrypt key management services are backed by the Excrypt SPP Enterprise v.2 with hardened FIPS 140-2 Level 3-validated technology. Whether an organization requires complete infrastructure management or simply more functionality for existing Futurex infrastructure, VirtuCrypt offers a variety of service structures designed to meet security requirements.

VirtuCrypt services

Industry compliance standards

  • FIPS 140-2 Level 3
  • ANSI X9.24 part 1 and part 2 – TR-39

Supported cryptographic functionality

  • DES
  • Triple-DES
  • Master/Session
  • AES
  • RSA
  • EMV
  • PKCS #11 cryptographic library for host application integration

VirtuCrypt integration

  • Monitoring and alerting
  • Backup and disaster recovery

Want to learn more?

Contact a Solutions Architect today.

Give us a call