Please Fill Out Form

to Request Document

Required Fields*

Security and Convenience

The Futurex USB Backup HSM is the ultimate solution for portability, affordability, and data protection. The device is a software-free, 100% hardware-based 256-bit AES XTS encrypted USB key, with onboard keypad PIN authentication and ultra-fast USB 3.1 (3.0) data transfer speeds. Equipped with on-the-fly encryption, PINs and other important data remain encrypted while the drive is at rest. The USB Backup HSM is completely cross-platform compatible and OS agnostic, thriving in Windows, Linux, Mac, Android, Chrome, embedded systems, and equipment possessing a powered USB port and storage file system. All internal components are protected from physical tampering with a layer of hardened epoxy, and locked-down firmware brings immunity to malware attacks such as BadUSB.

USB Backup HSM Features

  • FIPS 140-2 Level 3 validated HSM
  • 16GB of storage space
  • Multi-user authentication & locking
  • Back up servers or select encrypted keys
  • Double-encrypted using keys on source HSM & on USB backup HSM

Physically back up Futurex devices with the USB Backup HSM

The USB Backup HSM allows you to physically secure & store multiple hardware security module (HSM) & Base Architecture Model (BAM) device backups. Secured with a passcode number pad, the FIPS 140-2 Level 3 validated USB device can be directly connected to Futurex devices or remotely connected through the Excrypt Touch. HSM & BAM device backups are double-encrypted using source and USB HSM keys and multi-user authentication.

Supported Futurex Devices

  • Excrypt Plus
  • Excrypt SSP Enterprise v.2
  • Vectera Plus
  • SKI Series 3
  • KMES Series 3
  • Guardian Series 3

Fully Standards Compliant

The USB Backup HSM is compliant with the guidelines for FIPS 140-2 Level 3 validation, which encompasses both its physical tamper-resistant features as well as its identity-based authentication. The epoxy-coated boundary includes all encryption functions and all Critical Security Parameters (CSPs) such as PIN storage, encryption key generation and storage, random number and seed generators, all firmware storage, and device storage. The device is a complete encryption system, and all CSPs are never shared with a host system.

Polymer-Coated & Wear-Resistant Onboard Keypad

The drive is unlocked by entering a PIN on keypad, not on the host computer’s keyboard. Until the secure USB HSM is unlocked via its keypad, it remains invisible to the host. The embedded keypad circumvents all hardware and software key logging attempts to capture passwords by excluding the host system from the authentication process. The keypad has polymer-coated buttons designed to prevent wear on the most commonly used buttons.

Separate Admin and User Mode

The USB Backup HSM offers Admin mode and User Access mode. The Admin mode controls the universal programmable settings of the device and can only be accessed with the Admin PIN. The User mode is limited to basic external drive functions like read/write, unlock/lock, etc. The data on the drive can also be accessed with the Admin PIN in the User mode.

Brute-Force Defense

All USB Backup HSMs are authenticated by entering a PIN on the onboard keypad. Since the PIN is not entered using the host computer’s keyboard, the device is not vulnerable to software or hardware-based key-loggers or software-based brute force attacks. If the device comes under a physical brute force attack, your data is protected with a programmable “Brute Force Hack Defense Mechanism” which will trigger the deletion of the device's encryption key if the programmed number (between 4 and 20 of consecutive incorrect password entries has been attempted, destroying the ability to decrypt the stored data.

Self-Destruct PIN

When programmed and activated, the USB Backup HSM performs a Crypto-Erase. This is the last line of defense for data security when the device’s physical security is at risk. The Self-Destruct PIN defends against physically compromising situations by erasing the key’s contents, leaving it in normal working order.

Other Functions

  • User-Forced and Admin-Forced Enrollment
  • Two ReadOnly Modes
  • Unattended Auto Lock
  • Lock Override
  • Programmable PIN Lengths

Data Transfer Rate

  • Up to 190MB/s Read / 80MB/s Write

Power Supply

  • USB Port / Internal Battery


  • Super Speed USB 3.1 (Backwards compatible with USB 3.0, 2.0 and 1.1)

ECCN / HTS / Cage Code

  • 5A992.c
  • 8473.50.3000
  • 3VYK8

System Requirements

Windows®, Mac®, Linux, Android and Symbian systems, or any powered USB OS with a storage file system


  • FIPS 140-2 Level 3
  • IP-67
  • FCC
  • CE
  • VCCI
  • WEE
  • C-TICK


  • 81mm x 18.4mm x 9.5mm | 22 g