Futurex Payment HSM
Protect card issuance, mobile payments, transaction acquiring, PIN, P2PE, and tokenization workflows with certified payment cryptography built for scale and operational control.
At a Glance
Futurex Payment HSMs secure card issuance, transaction acquiring, mobile payments, PIN processing, P2PE, and tokenization workflows on the same converged Excrypt HSM platform that runs Futurex's general-purpose HSM. It is available as a rack appliance, PCIe card, or cloud instance through VirtuCrypt for flexible deployment across enterprise environments.
World's fastest HSM with up to 100,000 payment operations per second on a single Excrypt HSM
Native support for EMV, PIN, P2PE, tokenization, card issuance, mobile wallets, and mPOS acceptance workflows
Compliant with PCI HSM v4 and FIPS 140-3 Level 3 standards
Administration through web, APIs, CLI, with centralized CryptoHub workflows
Certified cryptography for critical payment workflows
A payment hardware security module (HSM) protects cryptographic operations used in card and payment transactions. It generates, stores, derives, translates, and uses payment keys inside a validated hardware boundary.
Futurex Payment HSM capabilities run on the Excrypt HSM platform across on-premises rack appliances, PCIe cards, and cloud instances through VirtuCrypt. Issuers, acquirers, processors, payment service providers, and payment infrastructure teams can use the same platform for issuance, authorization, acceptance, key distribution, and data protection workflows.

Reduce the operational burden of a fragmented payment HSM estate
Payment infrastructure rarely grows as one coordinated program. An issuance platform is added first. A mobile wallet rollout follows. mPOS, P2PE, PIN translation, or tokenization introduces another system, console, audit trail, and runbook. The cryptography works, but the operating model becomes harder to control and harder to evidence.
Excrypt consolidates payment cryptography onto a common platform. Teams can manage EMV, PIN, P2PE, tokenization, key lifecycle, and remote key loading through consistent administrative workflows, while payment workloads remain certified, isolated, and separately governed. Futurex provides 24/7 access to Technical Account Managers and Support Engineers for infrastructure where uptime and audit readiness depend on cryptographic availability.
Payment Workloads
| Workload | How the Excrypt HSM supports it |
| Card issuance and EMV | Generate and derive EMV issuer and application-level keys for card issuance and chip personalization. Validate transaction cryptograms while keeping cardholder-specific key material inside the certified boundary. |
| Mobile wallets and tokenization | Provision payment credentials into Apple Pay, Google Pay, Samsung Pay, and other mobile payment technologies. Support mobile wallet and card-on-file tokenization while keeping underlying PAN data out of the token flow. |
| PIN and transaction processing | Translate and validate PIN blocks and PIN offsets across ATM and POS networks. Decrypt cardholder data for authorization and clearing, and generate CVVs and MACs inside the HSM. |
| mPOS and micro-merchant acceptance | Use remote key loading to distribute payment credentials and encryption keys to widely distributed, low-footprint terminal fleets without sending a technician to every location. |
| Payment and enterprise HSM consolidation | Run payment cryptography and general-purpose enterprise cryptography on the Excrypt platform while keeping payment workloads certified, isolated, and separately governed. |
Keep payment keys and sensitive data inside the hardware boundary
Every payment cryptographic operation on the platform runs inside FIPS 140-3 Level 3 validated HSMs. Key material is generated, stored, and used inside that boundary rather than in application memory or general-purpose systems.
Payment keys never leave the validated hardware boundary in plaintext form
Hardware-backed random number generation, including an onboard quantum random number generator (QRNG) for high-entropy key material
Formal key ceremonies establish root and working keys under controlled, auditable procedures
The same hardware root of trust anchors payment-specific and general-purpose cryptographic workloads
Distribute and rotate keys across terminal fleets
Formal key ceremonies establish root and working keys under dual-control and audit procedures. Remote key loading distributes working keys to ATM, POS, and mPOS terminal fleets without requiring a site visit. This reduces the operational burden of initial deployment, rotation, and expansion across distributed acceptance environments.
Migrate payment workloads in controlled stages
Migration from an existing payment HSM is typically staged by workload rather than executed as a single cutover. Teams can move one key type or workflow, such as EMV issuance, PIN translation, or P2PE, while the Excrypt platform runs alongside the existing environment.
The Excrypt Universal Interface provides compatibility with legacy HSM interfaces. Futurex Technical Account Managers support key ceremony planning and cutover sequencing, helping payment teams reduce application disruption and preserve audit control during transition.
Scale and isolate payment services on shared infrastructure
A single physical Excrypt HSM can support up to 75 isolated virtual HSMs and up to 250 application partitions per host. Separate environments can be assigned by workload, region, business unit, or customer. Each has independent key material, access controls, configuration, and audit trails.
A partition supporting EMV issuance and a partition supporting P2PE on the same physical HSM cannot access each other's key material or configuration. This lets teams consolidate infrastructure without collapsing operational or compliance boundaries.
Prepare payment cryptography for algorithm change
Payment cryptography has a long compliance horizon. EMV, PIN, and tokenization key material can remain in production for years under certification cycles that do not move quickly. The Excrypt HSM platform supports classical and NIST-standardized post-quantum algorithms side by side, allowing payment teams to begin migration planning without re-platforming or disrupting certified workflows already in production.

Deployment, management, and integrations
The Excrypt HSM platform is available as a 1U rack-mounted appliance, PCIe card, or cloud instance through VirtuCrypt. Administration is available through web, API, and CLI workflows. CryptoHub adds centralized orchestration, reporting, discovery, key management, data protection, PKI, and CA services across physical, virtual, and cloud-hosted HSM estates.
| Category | Supported systems and interfaces |
| Card and issuance systems | Card issuance and personalization systems; mobile wallet provisioning systems (Apple Pay, Google Pay, Samsung Pay) |
| Network and terminal systems | Acquirer and processor authorization platforms; ATM and POS network switches; mPOS terminal fleets via remote key loading; P2PE key injection tooling |
| Cryptographic interfaces | PKCS #11, Java JCA/JCE, Microsoft CNG/CAPI/EKM, OpenSSL |
| APIs and native interfaces | RESTful API, Excrypt native interface, Excrypt Universal Interface for compatibility with legacy HSM interfaces |
| Ecosystem services | CryptoHub for orchestration, reporting, discovery, key management, data protection, PKI, and CA services |
Compliance support
Futurex payment HSMs support the compliance and assurance needs of payment environments.
-
FIPS 140-3 Level 3 validated HSMs for payment cryptographic operations
-
PCI PTS HSM v4 certification
-
Cartes Bancaires, Bancontact, AusPayNet AS2805, and GBIC certifications
-
ANSI X9.24 support for retail financial services key management
-
Support for PCI DSS cryptographic key protection controls within a broader cardholder data environment
Frequently Asked Questions
What does a key ceremony look like in practice?
A key ceremony is a controlled, witnessed procedure in which root or working keys are generated, split into components, and distributed to designated custodians under dual-control and audit requirements. It follows documented procedures suited to regulatory and card-scheme expectations and produces an audit record of who participated and what was generated.
Can Excrypt support multiple regions or business units on one platform?
Yes. Virtual HSMs and application partitions can be assigned by region, business unit, customer, or workload, each with independent key material and access policy, while reporting through CryptoHub.
Does Futurex support international card networks and schemes?
Yes. Beyond PCI PTS HSM v4, the platform supports certifications and requirements for Cartes Bancaires, Bancontact, GBIC, and AusPayNet AS 2805 supporting issuers and acquirers operating under regional card scheme requirements.
Featured Resources
“Futurex solutions have ensured that EPX has stayed ahead of the curve in the payments industry. Their innovation and foresight have helped EPX grow with confidence.”
- Truscott Lee, Director of Operations
EPX
Consolidate certified payment cryptography
Talk to Futurex about card issuance, transaction processing, mobile payments, remote key loading, migration, and payment HSM operations at scale.