Navigation

Get in touch
Logo
News

Futurex HSM: payments and PKI on one platform

Futurex combines payment HSMs and general purpose HSMs in one platform and adds cloud services, key management and devices for key injection. We check with you which generation fits and sort every claim about validations and certificate numbers. We then connect the devices to your applications and stay with you in daily operations.

Try product
  • FIPS 140-3 Level 3 per vendor statement
  • PCI PTS HSM v4
  • ML-KEM and ML-DSA
  • 75 virtual HSMs per device
Devices of the Futurex Excrypt HSM platform
Product photo: Futurex

Futurex at a glance

A hardware security module generates and stores cryptographic keys inside a certified device and never releases them in plaintext. Futurex brings two worlds together: payments with PINs and card keys and general applications such as PKI run on the same platform. One device carries up to 75 virtual HSMs and 250 partitions for applications.

Cryptography and hardware security modules are our core competence. We know the partitioning of the Excrypt platform, the command sets of the Classic line and the path into the VirtuCrypt cloud. We run your project from the selection through the integration into daily operations.

Excrypt HSM Platform, CryptoHub, Classic Enterprise, KMES
FIPS 140-3 Level 3 and PCI PTS HSM v4, vendor statement
ML-KEM and ML-DSA, SLH-DSA announced
1U appliance, PCIe card, VirtuCrypt cloud

The series in detail

Excrypt HSM Platform

The Excrypt HSM Platform is the current hardware and replaces the Classic line, and Futurex publishes no individual model numbers for it. One device carries up to 75 virtual HSMs and 250 partitions for applications and delivers up to 40,000 RSA-2048 signatures per second. In June 2025 Futurex stated it was the only PCI HSM validated module with post-quantum algorithms, which is a vendor statement.

View device illustration

Models

Excrypt HSM Platform: Models
Excrypt HSM 1U applianceUp to 100,000 payment operations per second
Excrypt HSM PCIe cardInstalled in your own server
Excrypt HSM in VirtuCryptCloud instance in the Futurex data center
Form factors
1U appliance, PCIe card, Cloud instance
Operation
Your own data center, VirtuCrypt cloud

Certifications

  • FIPS 140-3 Level 3, vendor statement without a certificate number
  • PCI PTS HSM v4 per the listing page
  • PCI HSM validated per the product page

Features

  • Up to 75 virtual HSMs and 250 partitions per device
  • Up to 40,000 RSA-2048 signatures and 100,000 payment operations per second
  • ML-KEM and ML-DSA natively, SLH-DSA is announced
  • Random number generator on a quantum basis
  • Excrypt Universal Interface for the commands of older devices
  • PKCS#11, JCA and JCE, CNG, OpenSSL and REST

Vendor information

CryptoHub

CryptoHub is a software defined platform that brings payment HSMs, general purpose HSMs, key management and certificate authorities onto one device. Several tenants work separately on it, and the appliance comes as a 2U device with up to 75 virtual HSMs. Next to it stand a virtual deployment, a deployment in a container and the CryptoHub Cloud operated by Futurex. The statements about the validation level differ: the appliance page names FIPS 140-3 Level 3, the cloud page names FIPS 140-2 Level 3 and PCI HSM.

Futurex CryptoHub
Product photo: Futurex

Models

CryptoHub: Models
CryptoHub HSM2U appliance with up to 75 virtual HSMs
CryptoHub virtualVirtual appliance or container
CryptoHub CloudOperated by Futurex
Form factors
2U appliance, Virtual appliance, Container, Cloud service
Operation
Your own data center, Virtualization, CryptoHub Cloud

Certifications

  • FIPS 140-3 Level 3 for the appliance, vendor statement
  • FIPS 140-2 Level 3 per the CryptoHub Cloud page
  • PCI HSM per the CryptoHub Cloud page

Features

  • Payment HSM and general purpose HSM in one platform
  • Key management across the whole life cycle, cloud keys included
  • Key injection for point of sale terminals, ATMs and IoT devices
  • Certificate authorities, tokenization and database encryption
  • Multitenancy, several areas on one device
  • The statements about the FIPS level differ per product page

Vendor information

VirtuCrypt

VirtuCrypt is the cloud operated by Futurex and stood ready in 16 data centers in December 2025. The service comes in three tiers: Enterprise, Elements with billing per transaction and Plus as an extension of an installation in your own data center. For payments Futurex names PCI PTS HSM v4, plus FIPS 140-2 and 140-3 Level 3 as well as ML-KEM and ML-DSA.

Futurex VirtuCrypt
Product photo: Futurex

Models

VirtuCrypt: Models
EnterpriseTier for full operations in the Futurex cloud
ElementsBilling per transaction
PlusExtension of an installation in your own data center
Form factors
Cloud service
Operation
Futurex cloud, Extension of your own data center, Marketplaces of AWS, Azure and Google Cloud

Certifications

  • FIPS 140-2 and FIPS 140-3 Level 3, vendor statement
  • PCI HSM
  • PCI PTS HSM v4 for payments

Features

  • 16 data centers as of December 2025
  • ML-KEM and ML-DSA for post-quantum algorithms
  • Available through the marketplaces of AWS, Azure and Google Cloud
  • Bring your own keys through Excrypt Touch
  • Three tiers: Enterprise, Elements and Plus

Vendor information

Vectera Plus

Vectera Plus is the general purpose HSM of the Classic Enterprise line, so of the prior generation, and it is still sold. The 1U device computes RSA up to 8192 bit and ECC. Virtual HSMs and partitions separate the applications, and custom code runs in the Secure Code Environment. It carries FIPS 140-2 Level 3 as well as the PCI PTS and PCI HSM validations. X9 TR-39 comes on top, and a cloud deployment runs in VirtuCrypt.

Futurex Vectera Plus
Product photo: Futurex

Models

Vectera Plus: Models
Vectera Plus1U appliance for general applications
Vectera Plus in VirtuCryptCloud deployment of the same series
Form factors
1U appliance, Cloud instance
Operation
Your own data center, VirtuCrypt cloud

Certifications

  • FIPS 140-2 Level 3
  • PCI PTS and PCI HSM
  • X9 TR-39

Features

  • RSA up to 8192 bit and ECC
  • Virtual HSMs and partitions on one device
  • Secure Code Environment for custom code
  • REST, PKCS#11, JCE, CNG and OpenSSL interfaces
  • Cloud deployment through VirtuCrypt

Vendor information

Excrypt SSP Enterprise v.2

The Excrypt SSP Enterprise v.2 is the payment HSM of the Classic Enterprise line. It stays backward compatible with the Excrypt SSP9000 and SSP9000 Enterprise. On throughput the sources name two values: the product page speaks of up to 50,000 transactions per second, the launch release of more than 20,000. Below it sits the Excrypt Plus with 5,000 transactions per second, 250 partitions and an upgrade path to the SSP Enterprise v.2.

Models

Excrypt SSP Enterprise v.2: Models
Excrypt SSP Enterprise v.2Up to 50,000 transactions per second per the product page
Excrypt Plus5,000 transactions per second and 250 partitions
Excrypt SSP9000 and SSP9000 EnterpriseOlder devices that stay compatible
Form factors
1U appliance
Operation
Your own data center

Certifications

  • FIPS 140-2 Level 3
  • PCI PTS HSM
  • PCI PTS HSM v3 for the Excrypt Plus
  • X9 TR-39

Features

  • Payment HSM of the Classic Enterprise line
  • The product page names up to 50,000 transactions per second, the launch release more than 20,000
  • Backward compatible with the Excrypt SSP9000 and SSP9000 Enterprise
  • Excrypt Plus with 5,000 transactions per second and 250 partitions
  • From the Excrypt Plus an upgrade path leads to the SSP Enterprise v.2

Vendor information

KMES Series 3

The KMES Series 3 is a 2U key server with a built in HSM and manages certificates across their whole life cycle. It runs the offline root CA and the issuing CA, speaks KMIP and separates tenants. Keys it moves into public clouds as BYOK, EKM or CSE. A hybrid CA with post-quantum algorithms is announced, and operations run in your own data center or in VirtuCrypt. In addition there are devices for key injection, for the administration of fleets and for remote key loading.

Futurex KMES Series 3
Product photo: Futurex

Models

KMES Series 3: Models
KMES Series 32U server with a built in HSM
SKI Series 3Key injection for 18 terminals at once
Guardian Series 3Administration and audit of whole device fleets
Excrypt TouchTablet at FIPS 140-2 Level 3 for remote key loading
Form factors
2U appliance, Cloud instance
Operation
Your own data center, VirtuCrypt cloud

Certifications

  • FIPS 140-2 Level 3 for the built in HSM
  • PCI PTS HSM
  • FIPS 140-2 Level 3 for the Excrypt Touch

Features

  • Offline root CA and issuing CA on one device
  • Manage certificates across the whole life cycle
  • BYOK, EKM and CSE for public clouds
  • KMIP for third party systems, separated tenants
  • A hybrid CA with post-quantum algorithms is announced

Vendor information

How you pick the right line

Four points decide the choice at Futurex: the kind of load, the generation of the devices, the required evidence and the operating model. We clear them in a workshop and record the result in a decision paper.

Kind of load

PINs and card keys require a payment HSM per PCI PTS. General applications such as PKI and code signing work with a general purpose HSM. The Excrypt HSM Platform and CryptoHub cover both on one device. The Classic line splits the tasks into Vectera Plus and Excrypt SSP Enterprise v.2.

Generation

The Excrypt HSM Platform is the current hardware and the successor of the Classic line, which Futurex still sells. Whoever runs Vectera Plus or Excrypt SSP Enterprise v.2 today plans the move along their own certificate lifetimes.

Evidence

Futurex names FIPS 140-3 Level 3 but publishes no certificate number for it, so we carry that as a vendor statement. On the PCI evidence the pages differ: the current platform is listed at v4, the Excrypt Plus at v3.

Operating model

You run the devices yourself, hand operations to us or use VirtuCrypt with 16 data centers. The service is also available through the marketplaces of the hyperscalers. For the transition the Plus tier connects your own data center with the cloud. The entire solution runs in German data centers.

Our work around Futurex

We do not only supply the device, we supply the work before and after it: selection, partitioning, connection of the applications, key ceremony and operations. We document the key ceremony so that auditors can follow it later. One team accompanies you from consulting to operations.

  • HSM consulting and integration

    We cut virtual HSMs and partitions to size and connect PKCS#11, JCE and REST. The commands of the Classic line we translate through the Excrypt Universal Interface. We document the key ceremony in an audit proof form.

    HSM & Key Management

  • PQC readiness

    We record which keys and protocols rest on RSA and ECC today, because quantum computers threaten both algorithms. We then plan the path to ML-KEM and ML-DSA and state clearly that SLH-DSA is only announced so far.

    Post-Quantum Cryptography

  • Cloud

    We connect your data center to VirtuCrypt or the CryptoHub Cloud. We set up the subscription through the marketplaces of the hyperscalers. Your own keys we bring in through Excrypt Touch.

    Cloud

Standards and evidence

These four rules decide the selection and the documentation in a Futurex project. We tell you which line carries each one today and which claim without a certificate number stays a vendor statement.

Requirement / Demands / OTOKO® delivers
RequirementDemandsOTOKO® delivers
FIPS 140-3Validated crypto modules with a defined physical protection levelExcrypt HSM Platform and CryptoHub at Level 3, without a published certificate number
PCI PTS HSMCertified hardware for PINs and card keysExcrypt HSM Platform and VirtuCrypt per v4, Excrypt Plus per v3
X9 TR-39Review of key management in the card businessVectera Plus and Excrypt SSP Enterprise v.2 support TR-39
KMIPVendor neutral key managementKMES Series 3 and CryptoHub speak KMIP for third party systems

Frequently asked questions about Futurex

Related topics

You would like to learn more about

Futurex

Futurex combines payment HSMs and general purpose HSMs in one platform and adds cloud services, key management and devices for key injection. We check with you which generation fits and sort every claim about validations and certificate numbers. We then connect the devices to your applications and stay with you in daily operations.

Our clients

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.