Key Management Service (KMS)

CloudHSM for HashiCorp Vault Enterprise

Managed hardware security module (HSM) for HashiCorp Vault Enterprise

This service uses CloudHSM Economy to store and manage your cryptographic keys for HashiCorp Vault Enterprise. Vault can be securely unsealed using cryptographic keys stored in the HSMs.

How it works

Your HSMs store your keys in the cloud. The HashiCorp Vault server communicates with your HSMs using the PKCS#11 interface for the auto unsealing procedure.

Benefits and features

Root key wrapping

Vault protects its root key by transiting it through the HSM for encryption rather than splitting into key shares.

Automatic unsealing

Vault stores its HSM-wrapped master key in storage, allowing for automatic unsealing.

Seal wrapping

This mechanism allows to wrap values with an extra layer of encryption for supporting seals. This adds an extra layer of protection and is useful in some compliance and regulatory environments, including FIPS 140-2 environments.

Entropy augmentation

High entropy allows for the generation of strong cryptographic keys by increasing randomness and unpredictability.

Getting started

Select a cluster for your HSM.

North America (USA)

No commitment. Cancel anytime.

Monthly

Europe (Germany/Switzerland)

No commitment. Cancel anytime.

Monthly

Asia Pacific (Singapore)

No commitment. Cancel anytime.

Monthly

Switzerland

No commitment. Cancel anytime.

Monthly

Global

No commitment. Cancel anytime.

Monthly

Switzerland (Sandbox)

clock_hex1b8d4c 1h

ch02-api.cloudshsm.com
us02-api.cloudshsm.com
sg01-api.cloudshsm.com    

Free 90 days trial
Proceed to the checkout to generate a pricing offer and adjust your currency & VAT.

Pricing

You pay a monthly fee for each HSM in your account. Rates vary by Region. You can view these at

CloudHSM Pricing

The HashiCorp Vault Enterprise license fee is not included.