Luna T-Series
Hardware Security Modules

Quantum Ready, U.S.-Built Security for Mission Critical Cryptographic Keys

Hardware Security Modules (HSMs) are dedicated cryptographic processors that protect the full lifecycle of cryptographic keys. As hardened, tamper‑resistant roots-of-trust, they securely generate, manage, and store keys for sensitive data and mission‑critical applications.

Thales Trusted Cyber Technologies’ (TCT) Luna T‑Series HSMs are the trusted choice of U.S. government agencies, meeting U.S. supply chain requirements and delivering high‑assurance protection for modern PKI environments.

Thales TCT’s Luna T-Series HSMs—the first PQC enabled HSMs manufactured in the U.S. to receive FIPS 140-3 Level 3 validation.

Post‑Quantum Cryptography

Luna T‑Series HSMs support the government’s transition to post‑quantum cryptography mandated by CNSA 2.0 and EO 14412. With support for ML‑DSA, ML‑KEM, and LMS/HSS, they safeguard long‑lived and mission‑critical data against emerging quantum threats.

 

Crypto Agility

Luna T‑Series HSMs are crypto-agile and offer broad support for modern asymmetric and symmetric algorithms, hashing functions, and message authentication codes. A hardware‑based classical RNG and quantum RNG compliant with NIST SP 800‑90A/B ensure high‑quality entropy for secure key generation.

 

Compliance Forged in the USA

Luna T‑Series HSMs are FIPS 140‑3 Inside (5450 & 5300), CNSS‑approved for National Security Systems PKI, and fully designed, manufactured, and supported in the United States. All Luna T‑Series HSMs are built under a DCSA proxy and a CFIUS National Security Agreement to ensure trusted supply chain integrity.

 

Common Architecture

The entire Luna T‑Series HSM portfolio—Network, PCIe, Mini, Tablet, and the FedRAMP High Authorized Luna as a Service—shares a unified architecture. With consistent clients, APIs, algorithms, and authentication methods, applications only need to be integrated once. Keys can be cloned securely across devices and across environments, from on‑premises deployments to the cloud.

Why Choose Thales TCT’s Luna T-Series HSMs?

  • Made in the USA for trusted federal supply chain compliance
  • FIPS 140‑3 Inside and CNSS‑approved for National Security Systems
  • Post‑quantum ready with ML‑DSA, ML‑KEM, and LMS/HSS support
  • Quantum‑enhanced key generation via embedded QRNG
  • Broad crypto agility across modern algorithms
  • Unified architecture for consistent APIs and easy key migration
  • Flexible deployment from core to cloud to tactical edge
  • Out-of-the-box integrations with third party applications
  • Supports multiple apps on one HSM, scales easily, and clusters for high availability

Root of Trust Where You Need It

Luna T-Series HSM Platforms

Luna Network HSM

Network‑attached HSM for on‑prem, virtual, and cloud environments

Use Cases:

  • PKI
  • SSL/TLS
  • Code Signing
  • Certificate Signing & Validation
  • Document Signing
  • Transaction Processing
  • DB Encryption
  • Smart Card Issuance

Luna PCIe HSM

Embedded HSM for securing keys and accelerating cryptographic operations

Use Cases:

  • Securing custom applications

Luna Tablet HSM

USB HSM for offline storage of root keys

Use Cases:

  • Offline Root CAs
FedRAMPlogo_FINAL_2017

Luna as a Service

Cloud‑based HSM delivered through XTec’s FedRAMP High AuthentX Cloud

Use Cases:

  • Cloud Root of Trust; anchoring applications across multiple cloud providers

Luna Backup HSM

USB HSM for the backup high value cryptographic key material. Accessory to Luna T-Series Network, PCIe, and Tablet HSMs

Use Cases:

  • Backup and duplicate keys in case of emergency, failure or disaster