Amazon CloudHSM logo

Amazon CloudHSM

AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to manage cryptographic keys on dedicated FIPS 140-2 Level 3 validated, single-tenant HSM instances running within your own VPC for regulatory compliance and data security.

1 APIs 1 Capabilities 5 Features
AWSCloudHSMSecurityCryptographyHSMCompliance

APIs

Amazon CloudHSM API

API for creating and managing CloudHSM clusters and HSM instances for dedicated hardware-based cryptographic key management.

Capabilities

Amazon CloudHSM Cryptographic Key Management

Workflow for cryptographic key management using Amazon CloudHSM for Security Engineer personas.

Run with Naftiko

Features

FIPS 140-2 Level 3 Validated

Dedicated single-tenant HSM instances meeting the highest FIPS validation levels.

Full Key Control

Complete control over cryptographic keys with no AWS access to key material.

Elastic Capacity

Add or remove HSMs from clusters as needed, paying only for active resources hourly.

High Availability

Multi-AZ HSM clusters provide redundancy and automatic failover.

Industry-Standard APIs

Supports PKCS#11, Java JCE, and Microsoft CNG APIs for application integration.

Use Cases

Data Encryption

Protect sensitive data with hardware-backed encryption keys.

SSL/TLS Offloading

Manage SSL/TLS certificates and private keys in dedicated HSMs.

Certificate Authority

Secure private CA keys for organizations issuing their own certificates.

Database Encryption

Support transparent data encryption (TDE) for Oracle and SQL Server databases.

Regulatory Compliance

Meet PCI DSS, HIPAA, and other regulatory requirements for key management.

Integrations

Amazon RDS

Use CloudHSM keys for Oracle TDE and SQL Server TDE in RDS.

AWS KMS

Use CloudHSM as a custom key store for AWS KMS operations.

Amazon VPC

HSM instances run inside your VPC for network isolation.

AWS IAM

Control access to HSM cluster management operations.

AWS CloudTrail

Audit HSM management API calls via CloudTrail.

API Governance Rules

Amazon CloudHSM API Rules

19 rules · 12 errors 6 warnings 1 info

SPECTRAL

Resources

🌐
Portal
Portal
🔗
Website
Website
🔗
Documentation
Documentation
📜
TermsOfService
TermsOfService
📜
PrivacyPolicy
PrivacyPolicy
💬
Support
Support
📰
Blog
Blog
👥
GitHubOrganization
GitHubOrganization
🌐
Console
Console
📝
SignUp
SignUp
🟢
StatusPage
StatusPage
👥
YouTube
YouTube
👥
StackOverflow
StackOverflow
🔗
Contact
Contact
🔗
Compliance
Compliance
🔗
SpectralRules
SpectralRules
🔗
Vocabulary
Vocabulary
🔗
NaftikoCapability
NaftikoCapability