Third-party solutions

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant, standards-compliant cloud service that enables you to safeguard cryptographic keys for your cloud applications, using FIPS 140-2 Level 3 validated HSMs. Learn more.

Several vendors have worked closely with Microsoft to integrate their solutions with Managed HSM. The table below lists these solutions with a brief description (provided by vendor). Links to their Azure Marketplace offering and documentation are also provided.

Third-party solutions integrated with Managed HSM

Vendor name Solution description
Cloudflare Cloudflare’s Keyless SSL enables your websites to use Cloudflare’s SSL service while keeping custody of their private keys in Managed HSM. This service, coupled with Managed HSM helps a high level of protection by safeguarding your private keys, performing signing and encryption operations internally, providing access controls, and storing keys in a tamper-resistant FIPS 140-2 Level 3 HSM.
Documentation
NewNet Communication Technologies NewNet’s Secure Transaction Cloud(STC) is an Industry first Cloud based secure payment routing, switching, transport solution augmented with Cloud based virtualized HSM, handling Mobile, Web, In-Store payments. STC enables cloud transformation for payment entities & rapid deployment for green field payment providers.
Azure Marketplace offering
Documentation
PrimeKey EJBCA Enterprise, world's most used PKI (public key infrastructure), provides the basic security services for trusted identities and secure communication for any use case. A single instance of EJBCA Enterprise supports multiple CAs and levels to enable you to build complete infrastructure(s) for multiple use cases.
Azure Marketplace offering
Documentation
HashiCorp Vault HashiCorp Vault is an identity-based security solution that leverages trusted sources of identity to keep secrets and application data secure, including API keys, passwords, or certificates. HashiCorp Vaults must be unsealed with an unsealing key to provide access to data. Hardware-backed keys stored in Managed HSM can be used to automatically unseal a HashiCorp Vault and reduce the operational overhead associated with storing and serving this unsealing key.
Documentation

Next steps