Secrets Vault · Dedicated HSM upgrade
Single-tenant HSM custody, sold by the month.
Tessarac's standard Secrets Vault is FIPS 140-3 Level 3 hardware-backed key management by default for everyone — and already meets every compliance framework we attest to (SOC 2 Type II, FedRAMP Moderate & High, HIPAA, PCI DSS, ISO 27001, SOC 1, DoD IL2/IL4/IL5). The dedicated HSM upgrade is for the small subset of customers (~2%) whose contracts require single-tenant cryptographic custody — or who simply want the additional isolation as a preference.
Monthly cluster pricing
You choose the cluster size based on your throughput, HA, and multi-region needs. Billed monthly with partial-month proration on enroll/decommission. The general formula isN × $1,500 − $1for commercial andN × $2,000 − $1for government, so any cluster size lands on a clean .99 ending.
| Cluster size | Use case | Commercial $/mo | Government $/mo |
|---|---|---|---|
| 1 HSM | dev/test (no HA) | $1,499 | $1,999 |
| 2 HSMs | active/standby | $2,999 | $3,999 |
| 3 HSMsRecommended | production HA | $4,499 | $5,999 |
| 5 HSMs | high-throughput production | $7,499 | $9,999 |
| 10 HSMs | enterprise multi-region | $14,999 | $19,999 |
Government pricing applies to sovereign US-only deployments. The $500/HSM/mo government premium reflects higher operational support overhead in regulated regions. Custom cluster sizes (4, 6, 7, 8, 9 HSMs and beyond) follow the same formula — contact sales for a quote.
Do you actually need a dedicated HSM?
Most customers do not. Our standard key-management infrastructure is FIPS 140-3 Level 3 hardware-backed and already meets every compliance framework we attest to:
- ✓ SOC 2 Type II
- ✓ SOC 1
- ✓ ISO 27001
- ✓ HIPAA
- ✓ PCI DSS v4
- ✓ FedRAMP Moderate
- ✓ FedRAMP High
- ✓ DoD IL2 / IL4 / IL5
There is no security advantage to a dedicated HSM if your compliance requirements are already met by our standard offering. Our default vault satisfies every framework in the list above using FIPS 140-3 Level 3 validated hardware. Choose dedicated HSM only if one of the two narrow situations below applies to you.
Reason 1 — contractual requirement
You have a contractual or regulatory clause that mandates a single-tenant HSM dedicated to your organization.
A small subset of customer agreements (some financial-services contracts, certain federal sub-contractor flowdown clauses, specific large-enterprise security policies, and a few sovereignty frameworks) explicitly require that the HSM holding cryptographic root-of-trust material be physically dedicated to your organization — not shared with any other customer. If your contract or regulator requires that, the dedicated HSM upgrade gives you the audit artifact you need.
Reason 2 — preference for additional isolation
You simply want the additional isolation, even though your compliance requirements are already met.
Some customers prefer the additional isolation of a single-tenant HSM cluster as a defense-in-depth measure or organizational preference, even when no contract or regulation requires it. That preference is legitimate and we are happy to ship it. Just be clear that you are paying for isolation as a preference, not for a higher security or compliance posture — the standard offering already covers every framework we attest to.
How provisioning works
Dedicated HSM is “contact sales” only — not self-serve through the customer portal. Once you sign the order, our team triggers a fully automated provisioning flow. End-to-end provisioning takes about 15-25 minutes.
- 1
Network setup
Isolated network + subnet + security group provisioned in your dedicated boundary.
- 2
Cluster create
Dedicated single-tenant HSM cluster created and tagged with your customer ID + tier.
- 3
HSM activation
Customer-chosen number of HSMs initialized; quorum-based crypto officer ceremony.
- 4
Custom key store
Your dedicated HSM cluster is wired into the Tessarac key-management API; existing API surface preserved.
- 5
Vault cutover
Your customer wrapping-key alias is updated to the dedicated HSM-backed key. Monthly billing starts (prorated for the partial month).
Provisioning is fully audited, hash-chained, and visible in your billing dashboard. The same teardown flow runs in reverse on offboarding — with key-deletion confirmation and a 7-30 day waiting period before the cluster is permanently destroyed.
Common questions
Do I need this for FedRAMP High or DoD IL5?
No. Our standard Secrets Vault is FedRAMP Moderate + High authorized and DoD IL2/IL4/IL5 authorized, and it uses FIPS 140-3 Level 3 validated hardware-backed key management. FedRAMP control SC-13 requires “FIPS-validated cryptography,” and the standard offering satisfies that requirement at every baseline. Dedicated HSM is only needed when your contract specifically requires single-tenant HSM custody — a separate requirement from FedRAMP/FIPS.
What's the FIPS level on dedicated HSM vs the default vault?
Both are FIPS 140-3 Level 3. The dedicated HSM upgrade does NOT change the FIPS level — it changes the tenancy model. Same hardware certification, different operational boundary.
Why is government pricing higher than commercial?
Sovereign US-only deployments carry higher operational support costs (FedRAMP Continuous Monitoring, ITAR-cleared support staff, agency-specific audit response), and federal procurement timelines are slower so we carry the cost of the cluster through longer onboarding. The $500/HSM/month government premium ($2,000 vs $1,500) reflects that real overhead.
How is this billed?
One settlement event per cluster per month, on the 1st of the month for the just-completed month. Partial-month enrollment / decommission is prorated to the second so you only pay for the time the cluster was actually live. Wire-only invoicing for government deployments.
Can I add or remove HSMs later?
Yes. Cluster scale-up is a single API call to your account team or via the customer portal once you're set up. Scale-down requires a 7-day notice to ensure key migration completes safely. The new HSM count rolls into the next month's settlement at the higher tier from the day of the scale event (prorated to the day).
What happens to my secrets if an HSM in the cluster fails?
We strongly recommend the 3-HSM production HA tier (or larger). With 3 HSMs the cluster tolerates a single HSM failure with zero downtime, and the failed HSM is auto-replaced. With 1 or 2 HSMs you accept higher risk in exchange for lower cost — suitable for dev/test only.
Ready to discuss a dedicated HSM?
Tell us your throughput, region, HA requirements, and any contract clauses driving the request — our team will spec the right cluster size and walk you through the order.