Enterprise
RemoteHSM API
Remote access to a dedicated hardware security module through a secure API interface. Every customer has their own dedicated HSM card — with no need to procure and operate hardware of their own.
Cryptographic keys under trusted supervision
RemoteHSM API gives customers remote access to an HSM through a secure API interface — with no need for hardware of their own.
Benefits
Your own dedicated card
Every customer has their own HSM card, fully isolated from other customers.
Secure remote access
Access to cryptographic keys through a secure API interface, with no need for your own hardware.
Guaranteed integrity
HSM management is handled by the trust service provider, which guarantees the integrity of the entire solution.
Lower infrastructure demands
No need to procure, operate and certify your own hardware HSM.
Variants and management
Dedicated or shared
HSM infrastructure
The solution offers two HSM deployment variants, whose integrity is taken care of by the trust service provider.
Remote HSM
A single customer has their own dedicated HSM card with full isolation from other customers.
- Dedicated HSM card per customer
- Full isolation of data and keys
- Remote access through a secure API
Virtual HSM
A shared HSM intended for multiple customers, also available as a standalone product.
- Shared infrastructure for multiple customers
- Available as a standalone product
- Lower entry costs for deployment
Management and integrity
HSM management is handled by the trust service provider, which guarantees the integrity of the entire solution.
- Operated by a trust service provider
- Continuous integrity checks
- Compliance with qualified service requirements
Who the solution is for
Core infrastructure
for your signing services
RemoteHSM is deployed as a supporting layer for other 4SIGNERR products, and standalone for companies without their own HSM.
4SIGNER Portal
Remote access to signing keys directly in the Portal interface.
PKI API
Secure storage of key material for integrations via the PKI API.
Enterprise Archive
Protection of keys and certificates associated with archived documents.
Companies without their own HSM
Organisations that need a certified HSM without investing in hardware.
What RemoteHSM brings
to your company
From a lower workload to high legal certainty, without investing in hardware of your own.
Reduced workload
Relieves your team from operating and maintaining your own hardware HSM.
Lower hardware requirements
No need to purchase and certify your own HSM device.
Time and cost savings
Faster deployment of cryptographic services without investing in your own infrastructure.
High legal certainty
Cryptographic material managed in line with the requirements for qualified services.
Technical specifications
Secure access
and guaranteed integrity
Remote access
a secure API interface.
INCLUDES:
- Secure API interface
- Dedicated HSM card per customer
- Full isolation from other customers
Remote vs. Virtual HSM
Two deployment variants based on customer requirements.
INCLUDES:
- Remote HSM — dedicated card
- Virtual HSM — shared infrastructure
- Virtual HSM also as a standalone product
Management and integrity
Operation and integrity of the HSM are ensured by the trust service provider.
INCLUDES:
- Managed by a trust service provider
- Guaranteed integrity of the solution
- Integration with Portal, PKI API and Archive
Dedicated HSM card
A dedicated HSM card for each customer with full isolation.
Secure API
Remote access to cryptographic keys through a secure interface.
Managed by a trusted provider
The integrity of the entire solution is guaranteed by the trust service provider.
Optional Virtual HSM
A shared variant for multiple customers, also available standalone.
Integration
Deployment for Portal, PKI API and Enterprise Archive.
No hardware of your own
No need to procure and certify your own HSM device.
Trusted by companies
and institutions
Tatraleasing
Reduced workload, lower hardware requirements, time and cost savings, and high legal certainty.
Medante
Digital signatures for medical documentation and contracts, implemented within the existing MEDANTE system.
BVS
Digitalised communication, online forms and contracts, electronic signing through infrastructure or API.
What exactly is an HSM and what is it for?
An HSM (Hardware Security Module) is a specialised hardware device designed for generating, storing and using cryptographic keys. To maintain integrity, the HSM must be managed by a trust service provider.
What is the difference between Remote HSM and Virtual HSM?
Remote HSM means your own dedicated HSM card with full isolation from other customers. Virtual HSM is a shared HSM for multiple customers, also available as a standalone 4SIGNER product.
Who is responsible for HSM management and integrity?
HSM management is handled by the trust service provider, which guarantees the integrity of the entire solution — the customer does not have to deal with hardware operation or certification.
How does RemoteHSM integrate with other 4SIGNER products?
RemoteHSM provides remote access to keys for 4SIGNER Portal, PKI API and Enterprise Archive through a secure API interface.
Do I need my own hardware for deployment?
No. RemoteHSM API provides remote access to the HSM via API, so there is no need to procure or certify your own hardware device.
Still have questions?
Feel free to ask — we will gladly advise you on both selection and deployment.
Deploy RemoteHSM
in your architecture
We will prepare a quote and an integration proposal tailored to your environment — with no commitment.
Related solutions
Other modules
from the Enterprise ecosystem
Enterprise PKI API
Signing module without its own interface — embeddable directly into your applications.
PKI · Integration
Enterprise Archive
Local archiving of documents with issued certificates, integrable with any DMS.
Archive
Enterprise Web Signer
Signing · On-premise