Contact
All of the portfolioProcenne
Data and cryptography

Procenne

Procenne builds the hardware that keeps cryptographic keys out of software, certified to the standards tender documents name.

The alternative

Thales Luna, Entrust nShield and Utimaco. These are the names a tender usually lists.

At a glance

Products
ProCrypt HSM, CryptAway, SignAway, Procenne Cloud HSM
Models
ProCrypt KM-X Performance, ProCrypt KM-X Premium
Standards
Common Criteria EAL4+, PCI HSM v3.0, PCI HSM 4.x
Signature standards
XAdES, PAdES, CAdES
Deployment
On-premise, cloud and hybrid
The question on a tender is not whether you encrypt. It is where the key lives, which authority certified the device it lives in, and who can be compelled to produce it.

Start with the certificates, because in this category they are the entry condition rather than a credential. Common Criteria and PCI HSM are written into tender documents by name and by level, and a product without them is not evaluated, whatever it does. ProCrypt holds Common Criteria EAL4+, and the KM-X Performance and KM-X Premium models were certified to PCI HSM 4.x at the start of 2024, having held PCI HSM v3.0 since 2021.

The second difference is supplier choice. A buyer who needs a supplier outside the usual list has often had to choose between certification and choice. Procenne is certified to the same standards the tenders name, which turns a sovereignty conversation into a procurement one. That distinction matters. The argument is not about where a product should come from. It is that a buyer with a supplier constraint now has an option that still clears the bar.

The third difference is what happens when the buyer already owns hardware. CryptAway runs a cluster across devices from more than one manufacturer, so adding capacity does not mean replacing what is installed, and key operations keep running while it happens. That changes the size of the first order. Nobody has to retire an appliance to buy one.

How it works

  • Keys are generated inside the device and never leave it
  • Encryption, decryption and signing are performed in hardware
  • Tamper-evident and tamper-resistant construction
  • A gateway clusters devices from more than one manufacturer behind one interface
  • Signing runs to the XAdES, PAdES and CAdES standards
  • Serves on-premise, cloud and hybrid estates

Who it is for

  • Banking and payment infrastructure
  • Public sector and defence programmes
  • Certificate authorities and electronic signature infrastructure
  • Any buyer with a key custody requirement they have to evidence

Where it sits

Data and cryptography. Email and file encryption is a different problem with the same word attached, and sits with BeamSec in the human layer.

Talk to us about ProcenneVendor site