Fortanix Data Security Manager is three security products in one - Key Management, Tokenization, and Secrets Management solution. Through this integrated approach, Fortanix Data Security Manager protects your sensitive information throughout the customer's journey to the cloud.
As you shift your applications to new infrastructures, you need a solution that can protect all your data on-premises as well as in the cloud. Fortanix Data Security Manager is a unified Key Management, Tokenization, and Secrets management solution. Fortanix protects sensitive data across public, hybrid, multi-cloud, and private cloud environments with a single point of management and control. Our customers can securely operate even the most sensitive applications in any environment. Additionally, AWS cluster of Fortanix Data Security Manager can be connected seamlessly to an on-premises cluster of Fortanix Data Security Manager or other 3rd party legacy HSMs as well as AWS CloudHSM to achieve FIPS 140-2 Level 3 HSM security with software-defined simplicity.
INSTANT VALUE: Quick time to value with rapid deployment, simplified operations, and centralized management
SCALE ON-DEMAND: Scale as you need to support millions of clients and billions of transactions with automated load-balancing and high availability
The below pricing is for base package only. Base package includes:
Features: Key Management, Application Encryption, Secrets Management, Transparent Data Encryption, Secure Business Login, Standard Support.
Constraint: 5 Apps/Cluster
UNMATCHED SECURITY - Ensures that you remain in complete control over your keys and secrets. It offers unified key management, HSM, tokenization, secrets management capabilities, with all the operational simplicity of a single solution.
SOFWARE-DEFINED SIMPLICITY: Centralized web UI for all crypto-operations with enterprise-level access controls, SSO, and comprehensive auditing. Offers restful APIs and interfaces such as KMIP, PKCS#11, JCE, CAPI, and more for easy integration.
CLOUD SCALABILITY: Built to scale horizontally and geographically as your demand for managing your keys and secrets increases while providing automated load-balancing, disaster recovery, and high availability.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the compute instance size you run. The three options are EC2 instance types that differ in capacity: m5.2xlarge, m5.4xlarge, and m5.8xlarge. Each larger instance size adds more compute resources to handle higher transaction volumes. You choose the instance that matches your workload and scale up or down as needs change. Billing is usage-based, so your cost reflects the hours each instance runs. All three deliver the same data security and key management platform; only the underlying capacity differs.
Top-of-mind questions for buyers
What do the m5.2xlarge, m5.4xlarge, and m5.8xlarge instance sizes mean for capacity?
Each name is an EC2 compute instance size. The m5.4xlarge doubles the compute resources of the m5.2xlarge, and the m5.8xlarge doubles them again. Larger sizes handle higher transaction volumes and encryption throughput. You pick the size that matches your cryptographic workload.
Am I charged when an instance is stopped or powered off?
Hourly charges apply only while an instance runs. A fully stopped instance stops accruing software hours. Note that underlying AWS storage or other resource fees may still apply separately even when the software meter is paused.
Do all three instance sizes include the same key management and encryption features?
Yes. Every size runs the same Data Security Manager platform, including key lifecycle management, integrated HSM functions, tokenization, and secrets management. Only the compute capacity differs. You scale by choosing a larger instance, not by unlocking extra features.
www.fortanix.com+1
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel anytime.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Use this template to quickly setup a minimum 3 node cluster across all 3 AZs. Upon launch, this stack will create 3 EC2 instances in an autoscaling group (manual scaling policy)
with 512GiB EBS gp2 storage on each node. In addition, security group will be created with inbound rules to allow traffic on 443, 4445, 5696 ports from outside via Load balancer. For inter-node connectivity, all ports are open.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Unified key management with centralized control over cryptographic keys and secrets across public, hybrid, multi-cloud, and private cloud environments
Tokenization and Secrets Management
Integrated tokenization and secrets management capabilities for protecting sensitive data throughout the application lifecycle
HSM Security Integration
Support for FIPS 140-2 Level 3 HSM security with capability to connect AWS cluster to on-premises clusters, AWS CloudHSM, and third-party legacy HSMs
API and Protocol Support
Multiple integration interfaces including RESTful APIs, KMIP, PKCS#11, JCE, and CAPI for seamless application integration
Horizontal Scalability and High Availability
Horizontal and geographic scaling with automated load-balancing, disaster recovery, and high availability to support millions of clients and billions of transactions
Secrets Management and Rotation
Centrally manages and rotates credentials across hybrid and multi-cloud environments with automated lifecycle management
Privileged Access Management
Provides just-in-time, least-privilege access with intent-aware control that evaluates requested actions before granting access and issues task-scoped, short-lived credentials
Multi-Vault Governance
Unifies visibility and control across AWS and third-party vaults through a single policy and audit framework
Cryptographic Security
FIPS 140-3 validated platform powered by Distributed Fragments Cryptography (DFC) and zero-knowledge architecture that ensures encryption keys and secrets are never fully assembled or accessible
AI Agent Identity Security
Secures autonomous agents with ephemeral, policy-bound access without embedding credentials in code, prompts, or workflows, with continuous execution inspection and audit trails
Key Lifecycle Management
Supports comprehensive key and certificate lifecycle management including key storage, generation, rotation, distribution, and usage policies.
Cryptographic Algorithm Support
Implements FIPS 140-3 validated encryption libraries, Covercrypt for post-quantum resistance with access policy support, and Findex for search encryption capabilities.
Public Key Infrastructure Integration
Provides seamless integration with external Public Key Infrastructure systems for managing keys and certificates beyond organizational boundaries.
On-the-Fly Encryption and Decryption
Delivers real-time encryption and decryption key operations for protecting sensitive data including workspace, research and development data, HR information, and electronic communications.
Fortanix has separated encryption keys from hardware, it has provided me with something that the traditional key management solutions do not have – flexibility and portability. This has been very useful in facilitating Cloud Migration strategy for our organization.
What do you dislike about the product?
Managing many encryption devices, configuring them and monitoring can be strenuous, and especially in large organizational networks.
What problems is the product solving and how is that benefiting you?
Fortanix is protecting information in a complicated hybrid IT world. The data-centric approach also frees us from the constraints of having to rely on hardware and being locked into a specific vendor for encryption.
Rafael R.
Management solution for data centric security
Reviewed on Sep 04, 2024
Review provided by G2
What do you like best about the product?
I found it interesting that Fortanix has a data-centric approach. This flexibility helps to rationalise the management of security operations and some of the principal lifecycle aspects in multi-Cloud and hybrid environments.
What do you dislike about the product?
I require more information on how those keys are being utilized in other applications and in various settings. They do not offer much in terms of granular visibility into the service, which is vital for troubleshooting and identifying possible security threats.
What problems is the product solving and how is that benefiting you?
Fortanix has boosted my organization’s encryption capabilities. It also makes sure that we have a similar level of security when our data is stored in different locations. The single key management also helps to avoid some problems in work because administrative functions are carried out quickly.