Does anyone know what HSM manufacturer AWS use for their Payment Cryptography service?
The main reason I want to know this is because the company I work for currently uses Thales payShield 9K HSMs and we’re looking to upgrade to the newer/supported 10K model. Due to various unknowns, we’d prefer to go with a HSMaaS offering with consumption-based billing (rather than building out another on-prem HSM estate, which can be quite expensive). If AWS use Thales payShields under the hood or a HSM manufacturer that’s compatible with the Thales payShield commands (which I believe a lot of the alternate manufacturers are) then we might just be able to use AWS Payment Cryptography.
FWIW., I know Azure Payment HSMs do use Thales payShield 10Ks under the hood, but we’re mostly in AWS and there’d be a bit of networking to configure internal routing from AWS to the Payment HSMs service in Azure. We might end up going in this direction if the HSM manufacturer for AWS Payment Cryptography is incompatible with the Thales payShield commands, but just checking out the AWS service first.