Listing Thumbnail

    Data Security Accelerator for Banking, Finance and Insurance

     Info
    Serverless CloudHSM encryption and automated secrets rotation built for banks, insurers, and financial institutions protecting customer data.

    Overview

    VigourSoft implements a serverless CloudHSM-on-Lambda pattern for encryption, decryption, and digital-signing workloads that protect customer, account, and claims data with FIPS 140-2 Level 3 validated HSM-held keys, packaged as a Lambda layer with Secrets Manager–backed Crypto User credentials. We pair this with automated Secrets Manager rotation Lambdas covering RDS, ElastiCache, Active Directory, and SSH key credentials, so every secret in scope rotates on a compliance-driven schedule with a full CloudWatch and CloudTrail audit trail. This is built to help banks, insurers, and lenders meet NAIC Insurance Data Security Model Law, HIPAA, GLBA, and state regulatory requirements, and we validate current CloudHSM SDK guidance (SDK5) before any customer delivery.

    Scope of Work:

    • Compliance scoping workshop mapping encryption and rotation controls to NAIC Insurance Data Security Model Law, HIPAA, GLBA, and applicable state requirements
    • VPC and CloudHSM cluster readiness review (private subnets, NAT gateway, HSM ENIs)
    • Lambda layer build for the CloudHSM client, Java JCE library, and required dependencies
    • IAM role, Secrets Manager secret, and resource-based policy configuration for CU credentials
    • Deployment of Secrets Manager rotation Lambdas for customer, account, and claims data stores
    • End-to-end rotation testing (createSecret / setSecret / testSecret / finishSecret) and CloudWatch and CloudTrail validation

    Deliverables:

    • Published CloudHSM Lambda layer and sample encryption/decryption/signing functions
    • Configured Secrets Manager rotation schedules for in-scope credential types
    • IAM and resource-policy documentation scoped to least privilege
    • Compliance mapping document tying encryption and rotation controls to NAIC, HIPAA, GLBA, and state requirements
    • Operational runbook for key rotation, incident response, and SDK version tracking

    Target Audience: Banks, insurance carriers, MGAs, TPAs, and lending institutions that must protect customer, account, claims, and medical-record data with strict, auditable key management and credential rotation, while meeting NAIC, HIPAA, GLBA, and state regulatory requirements.

    Outcome Summary: The customer ends up with serverless, HSM-backed crypto operations running on Lambda and a set of secrets that rotate automatically on schedule. This protects customer, account, and claims data with no manual key handling, a documented rotation runbook, and CloudWatch and CloudTrail logs that support auditors and regulators.

    Highlights

    • Serverless CloudHSM crypto operations with no persistent EC2 instance to manage
    • Automated credential rotation across RDS, ElastiCache, Active Directory, and SSH, sized for customer and account data stores
    • Built to help banks, insurers, and lenders meet NAIC, HIPAA, GLBA, and state data security requirements

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Vendor support

    • support@vigoursoft.com 
    • +1-408-558-3600
    • Please email or call the above for any support requests and our team will help resolve your issues and queries.