808bits

X4i Hardware Security Module (HSM)

FIPS 140-2 certificate #3830 · Pitney Bowes, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS Mode.

Certificate

Certificate number3830
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentSingle Chip
VendorPitney Bowes, Inc. · website
Hardware versionsMAX32590 Secure Microcontroller Revision B4
Firmware versionsPB Bootloader Version 00.00.0016, HSM Application Version 21.02.000F [1] or 21.03.0001 [2], and Device Abstraction Layer (DAL) Version 01.02.0018 [1] or 01.02.0024 [2]

Module description

The X4i HSM is a single chip cryptographic module using the Maxim MAX32590 hardware. The central purpose of the module is as a physical computing device that safeguards and manages cryptographic keys and provides cryptographic services to connected host devices. The module uses a number of strong identity-based authentication mechanisms to provide authentication, integrity, and (when necessary) non-repudiation.

Approved algorithms

AlgorithmCAVP certificate
AES5954
CKGvendor affirmed
DRBGC472
DSAC475
ECDSAC476
HMACC464
KASvendor affirmed
KAS-SSCvendor affirmed
KDAvendor affirmed
KTS
KTS
RSAC477
SHSC295

Allowed algorithms

NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-02-26InitialPenumbra Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-02-26

Source documents