- Prevent Identity Theft
- Stop Espionage & Mass Surveillance
- Prevent Data Loss
Login to websites (e.g. Google, Facebook, Dropbox) using secure One Time Passwords (OTP), FIDO U2F or ordinary static passwords. Login to computers and network services (e.g. SSH) using certificates.
Encrypt your emails with GnuPG, OpenPGP, S/MIME or your favorite email client. Keep your secret keys secure on your Nitrokey.
Carry important data with you, hardware-encrypted on your Nitrokey Storage device (16-64 GB). Compatible with Windows, Linux and Mac OS.
Encrypt your hard disks and files using TrueCrypt/VeraCrypt, GnuPG Tools and more. Keep your secret keys secure on your Nitrokey.
Protect your server certificates by using up to 300 cryptographic keys with the Nitrokey HSM. Ideal for security servers, Public Key Infrastructures (PKI) and Certificate Authorities (CA).
Manage your servers, critical infrastructure, and Internet of Things (IoT) not just securely but also more easily. Administrators no longer require to synchronize key files between their desktops or remember complex passwords. Nitrokey acts as a mobile latch key to your servers by using Secure Shell (SSH), providing 2FA always at hand.
Protect emails, files, hard drives, server certificates and online accounts using cryptography. Your private keys are always stored securely in the Nitrokey hardware and can't be stolen. The device is PIN-protected and is secured against brute force and hardware attacks. Backups protect against loss.
Your secret keys are stored in the tamper-resistant and PIN-protected device and are secured against computer viruses, other malware, phishing, loss, theft and brute-force attacks.
Nitrokey is developed and produced in Germany, primarily in Berlin. For the sake of higher quality and security, we do not use cheap overseas manufacturing.
Both hardware and software are open-source, free software and allow independent security reviews. Customisable, no vendor lock-in, no security via obfuscation, no hidden security issues!
Unlike some competitors, Nitrokey contains a complete and standard compliant USB plug. This ensures thousands of insertions without connectivity issues.
Installed firmware can be exported and verified, preventing attackers from inserting backdoors into products during shipping. Nitrokey is open-source and free of backdoors. Secret keys are generated only by you and we have no access to your private information.
The only hardware solution with hidden encrypted storage. This allows you to plausibly deny the existence of encrypted data, for example during border controls.
Nitrokey uses open interfaces and open drivers to enable its easy integration with your personal requirements. Custom solution can be provided on request.
The Nitrokey hardware functions independently of any operating systems and protects your secret keys against theft, loss, user mistakes, phishing, brute-force attacks, computer viruses and other malware.
The sustainable development and production of Nitrokeys contributes to a sustainable environment and society.
|Nitrokey Storage 2||Nitrokey Pro 2||Nitrokey Start||Nitrokey HSM 2||Nitrokey FIDO U2F|
|Tamper-resistant smart card||✓||✓||✓|
|S/MIME email and hard disk encryption (X.509, PKCS#11)||✓||✓||✓||✓|
|OpenPGP/ GnuPG email encryption||✓||✓||✓|
|Secure login (One Time Passwords)||✓||✓|
|Encrypted mass storage||✓|
|Firmware updates and verification||✓||✓|
|RSA key length [bit]||2048 - 4096||2048 - 4096||2048**||1024 - 4096|
|Number of RSA key pairs||3*||3*||3*||38|
|ECC key length [bit]||256 - 521||256 - 521||256||192 - 521|
|Elliptic curves||NIST P, Brainpool||NIST P, Brainpool||NIST P, Curve25519, SECG/Koblitz||NIST P, Brainpool, SECG/Koblitz|
|Number of ECC key pairs||3*||3*||3*||300|
|PKI/CA management features||✓|
|Secure login (FIDO U2F)||✓|
|Factsheet||Nitrokey Storage 2||Nitrokey Pro 2||Nitrokey Start||Nitrokey HSM 2||Nitrokey FIDO U2F|
|Price||Starting from € 109.00||€ 49.00||€ 29.00||€ 59.00||€ 22.00|
* Stores the key pair (RSA or ECC, if available) for one person/identity only. Technically these are 3 key pairs because GnuPG uses subkeys.
** 4096 bit are supported but each operation takes ca. 8 seconds.