The India-origin data-centric security pioneer — protect the data itself, so protection travels with it wherever it goes, revocable even after sharing. EDRM, DSPM, AI-DLP and Classification, unified on the ARMOR platform, built for AI. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
The complete Entrust portfolio — every linked card is a full intel page, from follows-the-data EDRM protection to AI-layer data control.
The hardware key custody with an Indian certification.
A tamper-resistant appliance that generates and stores cryptographic keys and performs operations inside the device, so key material never leaves in usable form. What separates it from its direct competitor for an Indian buyer is procurement rather than cryptography: nShield Connect XC holds Bureau of Indian Standards certification, which Thales's Luna does not. If BIS appears in your tender requirements, that single fact decides the comparison. Entrust's Security World architecture manages keys across a group of HSMs, so resilience and disaster recovery are designed in rather than bolted on.
The certificates inside your own estate.
Private certificate authority and PKI infrastructure for the certificates your own systems trust — machine identities, device certificates, internal TLS, code signing. Be clear about the scope, because the boundary moved in 2025: this is PRIVATE PKI, for certificates your organisation issues and trusts internally. Entrust sold its public TLS certificate business to Sectigo in September 2025, so publicly trusted SSL certificates for your website are no longer sold here. Private PKI is a different product with a different trust model, and it was not part of that sale.
The certificates you forgot exist, found before they expire.
Discovery, inventory, automated renewal and revocation across the certificates scattered through a real estate — load balancers, internal services, appliances, the one somebody installed manually four years ago. Expired certificates cause a genuinely disproportionate share of unplanned outages, and the cause is almost never the cryptography; it is that nobody knew the certificate existed until it stopped working. Automation matters increasingly as certificate lifetimes shorten across the industry, since manual renewal does not scale as validity periods contract.
Proving a remote person is who they claim to be.
Document and biometric identity verification, built on Onfido, which Entrust acquired in April 2024. It answers the onboarding question — is this remote person genuinely who they say they are — rather than the authentication question of whether a returning user is the same person as last time. For Indian financial services this sits alongside rather than inside the regulated KYC process: verify what your own risk appetite requires, and be precise about which parts of an RBI-prescribed KYC obligation a vendor product can and cannot discharge. Get that boundary confirmed in writing before you scope it.
SOLD to Sectigo, completed 18 Sept 2025 — Entrust no longer sells these
Managed HSM — UK, US, Germany and Australia; no India region
Entrust is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide shows how the category splits and which part is yours. →
Most vendor comparisons are won on features and lost on price. This one is frequently decided before either, because nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not— and for Indian government tenders and several BFSI procurement processes, BIS is a gate rather than a scoring criterion. A product without it cannot be bought, however well it performs. So the single most useful thing you can establish is whether BIS appears in your requirements: if it does, the comparison against Thales is already settled; if it does not, the two are genuinely close and Thales carries the stronger verified analyst position. We would rather you find that out in one question than after three demos.
nShield Connect XC holds Bureau of Indian Standards certification. For Indian government tenders and several BFSI procurement processes, BIS is a gate rather than a scoring criterion — a product without it cannot be bought regardless of how well it performs. That makes this the single most useful thing to establish early, because if BIS is in your requirements the comparison against Thales is already settled, and if it is not then the two are genuinely close.
The core argument is the same one that justifies any HSM, and it is worth stating precisely. Software key management holds keys in memory on a host, and a sufficiently compromised host can yield them. Hardware removes that possibility by construction: the key is generated inside the appliance, used inside it, and never leaves in usable form. Compromising the server that calls the HSM buys an attacker the ability to request operations while that access lasts — not the key itself.
Entrust's Security World manages keys across a group of HSMs as one logical unit, which is how you get resilience, disaster recovery and key portability between appliances without hand-carrying key material. It is the concept anyone comparing nShield and Luna meets immediately, and it is the reason a second appliance at another site is an architectural decision rather than an awkward retrofit.
Entrust sold its entire public TLS certificate business to Sectigo, completed 18 September 2025, after Chrome, Apple and Mozilla distrusted its roots from November 2024. It exited rather than rescued. If you arrived looking for publicly trusted SSL certificates, this is not the vendor any more. What remains — hardware key custody, private PKI, certificate lifecycle management and identity verification — is coherent and genuinely strong, and it is a smaller portfolio than Entrust had two years ago.
We are being deliberately careful here. Gartner publishes no Magic Quadrant for hardware security modules or key management at all — only Market Guides, which have no Leader quadrant — so no vendor in this category has a Gartner Leader placement, whatever a datasheet implies. We could not independently verify an HSM or key-management Leader placement for Entrust with any analyst, and rather than repeat a vendor claim we could not check, we are telling you it is unverified. Thales carries the stronger verified position here, with two 2025 KuppingerCole Overall Leader awards.
Start with follows-the-data protection (EDRM) or your most acute need — discovery, AI data control or classification — then extend across the connected ARMOR platform.
Every claim on this hub traces to one of these public signals.
nShield Connect XC — Bureau of Indian Standards
Live engineering hiring, including PKI security roles
Now Entrust Identity Verification
2024, with roughly 3,000 staff
Via Datacard — not Thoma Bravo, a common error
Tony Ball, succeeding Todd Wilkinson after 17 years
Sold to Sectigo after browser distrust
No HSM/key-management Leader placement confirmed
The appliance, presented by Entrust.
The category, explained.
Private PKI, not public TLS.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is an Entrust product: competitive position vs category momentum.
BIS certified — the India procurement fact.
Key custody vs the field — where hardware and a BIS certification decide it.
BIS certification; analyst standing unverified.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What is driving this?
2. Does BIS certification appear in your procurement requirements?
3. Were you looking for public SSL certificates?
If Bureau of Indian Standards certification is in your tender, the comparison against Thales is settled before features.
Read →It sold that business to Sectigo in September 2025 after browser distrust. What it does still sell, and what it does not.
Read →Two different trust models that share a word, and only one of them is still an Entrust product.
Read →Expired certificates cause a disproportionate share of outages, and the cause is never cryptography.
Read →What a regulator is actually asking when they ask about encryption, and what evidence answers it.
Read →Two credible hardware vendors. One has BIS, the other has the stronger verified analyst position.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
nShield Connect XC holds Bureau of Indian Standards certification. For Indian government tenders and several BFSI processes BIS is a gate rather than a scoring criterion, which means a product without it cannot be bought at all. Find out which you are dealing with first, because if it is a gate the vendor comparison is already over.
Entrust sold its public certificate business to Sectigo in September 2025. If part of what you need is publicly trusted SSL for internet-facing sites, that is a different vendor now. Private PKI for internal certificates was not part of the sale and remains an Entrust product. Buyers routinely conflate them, and the distinction changes who you are buying from.
Software key management under your control is sufficient for many buyers. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded a compromised host must not yield key material. If none applies, you may be buying more than you need.
Entrust's Security World manages keys across a group of HSMs, which is how resilience and disaster recovery work. If you want to survive a site failure you need more than one appliance, and it is far easier to design that in now than to retrofit it. Budget the second unit and the site it lives in.
Hardware key custody creates roles nobody previously had, and they should not be the same people. The person who administers the appliance should not also approve key use. Assign these during the project, because separation of duties retrofitted under delivery pressure tends to get waived.
If you are scoping Entrust Identity Verification for Indian financial services, be precise about which parts of an RBI-prescribed KYC obligation a vendor product can discharge and which remain yours. Get that in writing before you build a process around it. TechBag obtains it as part of the quote.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| nShield HSM | Quote-only — appliance purchase plus support | A physical device in your data centre | Where BIS certification is a procurement gate |
| Entrust PKI | Quote-only — on-premises or PKI as a Service | Private certificate authority | Certificates your own systems trust |
| Certificate Lifecycle | Quote-only | Discovery, inventory and renewal | Estates that have lost track of their certificates |
| Identity Verification | Quote-only — usage-based | Document and biometric checks | Remote onboarding, alongside regulated KYC |
Per-user/device plus appliances and MDR service — TechBag models the mix (managed vs self-managed) for your size.
This is the most likely wasted evaluation. Entrust sold its entire public TLS certificate business to Sectigo, announced January 2025 and completed 18 September 2025, after Chrome, Apple and Mozilla distrusted its roots from November 2024. It exited rather than rescued. Plenty of documentation, blog posts and search results still describe Entrust as a public CA. They are out of date, and if publicly trusted certificates are what you need then Sectigo or another public CA is where to look.
Tony Ball became chief executive on 31 March 2026, after Wilkinson's seventeen years. Most secondary sources and AI summaries still name Wilkinson, and we flag it here because a board paper or vendor assessment naming the wrong CEO undermines everything around it. Verify current leadership against the vendor's own page rather than a search summary — this is a fact that goes stale quietly.
Gartner publishes no Magic Quadrant for hardware security modules or key management — only Market Guides, which have no Leader quadrant. So no HSM vendor has a Gartner Leader placement, whatever a datasheet implies. We could not independently verify an HSM or key-management Leader placement for Entrust with any analyst, and we would rather tell you it is unverified than repeat a claim we could not check. Thales carries the stronger verified position, with two 2025 KuppingerCole Overall Leader awards.
An HSM is a physical device with a support contract, firmware maintenance on a security-critical component, backup of the Security World, and separation-of-duties roles that did not previously exist. Resilience means a second appliance somewhere else. None of this is exotic and all of it is real, and it is almost never in a first budget built from a hardware quote.
Identity verification proves a remote person is who they claim at onboarding. Authentication checks that a returning user is the same person as last time. They are different products solving different problems, and buying one expecting the other is a common and expensive mistake. Entrust sells both, so be explicit about which problem you are solving before the demo.
The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Six trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*Directionally consistent with public analyst forecasts; verify exact figures before quoting. The takeaway: AI data security and DSPM compound fastest — exactly where Seclore (data-centric, built for AI, India-origin) is placed.
Indian tenders increasingly require certifications like BIS rather than treating them as scoring criteria.
What it means for you
A product without the certification cannot be bought at all, which reshapes shortlists before any technical evaluation.
Validity periods keep contracting, and manual renewal does not scale as they do.
What it means for you
Certificate lifecycle automation moves from a convenience to an operational necessity.
HSMs bought today will still be in service when post-quantum algorithms are mandated.
What it means for you
Crypto-agility and a credible firmware path become purchase criteria rather than roadmap conversations.
Workloads, services and devices now vastly outnumber human users in any modern estate.
What it means for you
Private PKI and certificate automation matter more than the headcount-based sizing most organisations still use.
Regulators are looking harder at how remote identity is established, particularly in financial services.
What it means for you
Identity verification gets bought, and the boundary between vendor capability and regulated obligation gets tested.
Entrust's roots were distrusted by major browsers in 2024, ending a long-established certificate business.
What it means for you
Buyers are treating public CA relationships as replaceable, and paying more attention to private PKI they control.
Open any of the twelve intel pages for the deep dive, or let a TechBag advisor build the case with you — MDR-vs-self-managed scoping, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.