Vendor hubData-Centric · EDRM · DSPM · AI-DLPTechBag Intel Hub

Entrust

The India-origin data-centric security pioneer — protect the data itself, so protection travels with it wherever it goes, revocable even after sharing. EDRM, DSPM, AI-DLP and Classification, unified on the ARMOR platform, built for AI. This hub is your complete intel file.

4 intel pages insideData-centric, India-originIndia-ready via TechBag

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

Founded~2008 · Mumbai
OriginIIT Bombay-incubated
WhatData-centric pioneer
PlatformARMOR (built for AI)
Reach30+ countries

Quick answer

Entrust is a private American security company, headquartered in Shakopee, Minnesota, that sells hardware key custody, private PKI and identity verification. Its nShield hardware security modules are the direct peer to Thales's Luna, and for an Indian buyer they carry a differentiator no other candidate in this category has: nShield Connect XC holds Bureau of Indian Standards certification. If BIS certification appears in your procurement requirements — and for Indian government and several BFSI processes it does — that is a deciding fact rather than a preference, and it is the main reason to read this page before the Thales one. Two things about the company matter enough to state before any product detail, because both are recent and both are widely got wrong. The chief executive changed: Tony Ball became CEO on 31 March 2026, succeeding Todd Wilkinson after seventeen years. Wilkinson is still the answer most sources give, and it is wrong. And the portfolio is narrower than it was. Entrust sold its entire public TLS certificate business to Sectigo — announced January 2025, completed 18 September 2025 — after Chrome, Apple and Mozilla distrusted its roots from November 2024. It did not rescue that business; it exited it. So if you are here for public SSL certificates, Entrust is no longer the vendor, and we would rather tell you in the first paragraph than let you discover it three pages in. What remains is a coherent and genuinely strong portfolio: nShield HSMs, private PKI and certificate lifecycle management for the certificates inside your own estate, and Entrust Identity Verification, built on the Onfido acquisition completed in April 2024. On analyst standing we are going to be more careful than the vendor's own marketing. Gartner publishes no Magic Quadrant for hardware security modules or key management at all — only Market Guides, which have no Leader quadrant — so nobody in this category has a Gartner Leader placement. We could not verify an HSM or key-management Leader placement for Entrust with any analyst, and we are not going to imply one exists. Ownership is private, controlled through Datacard by Germany's Quandt family, with revenue around $917 million in 2024 and roughly 3,000 staff. There is live India engineering hiring in Bengaluru and Pune, though nShield as a Service has no India region — so the India answer here, as with Thales, is on-premises appliances with the keys in your own building. Read more ↓ Show less ↑
The portfolio

Twelve intel pages. One integrated platform.

The complete Entrust portfolio — every linked card is a full intel page, from follows-the-data EDRM protection to AI-layer data control.

BIS certifiedIntel page →

nShield HSM

The hardware key custody with an Indian certification.

A tamper-resistant appliance that generates and stores cryptographic keys and performs operations inside the device, so key material never leaves in usable form. What separates it from its direct competitor for an Indian buyer is procurement rather than cryptography: nShield Connect XC holds Bureau of Indian Standards certification, which Thales's Luna does not. If BIS appears in your tender requirements, that single fact decides the comparison. Entrust's Security World architecture manages keys across a group of HSMs, so resilience and disaster recovery are designed in rather than bolted on.

Keys never leave the deviceExplore
Private PKIIntel page →

Entrust PKI

The certificates inside your own estate.

Private certificate authority and PKI infrastructure for the certificates your own systems trust — machine identities, device certificates, internal TLS, code signing. Be clear about the scope, because the boundary moved in 2025: this is PRIVATE PKI, for certificates your organisation issues and trusts internally. Entrust sold its public TLS certificate business to Sectigo in September 2025, so publicly trusted SSL certificates for your website are no longer sold here. Private PKI is a different product with a different trust model, and it was not part of that sale.

Private CA — not public TLSExplore
Discover and renewIntel page →

Certificate Lifecycle Management

The certificates you forgot exist, found before they expire.

Discovery, inventory, automated renewal and revocation across the certificates scattered through a real estate — load balancers, internal services, appliances, the one somebody installed manually four years ago. Expired certificates cause a genuinely disproportionate share of unplanned outages, and the cause is almost never the cryptography; it is that nobody knew the certificate existed until it stopped working. Automation matters increasingly as certificate lifetimes shorten across the industry, since manual renewal does not scale as validity periods contract.

Automation, as lifetimes shortenExplore
Built on OnfidoIntel page →

Entrust Identity Verification

Proving a remote person is who they claim to be.

Document and biometric identity verification, built on Onfido, which Entrust acquired in April 2024. It answers the onboarding question — is this remote person genuinely who they say they are — rather than the authentication question of whether a returning user is the same person as last time. For Indian financial services this sits alongside rather than inside the regulated KYC process: verify what your own risk appetite requires, and be precise about which parts of an RBI-prescribed KYC obligation a vendor product can and cannot discharge. Get that boundary confirmed in writing before you scope it.

Onboarding, not authenticationExplore

Public TLS certificates

Platform & engine

SOLD to Sectigo, completed 18 Sept 2025 — Entrust no longer sells these

nShield as a Service

Platform & engine

Managed HSM — UK, US, Germany and Australia; no India region

Entrust is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide shows how the category splits and which part is yours. →

The thesis

Why “BIS certified” can end the evaluation

Most vendor comparisons are won on features and lost on price. This one is frequently decided before either, because nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not— and for Indian government tenders and several BFSI procurement processes, BIS is a gate rather than a scoring criterion. A product without it cannot be bought, however well it performs. So the single most useful thing you can establish is whether BIS appears in your requirements: if it does, the comparison against Thales is already settled; if it does not, the two are genuinely close and Thales carries the stronger verified analyst position. We would rather you find that out in one question than after three demos.

01
The India differentiator

BIS certification, which is a procurement fact not a preference

nShield Connect XC holds Bureau of Indian Standards certification. For Indian government tenders and several BFSI procurement processes, BIS is a gate rather than a scoring criterion — a product without it cannot be bought regardless of how well it performs. That makes this the single most useful thing to establish early, because if BIS is in your requirements the comparison against Thales is already settled, and if it is not then the two are genuinely close.

02
Key custody

Keys generated in hardware that never leaves your building

The core argument is the same one that justifies any HSM, and it is worth stating precisely. Software key management holds keys in memory on a host, and a sufficiently compromised host can yield them. Hardware removes that possibility by construction: the key is generated inside the appliance, used inside it, and never leaves in usable form. Compromising the server that calls the HSM buys an attacker the ability to request operations while that access lasts — not the key itself.

03
Architecture

Security World, so resilience is designed in

Entrust's Security World manages keys across a group of HSMs as one logical unit, which is how you get resilience, disaster recovery and key portability between appliances without hand-carrying key material. It is the concept anyone comparing nShield and Luna meets immediately, and it is the reason a second appliance at another site is an architectural decision rather than an awkward retrofit.

04
Scope

The portfolio is narrower than it was, and we will say so

Entrust sold its entire public TLS certificate business to Sectigo, completed 18 September 2025, after Chrome, Apple and Mozilla distrusted its roots from November 2024. It exited rather than rescued. If you arrived looking for publicly trusted SSL certificates, this is not the vendor any more. What remains — hardware key custody, private PKI, certificate lifecycle management and identity verification — is coherent and genuinely strong, and it is a smaller portfolio than Entrust had two years ago.

05
Recognition

Analyst standing, stated conservatively

We are being deliberately careful here. Gartner publishes no Magic Quadrant for hardware security modules or key management at all — only Market Guides, which have no Leader quadrant — so no vendor in this category has a Gartner Leader placement, whatever a datasheet implies. We could not independently verify an HSM or key-management Leader placement for Entrust with any analyst, and rather than repeat a vendor claim we could not check, we are telling you it is unverified. Thales carries the stronger verified position here, with two 2025 KuppingerCole Overall Leader awards.

Start with follows-the-data protection (EDRM) or your most acute need — discovery, AI data control or classification — then extend across the connected ARMOR platform.

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

India procurement

BIS certification

nShield Connect XC — Bureau of Indian Standards

India

Bengaluru & Pune

Live engineering hiring, including PKI security roles

April 2024

Onfido acquired

Now Entrust Identity Verification

Scale

~$917M revenue

2024, with roughly 3,000 staff

Ownership

Private, Quandt family

Via Datacard — not Thoma Bravo, a common error

March 2026

New CEO

Tony Ball, succeeding Todd Wilkinson after 17 years

September 2025

Exited public TLS

Sold to Sectigo after browser distrust

Analyst standing

Unverified

No HSM/key-management Leader placement confirmed

By the numbers

The company in six figures

$917M
Revenue, 2024
Entrust
~3,000 staff
Worldwide
Entrust
2026
Tony Ball became CEO, 31 March
Entrust newsroom
2025
Exited public TLS — sold to Sectigo, 18 Sept
Entrust
0 India SaaS regions
nShield as a Service is UK/US/DE/AU
Entrust docs
0 Gartner MQs
None exists for HSM or key management
Gartner

See the platform, hear the pitch

Entrust (official)·Hardware

Entrust nShield HSMs: On Another Level

The appliance, presented by Entrust.

Entrust (official)·Concept

What is a hardware security module (HSM)?

The category, explained.

Entrust (official)·PKI

What is Entrust PKI?

Private PKI, not public TLS.

The market maps

Where Entrust sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

Entrust Across Its Platform

Each dot is an Entrust product: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
nShield HSMEntrust

BIS certified — the India procurement fact.

Grid 02 · The industry

The MDR × Integration Map

Key custody vs the field — where hardware and a BIS certification decide it.

Niche data toolsBroad + data-centric platformPoint playersLocation-based only
EntrustEntrust

BIS certification; analyst standing unverified.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with Entrust?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What is driving this?

2. Does BIS certification appear in your procurement requirements?

3. Were you looking for public SSL certificates?

The acronym decoder

Every term on these pages, in one place
HSM
Hardware Security Module — a tamper-resistant appliance that generates and stores keys and performs operations inside the device, so key material never leaves in usable form.
BIS certification
Bureau of Indian Standards certification. For Indian government tenders and several BFSI processes it is a procurement gate rather than a scoring criterion. nShield Connect XC holds it.
Security World
Entrust's architecture for managing keys across a group of HSMs as one logical unit, so resilience and key portability are designed in rather than retrofitted.
Private PKI
A certificate authority your own organisation runs, issuing certificates your own systems trust. Distinct from public TLS, and not part of the Sectigo sale.
Public TLS
Publicly trusted SSL certificates for internet-facing sites. Entrust SOLD this business to Sectigo, completed 18 September 2025 — it is no longer an Entrust product.
Browser distrust
Chrome, Apple and Mozilla stopped trusting Entrust's public roots from November 2024 after compliance failures. The reason the certificate business was sold.
Certificate lifecycle management
Discovering, inventorying, renewing and revoking certificates across an estate — increasingly automation-dependent as industry certificate lifetimes shorten.
Onfido
The identity-verification company Entrust acquired in April 2024, now sold as Entrust Identity Verification.
Identity verification
Proving a remote person is who they claim at onboarding. Distinct from authentication, which checks a returning user is the same person as before.
Key custody
Who physically holds and controls the keys — the question a regulator is really asking when they ask about encryption.
Root of trust
The hardware or component everything else's security depends on. An HSM is the strongest commonly available one.
Gartner Market Guide
A Gartner format that describes a market WITHOUT ranking vendors. There is no Leader quadrant, which is why no HSM vendor can claim Gartner Leader status.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Establish whether BIS is a requirement or a preference

nShield Connect XC holds Bureau of Indian Standards certification. For Indian government tenders and several BFSI processes BIS is a gate rather than a scoring criterion, which means a product without it cannot be bought at all. Find out which you are dealing with first, because if it is a gate the vendor comparison is already over.

02

Separate public TLS from private PKI before you scope

Entrust sold its public certificate business to Sectigo in September 2025. If part of what you need is publicly trusted SSL for internet-facing sites, that is a different vendor now. Private PKI for internal certificates was not part of the sale and remains an Entrust product. Buyers routinely conflate them, and the distinction changes who you are buying from.

03

Decide whether hardware key custody is genuinely required

Software key management under your control is sufficient for many buyers. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded a compromised host must not yield key material. If none applies, you may be buying more than you need.

04

Plan Security World and the second appliance

Entrust's Security World manages keys across a group of HSMs, which is how resilience and disaster recovery work. If you want to survive a site failure you need more than one appliance, and it is far easier to design that in now than to retrofit it. Budget the second unit and the site it lives in.

05

Name the administrators and the approvers separately

Hardware key custody creates roles nobody previously had, and they should not be the same people. The person who administers the appliance should not also approve key use. Assign these during the project, because separation of duties retrofitted under delivery pressure tends to get waived.

06

Check the identity-verification regulatory boundary in writing

If you are scoping Entrust Identity Verification for Indian financial services, be precise about which parts of an RBI-prescribed KYC obligation a vendor product can discharge and which remain yours. Get that in writing before you build a process around it. TechBag obtains it as part of the quote.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
nShield HSMQuote-only — appliance purchase plus supportA physical device in your data centreWhere BIS certification is a procurement gate
Entrust PKIQuote-only — on-premises or PKI as a ServicePrivate certificate authorityCertificates your own systems trust
Certificate LifecycleQuote-onlyDiscovery, inventory and renewalEstates that have lost track of their certificates
Identity VerificationQuote-only — usage-basedDocument and biometric checksRemote onboarding, alongside regulated KYC

Per-user/device plus appliances and MDR service — TechBag models the mix (managed vs self-managed) for your size.

Five pitfalls that cost buyers quarters

1

Arriving for public SSL certificates

This is the most likely wasted evaluation. Entrust sold its entire public TLS certificate business to Sectigo, announced January 2025 and completed 18 September 2025, after Chrome, Apple and Mozilla distrusted its roots from November 2024. It exited rather than rescued. Plenty of documentation, blog posts and search results still describe Entrust as a public CA. They are out of date, and if publicly trusted certificates are what you need then Sectigo or another public CA is where to look.

2

Assuming the CEO is still Todd Wilkinson

Tony Ball became chief executive on 31 March 2026, after Wilkinson's seventeen years. Most secondary sources and AI summaries still name Wilkinson, and we flag it here because a board paper or vendor assessment naming the wrong CEO undermines everything around it. Verify current leadership against the vendor's own page rather than a search summary — this is a fact that goes stale quietly.

3

Treating an unverified analyst claim as a Leader placement

Gartner publishes no Magic Quadrant for hardware security modules or key management — only Market Guides, which have no Leader quadrant. So no HSM vendor has a Gartner Leader placement, whatever a datasheet implies. We could not independently verify an HSM or key-management Leader placement for Entrust with any analyst, and we would rather tell you it is unverified than repeat a claim we could not check. Thales carries the stronger verified position, with two 2025 KuppingerCole Overall Leader awards.

4

Budgeting the appliance and nothing around it

An HSM is a physical device with a support contract, firmware maintenance on a security-critical component, backup of the Security World, and separation-of-duties roles that did not previously exist. Resilience means a second appliance somewhere else. None of this is exotic and all of it is real, and it is almost never in a first budget built from a hardware quote.

5

Confusing identity verification with authentication

Identity verification proves a remote person is who they claim at onboarding. Authentication checks that a returning user is the same person as last time. They are different products solving different problems, and buying one expecting the other is a common and expensive mistake. Entrust sells both, so be explicit about which problem you are solving before the demo.

The evaluation kit

The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:

Skip the homework entirely

Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about Entrust

No, and this is the first thing to establish because it is the most likely reason an evaluation here is wasted. Entrust sold its entire public TLS certificate business to Sectigo — announced January 2025, completed 18 September 2025 — after Chrome, Apple and Mozilla distrusted its public roots from November 2024 following a series of compliance failures. It did not rescue the business, partner its way out, or retain a portion. It exited. If what you need is publicly trusted SSL for an internet-facing site, Entrust is no longer the vendor and you should look at Sectigo or another public CA. Be careful here, because a great deal of material still says otherwise: documentation, blog posts, comparison articles and search summaries continue to describe Entrust as a public certificate authority, and much of it is well-ranked. It is out of date. What Entrust does still sell, and sells well, is different: private PKI for the certificates your own organisation issues and your own systems trust, certificate lifecycle management for discovering and renewing certificates across your estate, nShield hardware security modules, and identity verification built on Onfido. Private PKI in particular is easy to confuse with public TLS because they share vocabulary, and it was not part of the sale. If your requirement is internal machine identities, device certificates or internal TLS, you are in the right place.

Ready to shortlist Entrust?

Open any of the twelve intel pages for the deep dive, or let a TechBag advisor build the case with you — MDR-vs-self-managed scoping, quotes, trials, GST invoicing and lifecycle support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.