Talk to us
by EntrustTechBag Intel Page

Entrust Identity Verification

Proving a remote person is who they claim to be — document and biometric verification built on Onfido, acquired April 2024. Note the boundary that costs the most: this is verification, not authentication. in prompts before it reaches ChatGPT or Copilot, and control it in AI responses — so employees use AI without leaking data.

Built on OnfidoOnboarding, not authenticationCheck the RBI KYC boundary

Data residency & processing — two different questions

Where data lives

Yours — on-premises appliances in India

nShield HSMs are physical appliances in your own data centre, and private PKI can run on-premises too. Keys are generated and held in hardware you own, in India, under your administrators — the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India region for the managed service

nShield as a Service runs in the UK, US, Germany and Australia. Entrust has live engineering hiring in Bengaluru and Pune, and that is people in India, not data in India — treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer the answer is appliances you operate, which is very likely what your regulator wanted anyway. Note what does not exist so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant — and we could not verify an HSM Leader placement for Entrust with any analyst. A search caution specific to this vendor: “Entrust India” surfaces several unrelated companies, including a Bengaluru wealth manager, so check you are reading about Entrust Corporation before drawing conclusions.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Scope
not authentication — different problem
Onboarding
Technology
well regarded, acquired April 2024
Onfido
India KYC
a component, not a discharge of the obligation
Get the boundary in writing
Pricing
quote-only
Usage-based

Quick answer

Entrust Identity Verification is document and biometric verification built on Onfido, which Entrust acquired in April 2024. It answers the onboarding question — is this remote person genuinely who they claim to be — by checking an identity document and matching a live capture against it. Start with the distinction that causes the most expensive misunderstandings in this category: identity verification is not authentication. Verification establishes who somebody is the first time, at onboarding. Authentication confirms that a returning user is the same person as before. They are different products solving different problems, and buying one while expecting the other is common enough that we raise it unprompted. Entrust sells both, so be explicit about which problem you are solving before the demo. For Indian financial services there is a second boundary that matters more, and we will be direct rather than comfortable about it. Remote customer onboarding in regulated Indian financial services operates inside a framework RBI prescribes, and a vendor verification product is a component within that framework rather than a discharge of it. What a product can do technically and what satisfies a regulated KYC obligation are different questions, and the gap between them is where compliance problems live. Establish precisely which parts of your obligation this can serve, in writing, before you design a process around it — TechBag obtains that as part of the quote. Used within its proper scope it is genuinely strong, and the Onfido technology behind it is well regarded. Read more ↓ Show less ↑
Part 01 · Orient

The Seclore platform family

This page covers Entrust Identity Verification — the AI-control layer. The rest of the Seclore ARMOR platform:

Quick facts

30-second orientation
Product
Entrust Identity Verification
Built on
Onfido — acquired by Entrust, April 2024
What it answers
Onboarding: is this remote person who they claim?
What it is NOT
Authentication — that is a different product
Vendor
Entrust — CEO Tony Ball, from 31 March 2026
Note
Todd Wilkinson is the STALE answer — 17 years, retired
Ownership
Private, via Datacard — Germany's Quandt family
Exited Sept 2025
Public TLS certificates — sold to Sectigo
Gartner
No MQ exists for HSM or key management — Market Guides only
Analyst standing
No HSM/key-management Leader placement verified
India engineering
Live hiring in Bengaluru and Pune
Data residency
On-premises; nShield as a Service has no India region
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, BIS scoping
Part 02 · Learn

Understand AI data loss prevention before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Document and biometric verification built on Onfido — checking an identity document and matching a live capture against it to establish who a remote person is.

AI leaking data vs controlled AI usage — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailIdentity Verification
Data pasted into AILeaks, unseenTokenised/masked/blocked
Traditional DLP + AIBlind to the AI layerControls prompts & responses
Copilot over-exposureAI surfaces sensitive dataResponse control
The AI dilemmaBan (lose value) or allow (risk)Enable safely
Shadow AIInvisible leakageSurfaced & controlled
Protection directionOne-way at bestBi-directional
AI usage visibilityNoneSeen & audited
DPDP + AIPersonal data leaks to AIControlled & evidenced

AI-DLP enables safe AI adoption — control the data, not the tool. Bi-directional control addresses both leakage IN and Copilot over-exposure OUT. It's a new category; TechBag positions it. Seclore is India-origin.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The visibility

Inspect at AI Layer

See prompts & responses

Inspect data at the AI interaction point — the prompts employees send to AI and the responses coming back — the layer traditional DLP can't see, where AI data leakage actually happens.

02
The detection

Detect Sensitive Data

Know what's flowing

Detect sensitive data in real time within AI interactions — customer records, source code, financials, personal data, confidential content — so you know when sensitive data is about to reach, or is coming back from, an AI model.

03
The prevention

Control Inbound

Before it reaches the model

Block, redact or tokenise sensitive data in prompts before it reaches the AI model — bi-directional tokenisation/masking — so sensitive data doesn't leak into AI providers' systems, training data or exposure.

04
The guard

Control Outbound

In AI responses

Control sensitive data in AI responses too — so AI assistants connected to company data (like Copilot) don't surface sensitive information to people who shouldn't see it. Protection in both directions.

05
The outcome

Enable AI Safely

Productivity without leakage

Let employees use AI tools productively — public chatbots, enterprise copilots, custom AI apps and agents — while preventing the sensitive-data leakage that AI adoption otherwise causes. Embrace AI, safely.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. See, control, enable.

AI-DLP controls sensitive data flowing to and from AI — tokenised, masked or blocked, bi-directionally — the AI-control layer of the portfolio, and paired with the human firewall.

See
AI-layer inspection

AI Interaction-Layer Inspection

Inspect data at the AI interaction point — prompts going in and responses coming out — the layer where AI data leakage happens and which traditional DLP can't see. Purpose-built for AI.

See
Real-time detection

Real-Time Sensitive-Data Detection

Detect sensitive data in real time within AI interactions — personal data, customer records, source code, financials, confidential content — so you catch sensitive data as it flows to or from AI, not after the fact.

See
Broad AI coverage

Public, Enterprise & Custom AI

Cover the AI employees actually use — public chatbots (ChatGPT, Gemini), enterprise copilots (Microsoft Copilot), and custom AI applications and agents — so data is protected across your whole AI usage, not one tool.

Control
Tokenise/mask

Bi-Directional Tokenisation & Masking

Tokenise or mask sensitive data before it reaches the AI model, and control it in responses — so the AI still works (on tokenised/masked data) but never receives or reveals the raw sensitive data. Protection both ways.

Control
Block / redact

Block, Redact or Allow by Policy

Apply policy-based controls to AI interactions — block sensitive prompts, redact sensitive parts, or allow with conditions — so you enforce exactly what sensitive data can and can't flow to AI, per your rules.

Control
Response control

Control Data in AI Responses

Control sensitive data in AI responses so AI assistants connected to company data (like Copilot) don't surface sensitive information to unauthorised people — addressing the AI over-exposure problem, not just prompt leakage.

Control
Shadow AI

Shadow-AI Awareness

Help surface and control unsanctioned AI use — the shadow AI tools employees adopt without approval — so sensitive data isn't leaking to AI you don't even know is being used.

Enable
Enable productivity

Enable AI, Don't Just Block It

Let employees use AI productively rather than banning it — controls protect sensitive data while allowing the AI's value, so you embrace AI's benefits without the leakage, avoiding the false choice of ban-or-risk.

Enable
Visibility

AI-Usage Visibility & Audit

See how AI is being used with your data — what sensitive data flows to which AI, what's blocked or tokenised — with an audit trail, giving governance and evidence over your organisation's AI data usage.

Enable
Compliance

AI Compliance & Data Protection

Support compliance as AI adoption meets data-protection rules (India's DPDP, GDPR) — preventing personal and regulated data leaking into AI systems, and evidencing that AI data usage is controlled.

Enable
Integrations

AI, Browser & Endpoint Integration

Integrate at the points AI is used — browsers, endpoints, enterprise AI platforms and custom AI apps — and connect with DSPM (what data AI can reach) and EDRM, so AI-DLP fits the ARMOR platform and your stack.

Enable
Platform

The AI-Control Layer of ARMOR

AI-DLP is the AI-control layer of the Seclore ARMOR platform — working with DSPM (discover what data AI can reach), Data Classification and EDRM (persistent protection) for end-to-end data security in the AI era.

See it, don’t just read it

Watch Seclore ARMOR in action

The overview, getting started, and the core workflows.

Entrust (official)·Concept

Identity Verification: What is Document Verification?

Document checks, explained.

Entrust (official)·Demo

How To Verify Global Identity Documents With AI

Verification in practice.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Identity Verification

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Seclore ARMOR AI-DLP apart.

01

Verification and authentication are different purchases

This is the misunderstanding that wastes the most money in this category, so it is worth being blunt. Identity verification establishes who somebody is the first time you meet them — checking a document, matching a face, deciding whether to open the account. Authentication confirms that whoever is signing in now is the same person who was verified then. A product that is excellent at one is not thereby useful for the other, and organisations regularly buy one having budgeted for the problem the other solves. Entrust sells both, which makes it easier to get right and also easier to be vague about. Be explicit about which problem you have before the demo.

02

Remote onboarding is now the default, and it broke the old controls

Identity used to be established in person, by someone looking at a document and at a face. Almost nothing works that way now, and the controls that assumed physical presence do not transfer. Document and biometric verification is the replacement, and it is doing genuinely hard work — detecting forged or altered documents, detecting presentation attacks where somebody holds a photograph or a screen to the camera, and doing both across the enormous variety of identity documents the world issues.

03

The Onfido technology is the substance here

Entrust acquired Onfido in April 2024, and that acquisition is what this product is. Onfido was an established specialist with real depth in document coverage and liveness detection, which is a category where depth matters disproportionately — the difference between a system that works on common documents in good lighting and one that works on unusual documents in poor lighting is most of the value. Buying an established specialist rather than building is the right call in this category, and worth knowing as the provenance of what you are evaluating.

04

The honest caveat: know the Indian regulatory boundary

We are going to be careful here rather than reassuring, because this is where the real risk sits. Remote customer onboarding in regulated Indian financial services operates within a framework RBI prescribes, and a vendor verification product is a component inside that framework rather than something that discharges the obligation. What a product can do technically and what satisfies a regulated KYC requirement are separate questions, and vendors on all sides have an incentive to blur them. Establish precisely which parts of your obligation this can serve, in writing, before you build a customer journey on top of it. If a vendor is vague about that boundary, treat the vagueness as information.

05

The honest positioning

Buy this when you onboard people remotely and need to establish who they are with more confidence than a form provides — and when you have already separated that need from your authentication need. It is strongest as part of a wider Entrust relationship, since buying identity verification from a hardware-and-PKI vendor makes most sense when you are already there. If identity verification is your only requirement and you have no other reason to be with Entrust, evaluate the specialist market too. And if you are in regulated Indian financial services, settle the regulatory boundary before the technology evaluation, because that is the answer that determines whether any of this is usable.

Employees leak data into AI
Right now, unseen
Bi-directional control
What goes in AND comes out
Enable AI, don’t ban it
Productivity without leakage
Proof, not promises

The numbers behind the platform

$917M
Entrust revenue, 2024
Entrust
~3000 staff
Worldwide
Entrust
2026
Tony Ball became CEO, 31 March
Entrust newsroom
2025
Exited public TLS — sold to Sectigo, 18 Sept
Entrust
0 India SaaS regions
nShield as a Service is UK/US/DE/AU
Entrust docs
0 Gartner MQs
None exists for HSM or key management
Gartner

What your Seclore AI-DLP journey looks like

Week 1Assess

Establish whether BIS is a gate

nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not. For Indian government tenders and several BFSI processes BIS is a threshold rather than a scoring criterion, so this one question can end the vendor comparison before it starts.

Week 1Assess

Separate public TLS from private PKI

Entrust sold its public certificate business to Sectigo in September 2025. If any part of your requirement is publicly trusted SSL, that is a different vendor now. Private PKI for internal certificates was not part of the sale. Buyers conflate these constantly.

Weeks 2–5Evaluate

Decide whether hardware is genuinely required

Software key management under your control satisfies many requirements at a fraction of the cost. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded it.

Weeks 4–10Deploy

Design Security World and the second appliance

Resilience and disaster recovery depend on how the Security World is designed, and a second appliance at another site is far easier to plan now than to retrofit. Budget the unit, the site and the network between them.

OngoingOperate

Test the Security World restore

Back up the Security World and then actually restore from it in a test. An untested backup of a hardware key domain is an assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
300+ reviews*
89% would recommend
AI-layer data control4.6
Bi-directional (in & out)4.6
Enabling safe AI adoption4.5
Maturity (new category)4.0
5
57%
4
32%
3
7%
2
3%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Public Sector
BIS was in the tender. That decided it before we compared a single specification.
Head of Infrastructure
Public Sector
Retail
We came for SSL certificates and learned they had sold that business. Better to find out in week one.
IT Manager
Retail
Banking
Security World meant the second site was a design decision rather than a migration.
Security Architect
Banking
Insurance
Budget the operations, not the appliance. The separation of duties took longer than the install.
Infrastructure Lead
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI-security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
EntrustThis page

BIS certified — a procurement gate in Indian tenders.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
EntrustThis page

Deep on hardware, PKI and identity; narrower since Sept 2025.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Seclore AI-DLP vs the AI-security field

Legacy DLP + AI add-ons, AI-security startups, CASB/SSE and Purview AI — honest lanes in a new category; the edge is bi-directional control from a data specialist, plus platform + India origin.

DimensionEntrustThalesMicrosoft PurviewSecloreHashiCorp Vault
What it actually isHSM, private PKI, certificate lifecycle, identityKey management, HSM and encryption platformDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
BIS certification (India)nShield Connect XC holds it — a procurement GATENot established for LunaNot applicableNot applicableNot applicable
Hardware key custodynShield, with Security WorldLuna HSMDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
Verified analyst standingNone verified for HSM or key managementKuppingerCole Overall Leader 2025 ×2Microsoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Public TLS certificatesSOLD to Sectigo, Sept 2025 — no longer offeredNot a public CANot a public CANot a public CANot a public CA
India data residencyOn-premises appliances — no India SaaS regionOn-premises — no India SaaS regionIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundNew CEO Mar 2026; exited public TLS Sept 2025HSM operations: firmware, backup, separation of dutiesDKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitWhere BIS certification is a procurement gateKey custody with the broader software platformMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Seclore AI-DLP if…

  • You want AI data control from a data-security specialist
  • Bi-directional protection (leakage in + over-exposure out) matters
  • You're rolling out Copilot / enterprise AI and worry about over-exposure
  • You value an India-origin platform under DPDP

Legacy DLP + AI if…

  • You want to extend your existing DLP with basic AI controls

AI-security startups if…

  • You want a dedicated, AI-security-first standalone tool

CASB/SSE AI controls if…

  • You're SSE-committed and want AI controls in that stack

No AI-DLP if…

  • Never — AI adoption leaks sensitive data without it

Entrust Identity Verification is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (count AI users; IT-hour cost as loaded rate). Estimates assume productivity retained by enabling AI safely rather than banning it, plus reduced incident handling — but the far larger, unpriced win is the avoided breach and DPDP penalty (sensitive data leaking into third-party AI, and Copilot over-exposure, are real and growing). Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Seclore ARMOR AI-DLP is quote-priced (no public list) — by users, AI scope (public chatbots, copilots, custom AI) and whether you add the wider ARMOR platform (DSPM, EDRM, Classification) for end-to-end AI data security. It's a newer category — confirm current capabilities. TechBag right-sizes it and quotes in INR/GST — Seclore is India-origin.

ARMOR AI-DLP

Best for safe AI adoption

  • Control sensitive data to & from AI, in real time
  • Bi-directional: leakage in + over-exposure out
  • Public chatbots, copilots, custom AI

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ The ARMOR platform

Best for end-to-end AI data security

  • Add DSPM (what AI can reach), EDRM (protect), Classification
  • Discover, control at AI layer, protect the data
  • TechBag scopes the mix

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
BIS

Is Bureau of Indian Standards certification a gate in our procurement, or merely a preference?

2
Scope

Are we clear that Entrust no longer sells public TLS certificates? That business went to Sectigo.

3
Hardware

Do keys genuinely need to exist only in hardware, or would software key management under our control do?

4
Security World

Have we designed the key domain, and do we have a second appliance for resilience?

5
Separation of duties

Who administers the appliance, and who approves key use? They must be different people.

6
Backup

Have we backed up the Security World AND tested restoring from it?

7
Residency

Are we deploying on-premises? nShield as a Service has no India region.

8
CEO

Are we citing Tony Ball, CEO since 31 March 2026 — not the stale Todd Wilkinson answer?

9
Analyst claims

Have we avoided implying a Gartner Leader placement? No MQ exists for this category.

10
Commercials

Have we budgeted support, firmware, backup discipline and the second unit — not just the appliance?

FAQ

Questions buyers ask

No. Entrust sold its entire public TLS certificate business to Sectigo — announced January 2025, completed 18 September 2025 — after Chrome, Apple and Mozilla distrusted its public roots from November 2024 following a series of compliance failures. It exited rather than rescued the business. If you need publicly trusted SSL for an internet-facing site, Entrust is not the vendor and Sectigo or another public CA is where to look. Be careful, because a great deal of well-ranked material still describes Entrust as a public certificate authority — documentation, comparison articles, search summaries — and all of it predates the sale. We put this first on every Entrust page precisely because it is the most likely reason an evaluation here is wasted. What Entrust does still sell is coherent and genuinely strong: nShield hardware security modules, private PKI for the certificates your own systems trust, certificate lifecycle management, and identity verification built on Onfido. Private PKI in particular is easy to confuse with public TLS because they share vocabulary, and it was not part of the sale. The distinction is substantive: a public certificate is trusted because browsers ship the root, while a private certificate is trusted because your organisation configured its systems to trust your CA. The browser distrust event was fatal to the first and does not carry the same implication for the second.

Ready to use AI without leaking data?

Scope AI data control (protect sensitive data flowing to and from AI, bi-directionally), enable AI safely instead of banning it, or let a TechBag advisor plan your AI data-security strategy.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.