Proving a remote person is who they claim to be — document and biometric verification built on Onfido, acquired April 2024. Note the boundary that costs the most: this is verification, not authentication. in prompts before it reaches ChatGPT or Copilot, and control it in AI responses — so employees use AI without leaking data.
Data residency & processing — two different questions
Where data lives
Yours — on-premises appliances in India
nShield HSMs are physical appliances in your own data centre, and private PKI can run on-premises too. Keys are generated and held in hardware you own, in India, under your administrators — the evidence is a serial number and an access log rather than a contract clause.
The constraint, stated plainly
No India region for the managed service
nShield as a Service runs in the UK, US, Germany and Australia. Entrust has live engineering hiring in Bengaluru and Pune, and that is people in India, not data in India — treating an engineering presence as a residency answer is the error that surfaces during an audit.
For a residency-bound Indian buyer the answer is appliances you operate, which is very likely what your regulator wanted anyway. Note what does not exist so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant — and we could not verify an HSM Leader placement for Entrust with any analyst. A search caution specific to this vendor: “Entrust India” surfaces several unrelated companies, including a Bengaluru wealth manager, so check you are reading about Entrust Corporation before drawing conclusions.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Entrust Identity Verification — the AI-control layer. The rest of the Seclore ARMOR platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Document and biometric verification built on Onfido — checking an identity document and matching a live capture against it to establish who a remote person is.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | Identity Verification |
|---|---|---|
| Data pasted into AI | Leaks, unseen | Tokenised/masked/blocked |
| Traditional DLP + AI | Blind to the AI layer | Controls prompts & responses |
| Copilot over-exposure | AI surfaces sensitive data | Response control |
| The AI dilemma | Ban (lose value) or allow (risk) | Enable safely |
| Shadow AI | Invisible leakage | Surfaced & controlled |
| Protection direction | One-way at best | Bi-directional |
| AI usage visibility | None | Seen & audited |
| DPDP + AI | Personal data leaks to AI | Controlled & evidenced |
AI-DLP enables safe AI adoption — control the data, not the tool. Bi-directional control addresses both leakage IN and Copilot over-exposure OUT. It's a new category; TechBag positions it. Seclore is India-origin.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Inspect data at the AI interaction point — the prompts employees send to AI and the responses coming back — the layer traditional DLP can't see, where AI data leakage actually happens.
Detect sensitive data in real time within AI interactions — customer records, source code, financials, personal data, confidential content — so you know when sensitive data is about to reach, or is coming back from, an AI model.
Block, redact or tokenise sensitive data in prompts before it reaches the AI model — bi-directional tokenisation/masking — so sensitive data doesn't leak into AI providers' systems, training data or exposure.
Control sensitive data in AI responses too — so AI assistants connected to company data (like Copilot) don't surface sensitive information to people who shouldn't see it. Protection in both directions.
Let employees use AI tools productively — public chatbots, enterprise copilots, custom AI apps and agents — while preventing the sensitive-data leakage that AI adoption otherwise causes. Embrace AI, safely.
One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.
AI-DLP controls sensitive data flowing to and from AI — tokenised, masked or blocked, bi-directionally — the AI-control layer of the portfolio, and paired with the human firewall.
Inspect data at the AI interaction point — prompts going in and responses coming out — the layer where AI data leakage happens and which traditional DLP can't see. Purpose-built for AI.
Detect sensitive data in real time within AI interactions — personal data, customer records, source code, financials, confidential content — so you catch sensitive data as it flows to or from AI, not after the fact.
Cover the AI employees actually use — public chatbots (ChatGPT, Gemini), enterprise copilots (Microsoft Copilot), and custom AI applications and agents — so data is protected across your whole AI usage, not one tool.
Tokenise or mask sensitive data before it reaches the AI model, and control it in responses — so the AI still works (on tokenised/masked data) but never receives or reveals the raw sensitive data. Protection both ways.
Apply policy-based controls to AI interactions — block sensitive prompts, redact sensitive parts, or allow with conditions — so you enforce exactly what sensitive data can and can't flow to AI, per your rules.
Control sensitive data in AI responses so AI assistants connected to company data (like Copilot) don't surface sensitive information to unauthorised people — addressing the AI over-exposure problem, not just prompt leakage.
Help surface and control unsanctioned AI use — the shadow AI tools employees adopt without approval — so sensitive data isn't leaking to AI you don't even know is being used.
Let employees use AI productively rather than banning it — controls protect sensitive data while allowing the AI's value, so you embrace AI's benefits without the leakage, avoiding the false choice of ban-or-risk.
See how AI is being used with your data — what sensitive data flows to which AI, what's blocked or tokenised — with an audit trail, giving governance and evidence over your organisation's AI data usage.
Support compliance as AI adoption meets data-protection rules (India's DPDP, GDPR) — preventing personal and regulated data leaking into AI systems, and evidencing that AI data usage is controlled.
Integrate at the points AI is used — browsers, endpoints, enterprise AI platforms and custom AI apps — and connect with DSPM (what data AI can reach) and EDRM, so AI-DLP fits the ARMOR platform and your stack.
AI-DLP is the AI-control layer of the Seclore ARMOR platform — working with DSPM (discover what data AI can reach), Data Classification and EDRM (persistent protection) for end-to-end data security in the AI era.
The overview, getting started, and the core workflows.
Document checks, explained.
Verification in practice.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Seclore ARMOR AI-DLP apart.
This is the misunderstanding that wastes the most money in this category, so it is worth being blunt. Identity verification establishes who somebody is the first time you meet them — checking a document, matching a face, deciding whether to open the account. Authentication confirms that whoever is signing in now is the same person who was verified then. A product that is excellent at one is not thereby useful for the other, and organisations regularly buy one having budgeted for the problem the other solves. Entrust sells both, which makes it easier to get right and also easier to be vague about. Be explicit about which problem you have before the demo.
Identity used to be established in person, by someone looking at a document and at a face. Almost nothing works that way now, and the controls that assumed physical presence do not transfer. Document and biometric verification is the replacement, and it is doing genuinely hard work — detecting forged or altered documents, detecting presentation attacks where somebody holds a photograph or a screen to the camera, and doing both across the enormous variety of identity documents the world issues.
Entrust acquired Onfido in April 2024, and that acquisition is what this product is. Onfido was an established specialist with real depth in document coverage and liveness detection, which is a category where depth matters disproportionately — the difference between a system that works on common documents in good lighting and one that works on unusual documents in poor lighting is most of the value. Buying an established specialist rather than building is the right call in this category, and worth knowing as the provenance of what you are evaluating.
We are going to be careful here rather than reassuring, because this is where the real risk sits. Remote customer onboarding in regulated Indian financial services operates within a framework RBI prescribes, and a vendor verification product is a component inside that framework rather than something that discharges the obligation. What a product can do technically and what satisfies a regulated KYC requirement are separate questions, and vendors on all sides have an incentive to blur them. Establish precisely which parts of your obligation this can serve, in writing, before you build a customer journey on top of it. If a vendor is vague about that boundary, treat the vagueness as information.
Buy this when you onboard people remotely and need to establish who they are with more confidence than a form provides — and when you have already separated that need from your authentication need. It is strongest as part of a wider Entrust relationship, since buying identity verification from a hardware-and-PKI vendor makes most sense when you are already there. If identity verification is your only requirement and you have no other reason to be with Entrust, evaluate the specialist market too. And if you are in regulated Indian financial services, settle the regulatory boundary before the technology evaluation, because that is the answer that determines whether any of this is usable.
nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not. For Indian government tenders and several BFSI processes BIS is a threshold rather than a scoring criterion, so this one question can end the vendor comparison before it starts.
Entrust sold its public certificate business to Sectigo in September 2025. If any part of your requirement is publicly trusted SSL, that is a different vendor now. Private PKI for internal certificates was not part of the sale. Buyers conflate these constantly.
Software key management under your control satisfies many requirements at a fraction of the cost. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded it.
Resilience and disaster recovery depend on how the Security World is designed, and a second appliance at another site is far easier to plan now than to retrofit. Budget the unit, the site and the network between them.
Back up the Security World and then actually restore from it in a test. An untested backup of a hardware key domain is an assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“BIS was in the tender. That decided it before we compared a single specification.”
“We came for SSL certificates and learned they had sold that business. Better to find out in week one.”
“Security World meant the second site was a design decision rather than a migration.”
“Budget the operations, not the appliance. The separation of duties took longer than the install.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI-security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
BIS certified — a procurement gate in Indian tenders.
The grid nobody publishes — how deep the core capability is vs how broad the wider platform.
Deep on hardware, PKI and identity; narrower since Sept 2025.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Legacy DLP + AI add-ons, AI-security startups, CASB/SSE and Purview AI — honest lanes in a new category; the edge is bi-directional control from a data specialist, plus platform + India origin.
| Dimension | Entrust | Thales | Microsoft Purview | Seclore | HashiCorp Vault |
|---|---|---|---|---|---|
| What it actually is | HSM, private PKI, certificate lifecycle, identity | Key management, HSM and encryption platform | Document rights management | India-built EDRM | Secrets and encryption-as-a-service |
| BIS certification (India) | nShield Connect XC holds it — a procurement GATE | Not established for Luna | Not applicable | Not applicable | Not applicable |
| Hardware key custody | nShield, with Security World | Luna HSM | DKE holds one key; not an HSM product | Not an HSM vendor | Can integrate with an HSM |
| Verified analyst standing | None verified for HSM or key management | KuppingerCole Overall Leader 2025 ×2 | Microsoft, evaluated broadly elsewhere | Specialist — no Gartner EDRM MQ exists | Widely recognised in its category |
| Public TLS certificates | SOLD to Sectigo, Sept 2025 — no longer offered | Not a public CA | Not a public CA | Not a public CA | Not a public CA |
| India data residency | On-premises appliances — no India SaaS region | On-premises — no India SaaS region | India region via Advanced Data Residency | India-built; SaaS or self-hosted | Self-host anywhere, including India |
| Published pricing | Quote-only | Quote-only | $12/user/mo Purview add-on; E5 $60 | Quote (INR) | Free community edition |
| The thing to plan around | New CEO Mar 2026; exited public TLS Sept 2025 | HSM operations: firmware, backup, separation of duties | DKE breaks co-authoring, search and Copilot | Adoption — manual protection is rarely applied | Operationally heavy to run well |
| Best fit | Where BIS certification is a procurement gate | Key custody with the broader software platform | Microsoft estates with E5 needing document labels | Documents shared outside, India-built vendor | Engineering-owned secrets and encryption services |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Entrust Identity Verification is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (count AI users; IT-hour cost as loaded rate). Estimates assume productivity retained by enabling AI safely rather than banning it, plus reduced incident handling — but the far larger, unpriced win is the avoided breach and DPDP penalty (sensitive data leaking into third-party AI, and Copilot over-exposure, are real and growing). Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Seclore ARMOR AI-DLP is quote-priced (no public list) — by users, AI scope (public chatbots, copilots, custom AI) and whether you add the wider ARMOR platform (DSPM, EDRM, Classification) for end-to-end AI data security. It's a newer category — confirm current capabilities. TechBag right-sizes it and quotes in INR/GST — Seclore is India-origin.
Best for safe AI adoption
Best for a broader rollout
Best for end-to-end AI data security
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is Bureau of Indian Standards certification a gate in our procurement, or merely a preference?
Are we clear that Entrust no longer sells public TLS certificates? That business went to Sectigo.
Do keys genuinely need to exist only in hardware, or would software key management under our control do?
Have we designed the key domain, and do we have a second appliance for resilience?
Who administers the appliance, and who approves key use? They must be different people.
Have we backed up the Security World AND tested restoring from it?
Are we deploying on-premises? nShield as a Service has no India region.
Are we citing Tony Ball, CEO since 31 March 2026 — not the stale Todd Wilkinson answer?
Have we avoided implying a Gartner Leader placement? No MQ exists for this category.
Have we budgeted support, firmware, backup discipline and the second unit — not just the appliance?
Scope AI data control (protect sensitive data flowing to and from AI, bi-directionally), enable AI safely instead of banning it, or let a TechBag advisor plan your AI data-security strategy.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.