Talk to us
by EntrustTechBag Intel Page

Entrust nShield HSM

Keys generated inside the appliance that never leave in usable form — and the one HSM here that holds Bureau of Indian Standards certification. For Indian government tenders BIS is a gate, not a preference, which can settle this comparison before a single feature is discussed. control who can view, edit, print, copy or forward, and revoke access even after you’ve shared a file outside your company.

BIS certifiedKeys never leave the deviceAnalyst standing unverified

Data residency & processing — two different questions

Where data lives

Yours — on-premises appliances in India

nShield HSMs are physical appliances in your own data centre, and private PKI can run on-premises too. Keys are generated and held in hardware you own, in India, under your administrators — the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India region for the managed service

nShield as a Service runs in the UK, US, Germany and Australia. Entrust has live engineering hiring in Bengaluru and Pune, and that is people in India, not data in India — treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer the answer is appliances you operate, which is very likely what your regulator wanted anyway. Note what does not exist so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant — and we could not verify an HSM Leader placement for Entrust with any analyst. A search caution specific to this vendor: “Entrust India” surfaces several unrelated companies, including a Bengaluru wealth manager, so check you are reading about Entrust Corporation before drawing conclusions.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
India procurement
the fact that can end the comparison
BIS certified
Key custody
hardware, in your own building
Strongest available
Analyst standing
no HSM Leader placement confirmed
Unverified
Operational cost
firmware, Security World backup, second unit
Real

Quick answer

Entrust nShield is a hardware security module: a tamper-resistant appliance that generates and stores cryptographic keys and performs operations inside the device, so key material never leaves in usable form. On the cryptography it is the direct peer to Thales's Luna, and for most buyers the two are genuinely close. For an Indian buyer there is one fact that can settle the comparison before any feature is discussed: nShield Connect XC holds Bureau of Indian Standards certification, and Luna does not. For Indian government tenders and several BFSI procurement processes BIS is a gate rather than a scoring criterion — a product without it is not permitted, regardless of how well it performs or what it costs. So the single most useful question to answer before any demo is whether BIS appears in your requirements. If it does, this evaluation is effectively over. If it does not, the comparison is close and Thales carries the stronger verified analyst position. Architecturally, Entrust's Security World manages keys across a group of HSMs as one logical unit, which is how resilience, disaster recovery and key portability between appliances work without anyone hand-carrying key material. That makes a second appliance at another site an architectural decision rather than an awkward retrofit, and it is the concept anyone comparing nShield and Luna meets immediately. On analyst standing we are being deliberately conservative: Gartner publishes no Magic Quadrant for hardware security modules at all, only Market Guides, which have no Leader quadrant — so no vendor here has a Gartner Leader placement whatever a datasheet implies, and we could not verify an HSM Leader placement for Entrust with any analyst. We would rather tell you that than repeat a claim we could not check. Read more ↓ Show less ↑
Part 01 · Orient

The Seclore platform family

This page covers Entrust nShield HSM — persistent protection. The rest of the Seclore ARMOR platform:

Quick facts

30-second orientation
Product
Entrust nShield HSM
The India fact
nShield Connect XC holds BIS certification
Why that matters
BIS is a procurement GATE, not a scoring criterion
Architecture
Security World — keys across a group of HSMs
Vendor
Entrust — CEO Tony Ball, from 31 March 2026
Note
Todd Wilkinson is the STALE answer — 17 years, retired
Ownership
Private, via Datacard — Germany's Quandt family
Exited Sept 2025
Public TLS certificates — sold to Sectigo
Gartner
No MQ exists for HSM or key management — Market Guides only
Analyst standing
No HSM/key-management Leader placement verified
India engineering
Live hiring in Bengaluru and Pune
Data residency
On-premises; nShield as a Service has no India region
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, BIS scoping
Part 02 · Learn

Understand data-centric security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

A tamper-resistant hardware appliance that generates and stores cryptographic keys and performs operations inside the device. Key material never leaves in usable form.

Location security vs data-centric protection — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailnShield HSM
Where protection livesIn the network/endpointIn the data itself
Data leaves your perimeterControl lostProtection travels with it
Wrong person got the fileNothing you can doRevoke access instantly
External sharingShare = lose controlShare with retained control
What recipients can doAnything, foreverExactly what you allow
Vendor relationship endsThey keep your dataRevoke every file
Visibility beyond perimeterNoneTrack who opened what, where
Data expiryNever — lives foreverAuto-expire on a date

EDRM is part of a data-security strategy, not all of it — it works with discovery, classification and DLP (which ARMOR also provides). Seclore is an India-origin pioneer. TechBag positions it within your full strategy.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The protection

Attach Policy

Wrap the file in controls

Each sensitive file is wrapped in a persistent policy defining who can access it and what they can do — the protection becomes part of the data itself, not the location it happens to be in.

02
The persistence

Travels With Data

Protection follows everywhere

The policy stays attached to the file wherever it goes — emailed out, downloaded, copied, forwarded, uploaded to any cloud — so control is never lost when data leaves your environment. This is the defining EDRM capability.

03
The control

Granular Rights

Control every action

Control precisely what each recipient can do — view only, edit, print, copy, screenshot, forward — from which locations and devices, and until when (expiry) — so access matches exactly what each person should have.

04
The power

Revoke Anytime

Even after sharing

Revoke or change access to a file at any time — even after you've already sent it to someone outside your company — so a document shared today can be locked tomorrow. Control you never had before.

05
The visibility

Track & Audit

See who does what

Track every access and action on protected files — who opened what, when, from where, and what they did — giving full visibility and an audit trail over sensitive data even beyond your perimeter.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Protect, control, govern.

EDRM protects the data itself — persistent controls that travel with each file and can be revoked even after sharing — the data-centric core of the portfolio, and paired with the human firewall.

Protect
Persistent protection

Persistent, Follows-the-Data Protection

Protection is attached to the file and travels with it everywhere — inside or outside your organisation, across email, cloud, devices and onward sharing — so control is never lost when data leaves your perimeter. The defining EDRM capability.

Protect
Encryption

Encryption Bound to Policy

Files are encrypted with the usage policy bound to them, so only authorised users (authenticated) can decrypt and access — and only within the rights granted. The data is protected even if the file is stolen.

Protect
Any file, anywhere

Any File Type, Any Location

Protect documents, spreadsheets, PDFs, images, CAD files and more, wherever they live or travel — endpoints, file shares, email, cloud apps, collaboration tools — so data-centric protection covers your sensitive data broadly.

Control
Granular rights

Granular Usage Controls

Control precisely what each user can do — view, edit, print, copy/paste, screenshot, forward — per file and per recipient, so access is exactly what each person should have, not all-or-nothing.

Control
Location & time

Location & Time Controls + Expiry

Restrict access by location/device and set expiry dates, so a file can be opened only from approved places and only until a chosen date — tightening control over where and when data can be used.

Control
Revoke

Revoke Access After Sharing

Revoke or change access to any protected file at any time — even after it's been sent outside your organisation — so a document shared today can be locked tomorrow. Control that traditional security can never offer.

Control
Secure sharing

Confident External Sharing

Share sensitive data with partners, vendors and across the supply chain while retaining control — recipients don't need to be your employees or on your systems, yet you govern what they can do and can revoke access.

Govern
Track & audit

Track, Audit & Visibility

Track every access and action on protected files — who opened what, when, from where, what they did — giving full visibility and an audit trail over sensitive data even after it leaves your perimeter.

Govern
Automated protection

Automated, Policy-Driven Protection

Automatically protect files based on classification, location or workflow — so sensitive data is secured without relying on users to remember, and protection scales across the organisation.

Govern
Integrations

Integrations & Ecosystem

Integrate with DLP, classification, CASB, file storage, email, IdP and collaboration tools (including Microsoft Teams and Office) — so persistent protection fits into your existing data-security stack and workflows.

Govern
Compliance

Compliance & Data Protection

Support compliance with data-protection regulations (India's DPDP, GDPR, sector mandates) by controlling and auditing access to personal and sensitive data wherever it travels — evidence that data is genuinely protected.

Govern
Platform

The Core of Seclore ARMOR

EDRM is the persistent-protection heart of the broader Seclore ARMOR platform — which adds DSPM (discover sensitive data), AI-DLP (protect data at the AI layer) and Data Classification — so protection connects to discovery and classification.

See it, don’t just read it

Watch Seclore EDRM in action

The overview, getting started, and the core workflows.

Entrust (official)·Hardware

Entrust nShield HSMs: On Another Level

The appliance, presented by Entrust.

Entrust (official)·Concept

What is a hardware security module (HSM)?

The category, explained.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why nShield

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Seclore ARMOR EDRM apart.

01

BIS certification is a gate, not a preference

This is the reason to read this page before the Thales one, and it is worth understanding precisely because it works differently from a normal feature comparison. Bureau of Indian Standards certification, which nShield Connect XC holds, functions in Indian government tenders and several BFSI procurement processes as a threshold: a product without it is not permitted to be considered, whatever its technical merits or price. That is different from being a point of differentiation you weigh against others. So find out early whether BIS is in your requirements, because if it is, you are not choosing between two vendors — you are confirming one. And if it is not, we will tell you the comparison is genuinely close.

02

Keys that cannot be extracted, by construction

The core argument for any HSM, stated plainly. Software key management can be excellent and is often sufficient, but its keys exist in memory on a host, and a sufficiently compromised host can yield them. Hardware removes that possibility architecturally: the key is generated inside the appliance, used inside it, and never leaves in usable form. Compromising the application server that calls the HSM buys an attacker the ability to request operations while that access lasts — it does not buy them the key. That distinction is what a regulator is reaching for when they ask specifically about hardware key protection rather than about encryption generally.

03

Security World makes resilience an architecture, not a retrofit

Entrust's Security World manages keys across a group of HSMs as one logical unit. Practically, that means a second appliance at another site is a design decision you make at the start rather than a painful exercise in moving key material later, and disaster recovery has a defined shape rather than being improvised. Anyone comparing nShield against Luna meets this concept in the first conversation, and it is a genuine architectural difference rather than marketing vocabulary.

04

The honest cost: an appliance, not software

HSM budgets go wrong in a predictable way — the hardware quote is captured and everything around it is not. There is a support contract. There is firmware maintenance on a security-critical device. There is backup of the Security World, which is its own discipline and genuinely unforgiving if neglected. There are separation-of-duties roles that did not previously exist, because the person administering the appliance should not be the person approving key use. And if you want to survive a data-centre failure, there is a second unit and somewhere to put it. None of it is exotic. All of it is real, and we would rather cost it with you now.

05

The honest positioning

Buy nShield when BIS certification is a requirement in your procurement — at that point it is the answer and the comparison is over. Buy it also when hardware key custody is genuinely required and Entrust's PKI or identity portfolio is part of your wider plan, since one vendor across those is simpler to manage. Look at Thales instead when BIS is not a gate and you want the stronger verified analyst position or the broader software platform around the hardware. And look at neither if software key management under your control would satisfy your actual requirement, which for many buyers it would — that is a smaller sale for us and frequently the right recommendation.

Protection travels with the data
Not tied to a location
Revoke after sharing
Even files already sent out
India-origin pioneer
Mumbai · IIT-Bombay roots
Proof, not promises

The numbers behind the platform

$917M
Entrust revenue, 2024
Entrust
~3000 staff
Worldwide
Entrust
2026
Tony Ball became CEO, 31 March
Entrust newsroom
2025
Exited public TLS — sold to Sectigo, 18 Sept
Entrust
0 India SaaS regions
nShield as a Service is UK/US/DE/AU
Entrust docs
0 Gartner MQs
None exists for HSM or key management
Gartner

What your Seclore EDRM journey looks like

Week 1Assess

Establish whether BIS is a gate

nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not. For Indian government tenders and several BFSI processes BIS is a threshold rather than a scoring criterion, so this one question can end the vendor comparison before it starts.

Week 1Assess

Separate public TLS from private PKI

Entrust sold its public certificate business to Sectigo in September 2025. If any part of your requirement is publicly trusted SSL, that is a different vendor now. Private PKI for internal certificates was not part of the sale. Buyers conflate these constantly.

Weeks 2–5Evaluate

Decide whether hardware is genuinely required

Software key management under your control satisfies many requirements at a fraction of the cost. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded it.

Weeks 4–10Deploy

Design Security World and the second appliance

Resilience and disaster recovery depend on how the Security World is designed, and a second appliance at another site is far easier to plan now than to retrofit. Budget the unit, the site and the network between them.

OngoingOperate

Test the Security World restore

Back up the Security World and then actually restore from it in a test. An untested backup of a hardware key domain is an assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.6
700+ reviews*
91% would recommend
Persistent follows-the-data protection4.7
Revoke-after-sharing control4.7
Granular usage controls4.6
Deployment & recipient experience4.1
5
63%
4
28%
3
6%
2
2%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Public Sector
BIS was in the tender. That decided it before we compared a single specification.
Head of Infrastructure
Public Sector
Retail
We came for SSL certificates and learned they had sold that business. Better to find out in week one.
IT Manager
Retail
Banking
Security World meant the second site was a design decision rather than a migration.
Security Architect
Banking
Insurance
Budget the operations, not the appliance. The separation of duties took longer than the install.
Infrastructure Lead
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data-centric security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
EntrustThis page

BIS certified — a procurement gate in Indian tenders.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
EntrustThis page

Deep on hardware, PKI and identity; narrower since Sept 2025.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Seclore EDRM vs the data-centric field

Microsoft Purview, Fasoo, Fortra/Vera and perimeter/DLP-only — honest lanes; the edge is deep, broad, external-capable follow-the-data protection from an India-origin pioneer.

DimensionEntrustThalesMicrosoft PurviewSecloreHashiCorp Vault
What it actually isHSM, private PKI, certificate lifecycle, identityKey management, HSM and encryption platformDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
BIS certification (India)nShield Connect XC holds it — a procurement GATENot established for LunaNot applicableNot applicableNot applicable
Hardware key custodynShield, with Security WorldLuna HSMDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
Verified analyst standingNone verified for HSM or key managementKuppingerCole Overall Leader 2025 ×2Microsoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Public TLS certificatesSOLD to Sectigo, Sept 2025 — no longer offeredNot a public CANot a public CANot a public CANot a public CA
India data residencyOn-premises appliances — no India SaaS regionOn-premises — no India SaaS regionIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundNew CEO Mar 2026; exited public TLS Sept 2025HSM operations: firmware, backup, separation of dutiesDKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitWhere BIS certification is a procurement gateKey custody with the broader software platformMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Seclore EDRM if…

  • You need persistent protection of data that leaves your control
  • Revoke-after-sharing and granular usage controls matter
  • You share sensitive data externally (partners, supply chain)
  • You value an India-origin data-centric pioneer (DPDP-aware)

Microsoft Purview if…

  • You're all-Microsoft and want bundled information protection

Fasoo if…

  • You want an alternative enterprise-DRM specialist

Fortra/Vera if…

  • You're standardising on the Fortra data-security portfolio

No data-centric if…

  • Never — location security loses control when data leaves

Entrust nShield HSM is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (count users; IT-hour cost as loaded rate). Estimates assume reduced effort chasing data that's left your perimeter and safer external collaboration once protection travels with the data — but the far larger, unpriced win is the avoided breach or IP loss (data shared externally is otherwise uncontrollable and unrecoverable). Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Seclore ARMOR EDRM is quote-priced (no public list) — by users, scope of protection, capabilities/integrations and whether you add the wider ARMOR platform (DSPM, AI-DLP, Classification). Budget for a thoughtful rollout too. TechBag right-sizes it and quotes in INR/GST with local support — and Seclore is India-origin.

ARMOR EDRM

Best for protecting data that leaves your control

  • Persistent controls that travel with each file
  • Revoke access even after external sharing
  • Granular rights: view/edit/print/copy/forward/expiry

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ The ARMOR platform

Best for full data security

  • Add DSPM (discovery), AI-DLP, Data Classification
  • Discover, classify, protect, control at the AI layer
  • TechBag scopes the mix

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
BIS

Is Bureau of Indian Standards certification a gate in our procurement, or merely a preference?

2
Scope

Are we clear that Entrust no longer sells public TLS certificates? That business went to Sectigo.

3
Hardware

Do keys genuinely need to exist only in hardware, or would software key management under our control do?

4
Security World

Have we designed the key domain, and do we have a second appliance for resilience?

5
Separation of duties

Who administers the appliance, and who approves key use? They must be different people.

6
Backup

Have we backed up the Security World AND tested restoring from it?

7
Residency

Are we deploying on-premises? nShield as a Service has no India region.

8
CEO

Are we citing Tony Ball, CEO since 31 March 2026 — not the stale Todd Wilkinson answer?

9
Analyst claims

Have we avoided implying a Gartner Leader placement? No MQ exists for this category.

10
Commercials

Have we budgeted support, firmware, backup discipline and the second unit — not just the appliance?

FAQ

Questions buyers ask

No. Entrust sold its entire public TLS certificate business to Sectigo — announced January 2025, completed 18 September 2025 — after Chrome, Apple and Mozilla distrusted its public roots from November 2024 following a series of compliance failures. It exited rather than rescued the business. If you need publicly trusted SSL for an internet-facing site, Entrust is not the vendor and Sectigo or another public CA is where to look. Be careful, because a great deal of well-ranked material still describes Entrust as a public certificate authority — documentation, comparison articles, search summaries — and all of it predates the sale. We put this first on every Entrust page precisely because it is the most likely reason an evaluation here is wasted. What Entrust does still sell is coherent and genuinely strong: nShield hardware security modules, private PKI for the certificates your own systems trust, certificate lifecycle management, and identity verification built on Onfido. Private PKI in particular is easy to confuse with public TLS because they share vocabulary, and it was not part of the sale. The distinction is substantive: a public certificate is trusted because browsers ship the root, while a private certificate is trusted because your organisation configured its systems to trust your CA. The browser distrust event was fatal to the first and does not carry the same implication for the second.

Ready to protect the data itself?

Scope data-centric protection (persistent controls that travel with your files and can be revoked even after sharing), enable confident external sharing, or let a TechBag advisor plan your data-security strategy.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.