Talk to us
by EntrustTechBag Intel Page

Entrust PKI

The certificates your own systems trust — machine identities, device certificates, internal TLS, code signing. Read the scope carefully: this is private PKI. Entrust sold its public TLS certificate business to Sectigo in September 2025. the foundation the rest of your data security builds on, with labels that drive Seclore’s persistent protection.

Private CA onlyPublic TLS sold to SectigoMachine identity is the driver

Data residency & processing — two different questions

Where data lives

Yours — on-premises appliances in India

nShield HSMs are physical appliances in your own data centre, and private PKI can run on-premises too. Keys are generated and held in hardware you own, in India, under your administrators — the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India region for the managed service

nShield as a Service runs in the UK, US, Germany and Australia. Entrust has live engineering hiring in Bengaluru and Pune, and that is people in India, not data in India — treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer the answer is appliances you operate, which is very likely what your regulator wanted anyway. Note what does not exist so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant — and we could not verify an HSM Leader placement for Entrust with any analyst. A search caution specific to this vendor: “Entrust India” surfaces several unrelated companies, including a Bengaluru wealth manager, so check you are reading about Entrust Corporation before drawing conclusions.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Scope
public TLS is no longer an Entrust product
Private only
Trust model
your systems trust your CA because you configured it
Yours to define
Machine identity
workloads now outnumber humans
The growth driver
Deployment
check regions if residency binds you
On-prem or managed

Quick answer

Entrust PKI is private certificate authority infrastructure: the certificates your own organisation issues and your own systems trust. Machine identities, device certificates, internal TLS between services, code signing. Before anything else, be clear about a boundary that moved recently and that buyers conflate constantly. This is PRIVATE PKI. Entrust sold its entire public TLS certificate business to Sectigo — announced January 2025, completed 18 September 2025 — after Chrome, Apple and Mozilla distrusted its public roots from November 2024. If what you need is a publicly trusted SSL certificate for an internet-facing website, Entrust is no longer that vendor, and a great deal of still-well-ranked material on the internet will tell you otherwise because it predates the sale. Private PKI was not part of that transaction and remains a genuine Entrust strength. The two share vocabulary and almost nothing else: a public certificate is trusted because browsers ship the root, and a private certificate is trusted because you decided it should be. That difference is why the browser distrust event, which was fatal to the public business, does not carry the same implication for the private one — your systems trust your CA because you configured them to. Where private PKI is going matters more than it used to. Machine identities now vastly outnumber human users in any modern estate, industry certificate lifetimes keep shortening, and manual issuance does not scale against either trend. Available on-premises or as PKI as a Service, though note the managed option's region list if Indian residency binds you. Read more ↓ Show less ↑
Part 01 · Orient

The Seclore platform family

This page covers Entrust PKI — the labelling foundation. The rest of the Seclore ARMOR platform:

Quick facts

30-second orientation
Product
Entrust PKI — private certificate authority
CRITICAL SCOPE
PRIVATE PKI — public TLS was sold to Sectigo, Sept 2025
What it issues
Machine identities, device certs, internal TLS, code signing
Deployment
On-premises or PKI as a Service
Vendor
Entrust — CEO Tony Ball, from 31 March 2026
Note
Todd Wilkinson is the STALE answer — 17 years, retired
Ownership
Private, via Datacard — Germany's Quandt family
Exited Sept 2025
Public TLS certificates — sold to Sectigo
Gartner
No MQ exists for HSM or key management — Market Guides only
Analyst standing
No HSM/key-management Leader placement verified
India engineering
Live hiring in Bengaluru and Pune
Data residency
On-premises; nShield as a Service has no India region
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, BIS scoping
Part 02 · Learn

Understand data classification before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Private certificate authority infrastructure — the certificates your own organisation issues and your own systems trust.

Unclassified data vs sensitivity-labelled data — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailEntrust PKI
How sensitive is this data?Unknown / inconsistentClearly labelled
Classification methodManual, user-dependentAutomated + assisted
CoveragePartial, forgottenConsistent, organisation-wide
The labelJust a tag in the cornerDrives real protection
Confidential fileLabelled, not protectedAuto-wrapped in EDRM
DLP accuracyCrude pattern-matchingActs on labels precisely
User handlingUnsure how to treat itLabel guides handling
DPDP data identificationAd-hocSystematic & evidenced

Classification's value is what it drives — Seclore's labels feed its follow-the-data EDRM, so confidential data is auto-protected. Best as the foundation of the ARMOR platform, not a standalone tool. Seclore is India-origin. TechBag positions it.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The analysis

Identify

Understand the content

Analyse data — documents, files, emails — by content, context and policy to determine its sensitivity, so classification is based on what the data actually is, not guesswork or user whim.

02
The tag

Label

Apply the sensitivity tag

Apply clear sensitivity labels — public, internal, confidential, restricted — to each piece of data, so its sensitivity and required handling are explicit, visible and consistent across the organisation.

03
The scale

Automate + Assist

At scale, with people

Classify automatically at scale (so it actually happens consistently) while assisting or prompting users where their judgement adds value — combining automation's consistency with human context where it matters.

04
The action

Drive Security

Labels power protection

Labels drive the rest of data security — telling DLP what to watch, EDRM what to protect, informing access and handling — and, distinctively, feed Seclore's persistent protection so 'confidential' data gets automatically protected.

05
The proof

Evidence Compliance

Prove data governance

Consistent classification evidences that you know and govern your data's sensitivity — supporting compliance (DPDP, GDPR) which expects organisations to identify and handle personal and sensitive data appropriately.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Identify, label, drive.

Data Classification labels your data by sensitivity — consistently, at scale — and drives real protection: the labelling foundation of the portfolio, and paired with the human firewall.

Identify
Auto classification

Automated Classification

Automatically classify data by analysing content, context and policy — so sensitivity is determined and labelled consistently at scale, without relying on every user to remember to classify correctly.

Identify
Content analysis

Content & Context Analysis

Analyse the actual content and context of data — recognising personal data, financials, IP, regulated information — to classify accurately, so labels reflect what data really is, not a superficial guess.

Identify
User-assisted

User-Assisted Classification

Prompt or assist users to classify where their judgement adds value (they know context automation can't), combining automation's consistency with human insight — and building a data-aware culture.

Label
Sensitivity labels

Clear Sensitivity Labels

Apply clear, consistent labels — public, internal, confidential, restricted (customisable to your scheme) — so every piece of data's sensitivity and handling requirements are explicit and visible to users and systems.

Label
Visual + metadata

Visual Markings & Metadata

Apply labels as both visual markings (headers, footers, watermarks) and metadata — so sensitivity is clear to people reading the document AND readable by security systems (DLP, EDRM) that act on it.

Label
Consistency

Consistent, Organisation-Wide

Ensure classification is consistent across the whole organisation — the same rules applied everywhere — so sensitivity means the same thing throughout, and the labels other controls rely on are trustworthy.

Drive
Drives DLP

Drives DLP Policy

Classification labels tell DLP what to watch and control — so DLP policies act on 'confidential' or 'restricted' data precisely, making DLP far more accurate and effective than pattern-matching alone.

Drive
Drives protection

Drives Persistent Protection (EDRM)

Distinctively, labels feed Seclore's persistent protection — a file classified 'confidential' can be automatically wrapped in follow-the-data EDRM controls — so classification leads directly to protection, not just a tag.

Drive
Informs access

Informs Access & Handling

Labels inform who should access data and how it should be handled — can it be emailed externally, printed, shared? — guiding both automated controls and user behaviour according to sensitivity.

Drive
Compliance

Compliance & Governance

Consistent classification evidences that you identify and govern your data's sensitivity — supporting DPDP, GDPR and sector mandates, which expect organisations to know and appropriately handle personal and sensitive data.

Drive
Integrations

Office, Email & Ecosystem

Integrate with the tools where data is created and used (Office, email, file systems, collaboration) and with the security stack (DLP, CASB, EDRM) — so classification fits naturally into workflows and drives the ecosystem.

Drive
Platform

The Labelling Foundation of ARMOR

Data Classification is the labelling foundation of the Seclore ARMOR platform — it labels the sensitive data DSPM discovers, so EDRM can protect it and AI-DLP can control it at the AI layer, according to its sensitivity.

See it, don’t just read it

Watch Seclore ARMOR in action

The overview, getting started, and the core workflows.

Entrust (official)·Overview

What is Entrust PKI?

Private PKI, presented by Entrust.

Entrust (official)·Platform

Cryptographic Security Platform Overview

Where PKI sits.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Entrust PKI

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Seclore ARMOR Data Classification apart.

01

Private PKI was not part of the Sectigo sale

This is the first thing to establish, because the internet will mislead you. Entrust sold its public TLS certificate business to Sectigo in September 2025 after browser distrust, and a great deal of well-ranked material still describes Entrust as a public certificate authority. Private PKI is a different product with a different trust model and it was not sold. The distinction is substantive rather than legal: a public certificate is trusted because browsers ship the root, while a private certificate is trusted because your organisation configured its systems to trust your CA. The browser distrust event was fatal to the first and does not carry the same implication for the second.

02

Machine identity is the volume problem nobody sized for

Human users get identity governance, joiner-mover-leaver processes and access reviews. Machine identities — services, workloads, containers, devices — vastly outnumber them in any modern estate and frequently get a spreadsheet. Every one of them needs a certificate, those certificates expire, and the number keeps growing as infrastructure becomes more automated. Private PKI is the infrastructure that makes issuing them a process rather than a series of individual favours, and the sizing that matters is workload count rather than headcount.

03

Shortening certificate lifetimes make automation mandatory

Industry certificate validity periods keep contracting, and the direction of travel is clear. Manual issuance and renewal scale badly against that: a process that worked when certificates lasted years becomes a recurring outage generator when they last months. A private CA with automation is what turns a shortening lifetime from an operational threat into a non-event, and it is the reason PKI investment is rising in organisations that had considered it a solved problem.

04

You define the trust, which is the point

With a private CA, your organisation decides what its systems trust and on what terms — issuance policy, validity periods, revocation, which identities may receive which certificates. That control is exactly what makes it appropriate for internal machine identity, where the relevant question is not whether the wider internet trusts a certificate but whether your systems should. It also means you are not dependent on a commercial CA's compliance record, which is a lesson the last two years made vivid.

05

The honest positioning

Buy Entrust PKI when you need certificates your own systems trust and you want the CA infrastructure run properly rather than improvised — particularly if machine identity volume is growing faster than your ability to issue by hand. Do not buy it expecting public TLS certificates, which Entrust no longer sells. And if you are already deploying nShield, running the private CA rooted in the same hardware is a coherent architecture rather than two separate purchases, which is a genuine reason to consider them together.

The foundation
You can’t protect the unclassified
Automated, not manual
Consistent at scale
Labels drive protection
Confidential → auto EDRM
Proof, not promises

The numbers behind the platform

$917M
Entrust revenue, 2024
Entrust
~3000 staff
Worldwide
Entrust
2026
Tony Ball became CEO, 31 March
Entrust newsroom
2025
Exited public TLS — sold to Sectigo, 18 Sept
Entrust
0 India SaaS regions
nShield as a Service is UK/US/DE/AU
Entrust docs
0 Gartner MQs
None exists for HSM or key management
Gartner

What your Seclore Classification journey looks like

Week 1Assess

Establish whether BIS is a gate

nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not. For Indian government tenders and several BFSI processes BIS is a threshold rather than a scoring criterion, so this one question can end the vendor comparison before it starts.

Week 1Assess

Separate public TLS from private PKI

Entrust sold its public certificate business to Sectigo in September 2025. If any part of your requirement is publicly trusted SSL, that is a different vendor now. Private PKI for internal certificates was not part of the sale. Buyers conflate these constantly.

Weeks 2–5Evaluate

Decide whether hardware is genuinely required

Software key management under your control satisfies many requirements at a fraction of the cost. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded it.

Weeks 4–10Deploy

Design Security World and the second appliance

Resilience and disaster recovery depend on how the Security World is designed, and a second appliance at another site is far easier to plan now than to retrofit. Budget the unit, the site and the network between them.

OngoingOperate

Test the Security World restore

Back up the Security World and then actually restore from it in a test. An untested backup of a hardware key domain is an assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
500+ reviews*
90% would recommend
Automated classification accuracy4.5
Consistency at scale4.6
Labels drive protection (EDRM)4.7
Vs bundled/standalone alternatives4.2
5
58%
4
31%
3
7%
2
3%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Public Sector
BIS was in the tender. That decided it before we compared a single specification.
Head of Infrastructure
Public Sector
Retail
We came for SSL certificates and learned they had sold that business. Better to find out in week one.
IT Manager
Retail
Banking
Security World meant the second site was a design decision rather than a migration.
Security Architect
Banking
Insurance
Budget the operations, not the appliance. The separation of duties took longer than the install.
Infrastructure Lead
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data-classification market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
EntrustThis page

BIS certified — a procurement gate in Indian tenders.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
EntrustThis page

Deep on hardware, PKI and identity; narrower since Sept 2025.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Seclore Classification vs the classification field

Microsoft Purview, Fortra/Titus, Boldon James and manual/no classification — honest lanes; the edge is classification that drives follow-the-data protection, from an India-origin pioneer.

DimensionEntrustThalesMicrosoft PurviewSecloreHashiCorp Vault
What it actually isHSM, private PKI, certificate lifecycle, identityKey management, HSM and encryption platformDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
BIS certification (India)nShield Connect XC holds it — a procurement GATENot established for LunaNot applicableNot applicableNot applicable
Hardware key custodynShield, with Security WorldLuna HSMDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
Verified analyst standingNone verified for HSM or key managementKuppingerCole Overall Leader 2025 ×2Microsoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Public TLS certificatesSOLD to Sectigo, Sept 2025 — no longer offeredNot a public CANot a public CANot a public CANot a public CA
India data residencyOn-premises appliances — no India SaaS regionOn-premises — no India SaaS regionIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundNew CEO Mar 2026; exited public TLS Sept 2025HSM operations: firmware, backup, separation of dutiesDKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitWhere BIS certification is a procurement gateKey custody with the broader software platformMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Seclore Classification if…

  • You want classification that drives real protection (EDRM), not just tags
  • You want it as the foundation of an integrated data-security strategy
  • You need consistent, automated classification (not failed manual)
  • You value an India-origin, DPDP-aware platform

Microsoft Purview if…

  • You're all-Microsoft and want bundled sensitivity labelling

Fortra/Titus or Boldon James if…

  • You want a dedicated classification specialist

Manual classification if…

  • Never — it's inconsistent and fails at scale

No classification if…

  • Never — you can't protect data whose sensitivity you don't know

Entrust PKI is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (count users; IT-hour cost as loaded rate). Estimates assume time saved and accuracy gained once classification is automated and consistent (making DLP and protection work) — but the far larger, unpriced win is the avoided breach and DPDP penalty (you can't protect or govern data whose sensitivity you don't know). Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Seclore ARMOR Data Classification is quote-priced (no public list) — by users, scope, and (typically) as the foundation of the wider ARMOR platform (EDRM, DSPM, AI-DLP), where its labels drive protection. Standalone labelling is commoditised — the value is what it drives. TechBag right-sizes it and quotes in INR/GST — Seclore is India-origin.

ARMOR Data Classification

Best as the data-security foundation

  • Auto-label by sensitivity, consistently at scale
  • Visual markings + metadata
  • Labels drive DLP, EDRM protection, compliance

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ The ARMOR platform

Best for label-to-protect

  • Add DSPM (discover), EDRM (protect), AI-DLP
  • Classification drives automatic protection
  • TechBag scopes the mix

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
BIS

Is Bureau of Indian Standards certification a gate in our procurement, or merely a preference?

2
Scope

Are we clear that Entrust no longer sells public TLS certificates? That business went to Sectigo.

3
Hardware

Do keys genuinely need to exist only in hardware, or would software key management under our control do?

4
Security World

Have we designed the key domain, and do we have a second appliance for resilience?

5
Separation of duties

Who administers the appliance, and who approves key use? They must be different people.

6
Backup

Have we backed up the Security World AND tested restoring from it?

7
Residency

Are we deploying on-premises? nShield as a Service has no India region.

8
CEO

Are we citing Tony Ball, CEO since 31 March 2026 — not the stale Todd Wilkinson answer?

9
Analyst claims

Have we avoided implying a Gartner Leader placement? No MQ exists for this category.

10
Commercials

Have we budgeted support, firmware, backup discipline and the second unit — not just the appliance?

FAQ

Questions buyers ask

No. Entrust sold its entire public TLS certificate business to Sectigo — announced January 2025, completed 18 September 2025 — after Chrome, Apple and Mozilla distrusted its public roots from November 2024 following a series of compliance failures. It exited rather than rescued the business. If you need publicly trusted SSL for an internet-facing site, Entrust is not the vendor and Sectigo or another public CA is where to look. Be careful, because a great deal of well-ranked material still describes Entrust as a public certificate authority — documentation, comparison articles, search summaries — and all of it predates the sale. We put this first on every Entrust page precisely because it is the most likely reason an evaluation here is wasted. What Entrust does still sell is coherent and genuinely strong: nShield hardware security modules, private PKI for the certificates your own systems trust, certificate lifecycle management, and identity verification built on Onfido. Private PKI in particular is easy to confuse with public TLS because they share vocabulary, and it was not part of the sale. The distinction is substantive: a public certificate is trusted because browsers ship the root, while a private certificate is trusted because your organisation configured its systems to trust your CA. The browser distrust event was fatal to the first and does not carry the same implication for the second.

Ready to build the classification foundation?

Scope automated data classification (label your data by sensitivity, consistently at scale), connect labels to real protection, or let a TechBag advisor plan your data-security strategy.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.