The certificates your own systems trust — machine identities, device certificates, internal TLS, code signing. Read the scope carefully: this is private PKI. Entrust sold its public TLS certificate business to Sectigo in September 2025. the foundation the rest of your data security builds on, with labels that drive Seclore’s persistent protection.
Data residency & processing — two different questions
Where data lives
Yours — on-premises appliances in India
nShield HSMs are physical appliances in your own data centre, and private PKI can run on-premises too. Keys are generated and held in hardware you own, in India, under your administrators — the evidence is a serial number and an access log rather than a contract clause.
The constraint, stated plainly
No India region for the managed service
nShield as a Service runs in the UK, US, Germany and Australia. Entrust has live engineering hiring in Bengaluru and Pune, and that is people in India, not data in India — treating an engineering presence as a residency answer is the error that surfaces during an audit.
For a residency-bound Indian buyer the answer is appliances you operate, which is very likely what your regulator wanted anyway. Note what does not exist so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant — and we could not verify an HSM Leader placement for Entrust with any analyst. A search caution specific to this vendor: “Entrust India” surfaces several unrelated companies, including a Bengaluru wealth manager, so check you are reading about Entrust Corporation before drawing conclusions.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Entrust PKI — the labelling foundation. The rest of the Seclore ARMOR platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Private certificate authority infrastructure — the certificates your own organisation issues and your own systems trust.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | Entrust PKI |
|---|---|---|
| How sensitive is this data? | Unknown / inconsistent | Clearly labelled |
| Classification method | Manual, user-dependent | Automated + assisted |
| Coverage | Partial, forgotten | Consistent, organisation-wide |
| The label | Just a tag in the corner | Drives real protection |
| Confidential file | Labelled, not protected | Auto-wrapped in EDRM |
| DLP accuracy | Crude pattern-matching | Acts on labels precisely |
| User handling | Unsure how to treat it | Label guides handling |
| DPDP data identification | Ad-hoc | Systematic & evidenced |
Classification's value is what it drives — Seclore's labels feed its follow-the-data EDRM, so confidential data is auto-protected. Best as the foundation of the ARMOR platform, not a standalone tool. Seclore is India-origin. TechBag positions it.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Analyse data — documents, files, emails — by content, context and policy to determine its sensitivity, so classification is based on what the data actually is, not guesswork or user whim.
Apply clear sensitivity labels — public, internal, confidential, restricted — to each piece of data, so its sensitivity and required handling are explicit, visible and consistent across the organisation.
Classify automatically at scale (so it actually happens consistently) while assisting or prompting users where their judgement adds value — combining automation's consistency with human context where it matters.
Labels drive the rest of data security — telling DLP what to watch, EDRM what to protect, informing access and handling — and, distinctively, feed Seclore's persistent protection so 'confidential' data gets automatically protected.
Consistent classification evidences that you know and govern your data's sensitivity — supporting compliance (DPDP, GDPR) which expects organisations to identify and handle personal and sensitive data appropriately.
One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.
Data Classification labels your data by sensitivity — consistently, at scale — and drives real protection: the labelling foundation of the portfolio, and paired with the human firewall.
Automatically classify data by analysing content, context and policy — so sensitivity is determined and labelled consistently at scale, without relying on every user to remember to classify correctly.
Analyse the actual content and context of data — recognising personal data, financials, IP, regulated information — to classify accurately, so labels reflect what data really is, not a superficial guess.
Prompt or assist users to classify where their judgement adds value (they know context automation can't), combining automation's consistency with human insight — and building a data-aware culture.
Apply clear, consistent labels — public, internal, confidential, restricted (customisable to your scheme) — so every piece of data's sensitivity and handling requirements are explicit and visible to users and systems.
Apply labels as both visual markings (headers, footers, watermarks) and metadata — so sensitivity is clear to people reading the document AND readable by security systems (DLP, EDRM) that act on it.
Ensure classification is consistent across the whole organisation — the same rules applied everywhere — so sensitivity means the same thing throughout, and the labels other controls rely on are trustworthy.
Classification labels tell DLP what to watch and control — so DLP policies act on 'confidential' or 'restricted' data precisely, making DLP far more accurate and effective than pattern-matching alone.
Distinctively, labels feed Seclore's persistent protection — a file classified 'confidential' can be automatically wrapped in follow-the-data EDRM controls — so classification leads directly to protection, not just a tag.
Labels inform who should access data and how it should be handled — can it be emailed externally, printed, shared? — guiding both automated controls and user behaviour according to sensitivity.
Consistent classification evidences that you identify and govern your data's sensitivity — supporting DPDP, GDPR and sector mandates, which expect organisations to know and appropriately handle personal and sensitive data.
Integrate with the tools where data is created and used (Office, email, file systems, collaboration) and with the security stack (DLP, CASB, EDRM) — so classification fits naturally into workflows and drives the ecosystem.
Data Classification is the labelling foundation of the Seclore ARMOR platform — it labels the sensitive data DSPM discovers, so EDRM can protect it and AI-DLP can control it at the AI layer, according to its sensitivity.
The overview, getting started, and the core workflows.
Private PKI, presented by Entrust.
Where PKI sits.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Seclore ARMOR Data Classification apart.
This is the first thing to establish, because the internet will mislead you. Entrust sold its public TLS certificate business to Sectigo in September 2025 after browser distrust, and a great deal of well-ranked material still describes Entrust as a public certificate authority. Private PKI is a different product with a different trust model and it was not sold. The distinction is substantive rather than legal: a public certificate is trusted because browsers ship the root, while a private certificate is trusted because your organisation configured its systems to trust your CA. The browser distrust event was fatal to the first and does not carry the same implication for the second.
Human users get identity governance, joiner-mover-leaver processes and access reviews. Machine identities — services, workloads, containers, devices — vastly outnumber them in any modern estate and frequently get a spreadsheet. Every one of them needs a certificate, those certificates expire, and the number keeps growing as infrastructure becomes more automated. Private PKI is the infrastructure that makes issuing them a process rather than a series of individual favours, and the sizing that matters is workload count rather than headcount.
Industry certificate validity periods keep contracting, and the direction of travel is clear. Manual issuance and renewal scale badly against that: a process that worked when certificates lasted years becomes a recurring outage generator when they last months. A private CA with automation is what turns a shortening lifetime from an operational threat into a non-event, and it is the reason PKI investment is rising in organisations that had considered it a solved problem.
With a private CA, your organisation decides what its systems trust and on what terms — issuance policy, validity periods, revocation, which identities may receive which certificates. That control is exactly what makes it appropriate for internal machine identity, where the relevant question is not whether the wider internet trusts a certificate but whether your systems should. It also means you are not dependent on a commercial CA's compliance record, which is a lesson the last two years made vivid.
Buy Entrust PKI when you need certificates your own systems trust and you want the CA infrastructure run properly rather than improvised — particularly if machine identity volume is growing faster than your ability to issue by hand. Do not buy it expecting public TLS certificates, which Entrust no longer sells. And if you are already deploying nShield, running the private CA rooted in the same hardware is a coherent architecture rather than two separate purchases, which is a genuine reason to consider them together.
nShield Connect XC holds Bureau of Indian Standards certification and its closest competitor does not. For Indian government tenders and several BFSI processes BIS is a threshold rather than a scoring criterion, so this one question can end the vendor comparison before it starts.
Entrust sold its public certificate business to Sectigo in September 2025. If any part of your requirement is publicly trusted SSL, that is a different vendor now. Private PKI for internal certificates was not part of the sale. Buyers conflate these constantly.
Software key management under your control satisfies many requirements at a fraction of the cost. Hardware becomes necessary when keys must never exist in software — usually because a regulator asked specifically, a payments or PKI use case mandates it, or your risk assessment concluded it.
Resilience and disaster recovery depend on how the Security World is designed, and a second appliance at another site is far easier to plan now than to retrofit. Budget the unit, the site and the network between them.
Back up the Security World and then actually restore from it in a test. An untested backup of a hardware key domain is an assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“BIS was in the tender. That decided it before we compared a single specification.”
“We came for SSL certificates and learned they had sold that business. Better to find out in week one.”
“Security World meant the second site was a design decision rather than a migration.”
“Budget the operations, not the appliance. The separation of duties took longer than the install.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data-classification market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
BIS certified — a procurement gate in Indian tenders.
The grid nobody publishes — how deep the core capability is vs how broad the wider platform.
Deep on hardware, PKI and identity; narrower since Sept 2025.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Microsoft Purview, Fortra/Titus, Boldon James and manual/no classification — honest lanes; the edge is classification that drives follow-the-data protection, from an India-origin pioneer.
| Dimension | Entrust | Thales | Microsoft Purview | Seclore | HashiCorp Vault |
|---|---|---|---|---|---|
| What it actually is | HSM, private PKI, certificate lifecycle, identity | Key management, HSM and encryption platform | Document rights management | India-built EDRM | Secrets and encryption-as-a-service |
| BIS certification (India) | nShield Connect XC holds it — a procurement GATE | Not established for Luna | Not applicable | Not applicable | Not applicable |
| Hardware key custody | nShield, with Security World | Luna HSM | DKE holds one key; not an HSM product | Not an HSM vendor | Can integrate with an HSM |
| Verified analyst standing | None verified for HSM or key management | KuppingerCole Overall Leader 2025 ×2 | Microsoft, evaluated broadly elsewhere | Specialist — no Gartner EDRM MQ exists | Widely recognised in its category |
| Public TLS certificates | SOLD to Sectigo, Sept 2025 — no longer offered | Not a public CA | Not a public CA | Not a public CA | Not a public CA |
| India data residency | On-premises appliances — no India SaaS region | On-premises — no India SaaS region | India region via Advanced Data Residency | India-built; SaaS or self-hosted | Self-host anywhere, including India |
| Published pricing | Quote-only | Quote-only | $12/user/mo Purview add-on; E5 $60 | Quote (INR) | Free community edition |
| The thing to plan around | New CEO Mar 2026; exited public TLS Sept 2025 | HSM operations: firmware, backup, separation of duties | DKE breaks co-authoring, search and Copilot | Adoption — manual protection is rarely applied | Operationally heavy to run well |
| Best fit | Where BIS certification is a procurement gate | Key custody with the broader software platform | Microsoft estates with E5 needing document labels | Documents shared outside, India-built vendor | Engineering-owned secrets and encryption services |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Entrust PKI is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (count users; IT-hour cost as loaded rate). Estimates assume time saved and accuracy gained once classification is automated and consistent (making DLP and protection work) — but the far larger, unpriced win is the avoided breach and DPDP penalty (you can't protect or govern data whose sensitivity you don't know). Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Seclore ARMOR Data Classification is quote-priced (no public list) — by users, scope, and (typically) as the foundation of the wider ARMOR platform (EDRM, DSPM, AI-DLP), where its labels drive protection. Standalone labelling is commoditised — the value is what it drives. TechBag right-sizes it and quotes in INR/GST — Seclore is India-origin.
Best as the data-security foundation
Best for a broader rollout
Best for label-to-protect
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is Bureau of Indian Standards certification a gate in our procurement, or merely a preference?
Are we clear that Entrust no longer sells public TLS certificates? That business went to Sectigo.
Do keys genuinely need to exist only in hardware, or would software key management under our control do?
Have we designed the key domain, and do we have a second appliance for resilience?
Who administers the appliance, and who approves key use? They must be different people.
Have we backed up the Security World AND tested restoring from it?
Are we deploying on-premises? nShield as a Service has no India region.
Are we citing Tony Ball, CEO since 31 March 2026 — not the stale Todd Wilkinson answer?
Have we avoided implying a Gartner Leader placement? No MQ exists for this category.
Have we budgeted support, firmware, backup discipline and the second unit — not just the appliance?
Scope automated data classification (label your data by sensitivity, consistently at scale), connect labels to real protection, or let a TechBag advisor plan your data-security strategy.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.