Your card and account numbers flow through a mainframe, a data centre and a cloud warehouse. They shouldn’t be cleartext in any of them — OpenText Voltage SecureData encrypts and tokenises card, account and ID fields without changing their format, on key servers you run yourself — in India if you choose.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText Voltage SecureData — format-preserving encryption and tokenisation, sold as SecureData Servers. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Sensitive fields are encrypted or tokenised in place, and the result keeps the same length and format as the original.
What consolidation actually replaces, dimension by dimension.
| Dimension | Cleartext columns and a token table | OpenText Voltage SecureData |
|---|---|---|
| A card number in the database | Cleartext, or AES that breaks the column | FF1 ciphertext of the same length and format |
| Keys | A key database to store, replicate and back up | Derived on demand after an identity check |
| Tokens | A token table that grows and must sync | Stateless tokens with no lookup table |
| Cloud analytics | Decrypt before loading, or do not migrate | Protected at ingestion; joins work on tokens |
| Test data | Production copies handed to developers | Protected values in the right format |
| What it is NOT | — | Document rights, data discovery or a price list |
The cheapest test is one data flow: protect a single feed at ingestion, then check that joins, reports and fraud rules still work on tokens.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Keys are derived on demand once an app or user passes an identity and policy check, so there is no key database to store, replicate or back up.
FF1 encryption keeps a card or account number at the same length and character set; stateless tokens and Format-Preserving Hash cover the other cases.
Apps call REST APIs or native Java, C# and .NET SDKs; native database functions and bulk-encryption tools de-identify large data sets in one pass.
Connectors protect data in Snowflake, BigQuery, Databricks, Teradata, Kafka and Spark; the Sentry gateway covers SaaS and packaged apps you cannot change.
Keys derived on demand, never stored — FF1 encryption and stateless tokens on servers you run, from mainframe to warehouse.
Voltage SecureData protects each sensitive field in place, so the systems that use it never notice.
NIST SP 800-38G FF1 keeps a 16-digit card number at 16 digits, so schemas, validation rules and reports need no change.
Secure Stateless Tokenization swaps values for tokens with no lookup table to grow, replicate or keep in sync across sites.
FPH anonymises fields such as click-stream IDs for good while keeping their format and referential integrity for joins.
Integrations cover Snowflake on AWS, Azure and GCP, BigQuery, Databricks Unity Catalog, Teradata and Trino, so analysts query tokens.
Hive, Impala, Kafka, NiFi, Spark and Sqoop integrations protect data as it lands on Cloudera or HPE Ezmeral platforms.
z/Protect brings the same FF1 and tokenisation to IBM z/OS, so data is protected before it leaves the mainframe for the cloud.
Key access follows Active Directory or OpenID identities checked against central policy; certified HSMs can generate the keys.
A gateway intercepts sensitive fields in network traffic to SaaS and packaged apps, for systems you cannot open to API calls.
OpenText maps it to PCI DSS, HIPAA, GLBA and GDPR, and says it fits PCI point-to-point encryption rules to cut audit scope.
The Voltage data-security family in brief, protected fields in cloud analytics, and a SecureData walk-through with Snowflake.
The whole Voltage family in two minutes; SecureData is the protect step between discovery and governance.
How protected fields stay usable in cloud analytics without being decrypted in the cloud.
A 33-minute walk through SecureData with Snowflake, recorded in 2021 when Voltage was part of Micro Focus.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Ordinary AES turns a 16-digit card number into a long binary value that breaks column types and validation. FF1 returns a value of the same length and character set, so OpenText says most rollouts need little or no app or schema change, and claims protection in 60 to 90 days.
Keys are derived on demand after an identity check, and Secure Stateless Tokenization needs no lookup table. That ends the store, replicate and back-up chores of key databases and token vaults, which matters when one data set lives in a data centre, three clouds and a mainframe.
Integrations for Snowflake, BigQuery, Databricks, Teradata, Trino and the Hadoop stack protect data at ingestion and keep it protected at rest and in use. Tokens are consistent, so analysts can join and count on them, and only the roles that need cleartext may decrypt.
No public price. The FIPS 140-2 certificate OpenText still cites, #2686, went to NIST’s historical list in April 2026, with no 140-3 successor found. It protects structured fields, not documents, and does not find sensitive data; that is the Voltage Data Security Platform, formerly Voltage Fusion.
List card, account, Aadhaar-style and contact fields, where each is created, and which roles truly need cleartext.
Choose FF1 where formats must hold, stateless tokens for card data, and Format-Preserving Hash where nobody needs it back.
Deploy appliances or containers in your own Indian site, tie policy to Active Directory, and add an HSM if required.
Protect one feed at ingestion into the warehouse, confirm joins and reports work on tokens, and time the throughput.
Extend to the next systems, document who can decrypt each field, and gather evidence for PCI DSS and DPDP Act reviews.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We tokenised card numbers in the core system and the fraud team still joins on them. No column type had to change.”
“Our Snowflake move was stuck on one audit question. Protecting fields at ingestion meant cleartext never reached the cloud.”
“Stateless keys spared us a key database across two data centres, but the first policy design took longer than planned.”
“The Java SDK was simple. Deciding which roles may decrypt which fields was the real project, so budget time for it.”
“Developers now get format-correct protected values instead of raw production extracts, and test runs still pass.”
“Strong technology, but no price list and a FIPS 140-2 certificate now on the historical list. Procurement pushed back.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data tokenisation and format-preserving encryption market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; FIPS 140-2 certificate now historical.
The grid nobody publishes — how many places it can run with your own keys, India included, vs how many ways it can protect a field.
FF1, stateless tokens and FPH; on-prem, K8s, three clouds, z/OS.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Thales CipherTrust Tokenization, HashiCorp Vault Transform, Skyflow, Google Cloud Sensitive Data Protection and Thales Transparent Encryption — on methods, keys, price, limits and India.
| Dimension | OpenText Voltage SecureData | Thales CipherTrust Tokenization | HashiCorp Vault Enterprise (Transform) | Skyflow Data Privacy Vault | Google Cloud Sensitive Data Protection | Thales CipherTrust Transparent Encryption |
|---|---|---|---|---|---|---|
| What it is | Field FPE and tokens | Tokenisation servers | Transform engine | Hosted privacy vault | De-identification API | At-rest file encryption |
| Deployment | Appliance, K8s, 3 clouds | Container or appliance | Self-managed or HCP | Skyflow-run service | Google Cloud only | Agent on each host |
| Protection methods | FF1, SST, FPH | FPE, tokens, masking | FF3-1, tokens, masking | Tokens + encryption | AES-SIV, FFX, HMAC | Whole files, no formats |
| Pricing model | Quoted per scope | Quote, with CM | Enterprise + ADP module | Enterprise contract | Per GiB transformed | Per protected host |
| Published entry price | Not published | Not published | No Enterprise price | Not published | $2.00/GiB after 1 GiB | Not published |
| Included vs add-on | Sentry, z/Protect apart | Needs CipherTrust Mgr | Not in Community | One API bundle | Inspection billed too | Access control included |
| Scale | Millions of ops/sec | Clustered servers | Cluster-bound | Not published | 10,000 requests/min | Measure the overhead |
| Keys and validation | Stateless; FIPS lapsed | CM keys, HSM root | Vault keys or BYOK | Confirm key custody | Cloud KMS-wrapped | CM keys, HSM option |
| Integrations and APIs | Snowflake to z/OS | REST, SDK, DB columns | Vault API | API and templates | Google data services | OS level, app-blind |
| Access policy | AD and OpenID policy | Masking by policy | Vault ACL policies | Field-level control | Cloud IAM | Privileged-user control |
| India data and keys | Your Indian servers | On-prem in India | Self-host in India | India vault since 2021 | Mumbai and Delhi | Your hosts in India |
| Support | Not published | Not published | Silver to Platinum | Not published | 3% of spend, min $29 | Not published |
| Lock-in and exit | Detokenise to leave | Detokenise to leave | FF3-1 is a standard | Data lives in the vault | Google-only service | Decrypt, then remove |
| Best fit | Regulated data at scale | Thales key estates | App-led engineering | API-first products | Google Cloud data | Unchangeable systems |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText Voltage SecureData is one of 21 encryption & rights management products TechBag carries. The Encryption & Rights Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (sensitive data fields in scope; engineer-hour cost). Estimates model engineering time spent on schema changes, per-application encryption code, masked test-data requests and audit evidence at an assumed 1.5 hours per field a year, with 70% of it removed by protecting fields in place under one central policy. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: OpenText prints no SecureData price in any currency. The quote is built from the key and protection servers, the integrations you need (Snowflake, Teradata, Hadoop and others), Sentry for SaaS apps, z/Protect for mainframes, and support. TechBag maps your fields and platforms first, then gets it quoted in INR with GST.
Best for apps and databases you control
Best for a broader rollout
Best for warehouses, SaaS and mainframes
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which fields need protection, and which must keep their exact length and format for apps and validation?
Where do you need reversible FF1 encryption, stateless tokens, or one-way Format-Preserving Hash?
Is every system covered — z/OS, Teradata, Hadoop, Snowflake, BigQuery, Databricks — or will you call the API?
Where will key servers run, across how many sites for availability, and will an HSM generate the keys?
Does a regulator or contract demand an active FIPS certificate? #2686 is historical; ask OpenText for its 140-3 status.
Which Active Directory or OpenID groups may decrypt each field, and who approves changes to that policy?
Which SaaS or packaged apps need the Sentry gateway because their code cannot be changed?
Does the quote itemise servers, integrations, Sentry and support? Ask for INR with GST and the renewal term.
Map the fields and platforms you need to protect first, or let a TechBag advisor scope a pilot that protects one data feed from source to warehouse.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.