Talk to us
by OpenTextTechBag Intel Page

OpenText Voltage SecureData

Your card and account numbers flow through a mainframe, a data centre and a cloud warehouse. They shouldn’t be cleartext in any of them — OpenText Voltage SecureData encrypts and tokenises card, account and ID fields without changing their format, on key servers you run yourself — in India if you choose.

Format-preserving FF1 encryptionStateless keys and tokensSelf-hosted, India if you choose

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText prints no SecureData price; servers, integrations and support are scoped and quoted
Quote
Standard
Format-preserving encryption to SP 800-38G; OpenText says it holds and licenses the FF1 patents
NIST FF1
Analysts
OpenText overall, in KuppingerCole’s 2025 Leadership Compass for Data Security Platforms
KuppingerCole Leader
India
Key and protection servers run on infrastructure you choose, in India or anywhere else
Your servers

Quick answer

OpenText Voltage SecureData protects sensitive fields such as card, account and ID numbers without changing their format, using NIST FF1 format-preserving encryption, stateless tokenisation and keys derived on demand. Apps, databases and warehouses such as Snowflake, BigQuery or Databricks keep working on protected values. You run it yourself: on-prem, on VMware or Kubernetes, or from the AWS, Azure and Google marketplaces. It is quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText Voltage SecureData — format-preserving encryption and tokenisation, sold as SecureData Servers. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
This page.
You’re here
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Format-preserving encryption, tokenisation and hashing for structured data, sold as SecureData Servers
Maker
Open Text Corporation, Waterloo, Canada; CEO Ayman Antoun since April 2026
Lineage
Voltage Security, bought by HP in 2015; reached OpenText with Micro Focus in January 2023
Method
NIST SP 800-38G FF1 encryption, Secure Stateless Tokenization and keys derived on demand
Platforms
Windows, Linux, IBM z/OS and Hadoop; Snowflake, BigQuery, Databricks, Teradata and Trino integrations
Deployment
Virtual appliances or Kubernetes containers, on-prem or via the AWS, Azure and Google marketplaces
Validation
FIPS 140-2 certificate #2686 moved to NIST’s historical list in April 2026; no 140-3 certificate found
Price
Not published in any currency; quoted by OpenText on the scope you need
India
Self-hosted, so key servers and protected data sit wherever you install them
In India via
TechBag — field mapping, quote in INR with GST, a pilot on one data flow
Part 02 · Learn

Understand format-preserving protection before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is format-preserving protection?

Sensitive fields are encrypted or tokenised in place, and the result keeps the same length and format as the original.

Cleartext columns and a token table vs format-preserving protection — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionCleartext columns and a token tableOpenText Voltage SecureData
A card number in the databaseCleartext, or AES that breaks the columnFF1 ciphertext of the same length and format
KeysA key database to store, replicate and back upDerived on demand after an identity check
TokensA token table that grows and must syncStateless tokens with no lookup table
Cloud analyticsDecrypt before loading, or do not migrateProtected at ingestion; joins work on tokens
Test dataProduction copies handed to developersProtected values in the right format
What it is NOT—Document rights, data discovery or a price list

The cheapest test is one data flow: protect a single feed at ingestion, then check that joins, reports and fraud rules still work on tokens.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where keys come from

Key Servers

Stateless key management

Keys are derived on demand once an app or user passes an identity and policy check, so there is no key database to store, replicate or back up.

02
What happens to each field

Protection

FF1, stateless tokens, hashing

FF1 encryption keeps a card or account number at the same length and character set; stateless tokens and Format-Preserving Hash cover the other cases.

03
How applications call it

Interfaces

APIs, SDKs and database functions

Apps call REST APIs or native Java, C# and .NET SDKs; native database functions and bulk-encryption tools de-identify large data sets in one pass.

04
Where protected data flows

Integrations

SecureData Integrations and Sentry

Connectors protect data in Snowflake, BigQuery, Databricks, Teradata, Kafka and Spark; the Sentry gateway covers SaaS and packaged apps you cannot change.

Keys derived on demand, never stored — FF1 encryption and stateless tokens on servers you run, from mainframe to warehouse.

Part 03 · Evaluate

Nine capabilities. Protect, integrate, govern.

Voltage SecureData protects each sensitive field in place, so the systems that use it never notice.

Protect
FF1 encryption

Encrypted, same format

NIST SP 800-38G FF1 keeps a 16-digit card number at 16 digits, so schemas, validation rules and reports need no change.

Protect
Tokenisation

Tokens without a token vault

Secure Stateless Tokenization swaps values for tokens with no lookup table to grow, replicate or keep in sync across sites.

Protect
Format-Preserving Hash

One-way, still joinable

FPH anonymises fields such as click-stream IDs for good while keeping their format and referential integrity for joins.

Integrate
Warehouses

Protected data in analytics

Integrations cover Snowflake on AWS, Azure and GCP, BigQuery, Databricks Unity Catalog, Teradata and Trino, so analysts query tokens.

Integrate
Pipelines

Hadoop and Kafka streams

Hive, Impala, Kafka, NiFi, Spark and Sqoop integrations protect data as it lands on Cloudera or HPE Ezmeral platforms.

Integrate
Mainframe

z/OS before the move

z/Protect brings the same FF1 and tokenisation to IBM z/OS, so data is protected before it leaves the mainframe for the cloud.

Govern
Key policy

Identity decides who decrypts

Key access follows Active Directory or OpenID identities checked against central policy; certified HSMs can generate the keys.

Govern
Sentry

SaaS without code changes

A gateway intercepts sensitive fields in network traffic to SaaS and packaged apps, for systems you cannot open to API calls.

Govern
Compliance

A smaller PCI audit scope

OpenText maps it to PCI DSS, HIPAA, GLBA and GDPR, and says it fits PCI point-to-point encryption rules to cut audit scope.

See it, don’t just read it

Watch Voltage SecureData in action

The Voltage data-security family in brief, protected fields in cloud analytics, and a SecureData walk-through with Snowflake.

OpenText (official)·Overview, 2025

OpenText data security: Discover, protect, and govern sensitive data everywhere

The whole Voltage family in two minutes; SecureData is the protect step between discovery and governance.

Voltage Unplugged (official OpenText channel)·Explainer, 2023

Secure Cloud Analytics with Voltage

How protected fields stay usable in cloud analytics without being decrypted in the cloud.

Voltage Unplugged (official OpenText channel)·Webinar, 2021

Voltage SecureData for Snowflake - Solution Overview

A 33-minute walk through SecureData with Snowflake, recorded in 2021 when Voltage was part of Micro Focus.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText Voltage SecureData

Encryption usually breaks the systems it protects. Voltage SecureData keeps every field’s format intact.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Protect the field, keep the format

Ordinary AES turns a 16-digit card number into a long binary value that breaks column types and validation. FF1 returns a value of the same length and character set, so OpenText says most rollouts need little or no app or schema change, and claims protection in 60 to 90 days.

02

No key database, no token vault

Keys are derived on demand after an identity check, and Secure Stateless Tokenization needs no lookup table. That ends the store, replicate and back-up chores of key databases and token vaults, which matters when one data set lives in a data centre, three clouds and a mainframe.

03

Analytics on protected data

Integrations for Snowflake, BigQuery, Databricks, Teradata, Trino and the Hadoop stack protect data at ingestion and keep it protected at rest and in use. Tokens are consistent, so analysts can join and count on them, and only the roles that need cleartext may decrypt.

04

Where it stops

No public price. The FIPS 140-2 certificate OpenText still cites, #2686, went to NIST’s historical list in April 2026, with no 140-3 successor found. It protects structured fields, not documents, and does not find sensitive data; that is the Voltage Data Security Platform, formerly Voltage Fusion.

The idea
Protect the field, keep its format
The residency
Self-hosted: your servers, in India if you choose
The price
Quote-only; no list price published
Proof, not promises

The numbers behind the platform

SP 800-38G
the NIST publication whose FF1 mode SecureData uses for format-preserving encryption
— NIST
50+ countries
where OpenText says large enterprises rely on Voltage data protection
— Vendor
60–90 days
OpenText’s claimed time to end-to-end protection, helped by little or no schema change
— Vendor
128-bit
the security OpenText says AES-256 keeps even against an optimal quantum attack
— Vendor
3 cloud marketplaces
AWS, Microsoft Azure and Google Cloud list SecureData for self-managed deployment
— Vendor
2026
the year NIST moved Voltage’s FIPS 140-2 certificate #2686 to its historical list
— NIST

What your Voltage SecureData rollout looks like

Week 1Model

Map the fields that matter

List card, account, Aadhaar-style and contact fields, where each is created, and which roles truly need cleartext.

Week 2Decide

Pick a method per field

Choose FF1 where formats must hold, stateless tokens for card data, and Format-Preserving Hash where nobody needs it back.

Weeks 3–4Pilot

Stand up the key servers

Deploy appliances or containers in your own Indian site, tie policy to Active Directory, and add an HSM if required.

Month 2Prove

Protect one flow end to end

Protect one feed at ingestion into the warehouse, confirm joins and reports work on tokens, and time the throughput.

Month 3Commit

Widen it and show the auditor

Extend to the next systems, document who can decrypt each field, and gather evidence for PCI DSS and DPDP Act reviews.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
38+ reviews*
80% would recommend
Format preservation4.5
Performance at scale4.3
Platform integrations4.1
Ease of deployment3.5
Value for money3.6
5★
42%
4★
38%
3★
14%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We tokenised card numbers in the core system and the fraud team still joins on them. No column type had to change.”
Head of Data Security
BFSI
Insurance
“Our Snowflake move was stuck on one audit question. Protecting fields at ingestion meant cleartext never reached the cloud.”
Data Platform Lead
Insurance
Telecom
“Stateless keys spared us a key database across two data centres, but the first policy design took longer than planned.”
Security Architect
Telecom
Healthcare
“The Java SDK was simple. Deciding which roles may decrypt which fields was the real project, so budget time for it.”
Application Architect
Healthcare
IT Services
“Developers now get format-correct protected values instead of raw production extracts, and test runs still pass.”
Engineering Manager
IT Services
Fintech
“Strong technology, but no price list and a FIPS 140-2 certificate now on the historical list. Procurement pushed back.”
CISO
Fintech
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the data tokenisation and format-preserving encryption market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Tokenisation & FPE Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText Voltage SecureDataThis page

Quote-only; FIPS 140-2 certificate now historical.

Grid 02 · The architecture

Run-Anywhere × Protection Depth

The grid nobody publishes — how many places it can run with your own keys, India included, vs how many ways it can protect a field.

Deep but provider-runPortable, deep protectionSingle-cloud basicsPortable, at rest only
OpenText Voltage SecureDataThis page

FF1, stateless tokens and FPH; on-prem, K8s, three clouds, z/OS.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Voltage SecureData vs the tokenisation field

Against Thales CipherTrust Tokenization, HashiCorp Vault Transform, Skyflow, Google Cloud Sensitive Data Protection and Thales Transparent Encryption — on methods, keys, price, limits and India.

DimensionOpenText Voltage SecureDataThales CipherTrust TokenizationHashiCorp Vault Enterprise (Transform)Skyflow Data Privacy VaultGoogle Cloud Sensitive Data ProtectionThales CipherTrust Transparent Encryption
What it isField FPE and tokensTokenisation serversTransform engineHosted privacy vaultDe-identification APIAt-rest file encryption
DeploymentAppliance, K8s, 3 cloudsContainer or applianceSelf-managed or HCPSkyflow-run serviceGoogle Cloud onlyAgent on each host
Protection methodsFF1, SST, FPHFPE, tokens, maskingFF3-1, tokens, maskingTokens + encryptionAES-SIV, FFX, HMACWhole files, no formats
Pricing modelQuoted per scopeQuote, with CMEnterprise + ADP moduleEnterprise contractPer GiB transformedPer protected host
Published entry priceNot publishedNot publishedNo Enterprise priceNot published$2.00/GiB after 1 GiBNot published
Included vs add-onSentry, z/Protect apartNeeds CipherTrust MgrNot in CommunityOne API bundleInspection billed tooAccess control included
ScaleMillions of ops/secClustered serversCluster-boundNot published10,000 requests/minMeasure the overhead
Keys and validationStateless; FIPS lapsedCM keys, HSM rootVault keys or BYOKConfirm key custodyCloud KMS-wrappedCM keys, HSM option
Integrations and APIsSnowflake to z/OSREST, SDK, DB columnsVault APIAPI and templatesGoogle data servicesOS level, app-blind
Access policyAD and OpenID policyMasking by policyVault ACL policiesField-level controlCloud IAMPrivileged-user control
India data and keysYour Indian serversOn-prem in IndiaSelf-host in IndiaIndia vault since 2021Mumbai and DelhiYour hosts in India
SupportNot publishedNot publishedSilver to PlatinumNot published3% of spend, min $29Not published
Lock-in and exitDetokenise to leaveDetokenise to leaveFF3-1 is a standardData lives in the vaultGoogle-only serviceDecrypt, then remove
Best fitRegulated data at scaleThales key estatesApp-led engineeringAPI-first productsGoogle Cloud dataUnchangeable systems
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Voltage SecureData if…

  • ✓Card, account or identity numbers must be protected in place without changing column types or application logic
  • ✓The same data crosses a mainframe, Teradata or Hadoop and a cloud warehouse such as Snowflake or BigQuery
  • ✓You want keys derived on demand and tokens without a lookup table, on servers you control in India

Compare alternatives if…

  • ✓You already run CipherTrust Manager — Thales tokenisation keeps every key under one authority
  • ✓You want a price you can read first — Google Sensitive Data Protection bills per GiB transformed
  • ✓Your developers would rather call a hosted vault — Skyflow keeps the real values out of your stack

Do not expect…

  • ✓A published price, or a current FIPS 140-3 certificate
  • ✓Document rights management, or discovery of where sensitive data lives
  • ✓A Gartner ranking — the verified analyst result is KuppingerCole’s 2025 Leadership Compass

OpenText Voltage SecureData is one of 21 encryption & rights management products TechBag carries. The Encryption & Rights Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does hand-built field encryption cost you?

Drag the sliders (sensitive data fields in scope; engineer-hour cost). Estimates model engineering time spent on schema changes, per-application encryption code, masked test-data requests and audit evidence at an assumed 1.5 hours per field a year, with 70% of it removed by protecting fields in place under one central policy. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual data-protection engineering cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: OpenText prints no SecureData price in any currency. The quote is built from the key and protection servers, the integrations you need (Snowflake, Teradata, Hadoop and others), Sentry for SaaS apps, z/Protect for mainframes, and support. TechBag maps your fields and platforms first, then gets it quoted in INR with GST.

SecureData Servers

Best for apps and databases you control

  • Quote-only; scoped by servers and sites
  • FF1 encryption, stateless tokens and FPH
  • REST APIs plus Java, C# and .NET SDKs

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Integrations, Sentry and z/Protect

Best for warehouses, SaaS and mainframes

  • Quoted on top of the core servers
  • Snowflake, BigQuery, Databricks, Teradata
  • Sentry gateway for apps you cannot change

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Field inventory

Which fields need protection, and which must keep their exact length and format for apps and validation?

2
Method

Where do you need reversible FF1 encryption, stateless tokens, or one-way Format-Preserving Hash?

3
Platforms

Is every system covered — z/OS, Teradata, Hadoop, Snowflake, BigQuery, Databricks — or will you call the API?

4
Key servers

Where will key servers run, across how many sites for availability, and will an HSM generate the keys?

5
Validation

Does a regulator or contract demand an active FIPS certificate? #2686 is historical; ask OpenText for its 140-3 status.

6
Identity

Which Active Directory or OpenID groups may decrypt each field, and who approves changes to that policy?

7
Untouchable apps

Which SaaS or packaged apps need the Sentry gateway because their code cannot be changed?

8
Licence

Does the quote itemise servers, integrations, Sentry and support? Ask for INR with GST and the renewal term.

FAQ

Questions buyers ask

It is OpenText’s data-centric protection software, sold as Voltage SecureData Servers. It encrypts, tokenises or hashes sensitive structured fields while keeping their length and format, so applications, databases and analytics keep working on protected values. You run it on-prem, in VMs, in Kubernetes or in your own cloud account.

Ready to evaluate Voltage SecureData?

Map the fields and platforms you need to protect first, or let a TechBag advisor scope a pilot that protects one data feed from source to warehouse.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.