The pioneer of the Data + AI Command Center — discover, secure, govern & safely USE all your data and AI on one graph, with Gencore AI to build safe enterprise AI. Now part of Veeam. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
The complete Thales platform — every linked card is a full intel page, from the Gencore AI flagship to data discovery, all on one graph.
One place that decides who can decrypt what.
The central key-management authority for the whole CipherTrust platform: it generates, stores, rotates and controls access to keys, and enforces the policy that decides which application, user or workload may use them. Deployable as a virtual appliance or as physical hardware, and it can be rooted in a Luna HSM so the master keys never exist in software at all. For an Indian regulated buyer this is the component that answers the auditor's question — not "is the data encrypted" but "who holds the key, and can they prove the cloud provider cannot decrypt it".
Files and databases, encrypted without touching the application.
An agent sits between the application and storage, encrypting data at rest and enforcing access policy without any change to the application itself — which is the entire point, because rewriting a working line-of-business system to add encryption is how encryption projects die. It also enforces privileged-user access control, so a root or DBA account can administer a system without reading the data inside it. That separation is exactly what an RBI or SEBI reviewer asks about when they ask who can see production data.
Keys generated in hardware that never leaves your building.
A tamper-resistant hardware appliance that generates and stores cryptographic keys and performs operations inside the device — key material never leaves in usable form. This is the strongest available answer to a key-custody question and the one Indian BFSI and government buyers most often need: the key exists in a physical box in your data centre, and no cloud provider, no vendor and no administrator can extract it. Luna also underpins the wider platform, since CipherTrust Manager can be rooted in it.
You cannot encrypt what nobody knows exists.
Scans structured and unstructured stores to find sensitive data and classify it, which is the unglamorous prerequisite to every other product on this page. Under India's DPDP Act the first genuine question is not how you protect personal data but where it is, and most organisations cannot answer that from an inventory. Discovery output feeds the encryption and access policy directly, so classification becomes an input to protection rather than a report nobody acts on.
The credentials your applications use, held properly.
Centralised management of the API keys, database passwords, certificates and tokens that applications and pipelines need — the credentials that in most organisations sit in configuration files, environment variables and, regularly, source control. KuppingerCole named Thales an Overall Leader in its 2025 Leadership Compass for Enterprise Secrets Management. Worth knowing that TechBag also sells HashiCorp Vault in this space; which one fits depends on whether you want secrets inside your key-management platform or as a separate engineering-led service.
Bring-your-own-key across cloud providers, from one console
Acquired Dec 2023 for $3.6B — data and application security, a separate portfolio
Thales is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide shows how the category splits and which part is yours. →
Cloud providers encrypt data at rest by default, and it genuinely helps — against a stolen disk. It does nothing about the provider, because they hold the key. When an Indian regulator asks about data protection, the question underneath is not whether the data is encrypted but whether you can demonstrate that a third party cannot decrypt it— and provider-managed encryption cannot answer that at all. Thales exists to invert the arrangement: keys generated inside a Luna HSM in your own data centre, under a CipherTrust Manager your people operate, so the answer to the auditor is evidence rather than a contractual assurance. Everything else on this page — transparent encryption, discovery, secrets — is built on that one idea.
Most cloud encryption answers the question "is this data encrypted" and leaves the more important one untouched: who can decrypt it. If the provider holds the key, the honest answer is that they can, and a lawful order to them does not involve you. Thales exists to invert that. Keys generated in a Luna HSM in your data centre, under a CipherTrust Manager you operate, mean the answer to the auditor is demonstrable rather than contractual.
The reason encryption projects stall is rarely the cryptography — it is that protecting data properly seems to require changing every application that touches it. Transparent Encryption puts an agent between the application and storage, so the application is unchanged and the data on disk is protected. That is what makes it deployable against legacy line-of-business systems nobody will refactor.
A root account or a DBA needs to keep a system running. It does not need to read customer records to do that, yet in most estates the two are the same permission. Transparent Encryption separates them, so administrators can operate a system without seeing the data inside it — which is precisely the control an RBI or SEBI reviewer is probing when they ask who has access to production data.
Thales is an Overall Leader in the 2025 KuppingerCole Leadership Compass for Data Security Platforms, and an Overall Leader in the 2025 Compass for Enterprise Secrets Management. Note what does not exist, because the absence is easy to misread: Gartner publishes no Magic Quadrant for hardware security modules or key management — Market Guides only, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any that implies one is misleading you.
Two engineering competence centres in India, with Noida specifically the Cyber and Digital centre; more than 2,200 staff and around 450 more being hired during 2026. Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's NBFC outsourcing directions. That is a materially stronger signal than a distributor logo — it means the vendor has already done the work of understanding what an Indian regulator expects.
Start with the Data Command Center (discover & map your data — the foundation), then add Privacy, DSPM and Governance, and build safe AI with Gencore. All on one DataAI Command Graph.
Every claim on this hub traces to one of these public signals.
Leadership Compass, Data Security Platforms
Leadership Compass, Enterprise Secrets Management
Two engineering centres; Noida is Cyber & Digital
Growing, not consolidating
Thales publishes its own mapped material
Cyber business expanded, not divested
None for HSM or key management — Market Guides only
CipherTrust as-a-Service is EU/NA — go on-premises
The platform, presented by Thales.
The hardware key custody layer.
Encrypting without changing the application.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a Thales product: competitive position vs category momentum.
The key authority the rest is rooted in.
Key custody vs the field — where Thales wins on hardware-rooted control.
Key custody, in hardware, with India engineering.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What is actually driving this?
2. How strong does key custody need to be?
3. Where must this run?
The question that separates real encryption from a compliance checkbox — and the one an Indian regulator actually asks.
Read →Tamper-resistant key custody explained without the acronyms, and an honest account of when software key management is enough.
Read →Why 'the data is encrypted' is not an answer, and what evidence a reviewer is actually looking for.
Read →How transparent encryption gets around the reason most encryption projects stall before they start.
Read →Key custody, hardware roots and document rights are three distinct purchases that buyers routinely conflate.
Read →Deployment model, key custody and who administers the HSM — three answers that shape the whole quote.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Software key management under your control, or keys that exist only inside tamper-resistant hardware? That single answer separates a CipherTrust Manager deployment from one rooted in a Luna HSM, and it usually comes from your regulator or your own risk appetite rather than from a feature comparison.
CipherTrust as-a-Service runs in Europe and North America only — there is no India region. If Indian residency binds you, the answer is on-premises or virtual CipherTrust Manager with Luna HSM in your own data centre. Establish this before a demo, because it changes the entire architecture.
Discovery and classification is the step teams skip and then repeat. You cannot scope an encryption project against an inventory nobody trusts, and under DPDP the location of personal data is the first question you will be asked. Run discovery first, then size the rest against what it finds.
Hardware key custody creates a role nobody had before, with genuine separation-of-duties requirements — the person who administers the appliance should not also be the person who approves key use. Name those people during procurement, because retrofitting the separation afterwards is considerably harder.
The promise is that the application needs no change. Test that against your least modern, most business-critical system rather than a clean one, because that is the system the project actually has to survive. Measure the performance overhead there too.
An HSM is a physical appliance with a purchase cost, a support contract and, if you want resilience, more than one of them across sites. Add the operational work of running them. TechBag models the whole thing and quotes in INR with GST.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| CipherTrust Manager | Quote-only | Virtual appliance or physical hardware | The central key authority for everything else |
| Transparent Encryption | Quote-only, typically per protected host | Agent-based, no application changes | Legacy systems nobody will rewrite |
| Luna HSM | Quote-only — hardware purchase plus support | A physical appliance in your data centre | When keys must never exist in software |
| Discovery & Classification | Quote-only | Scans structured and unstructured stores | DPDP scoping before you encrypt anything |
| Secrets Management | Quote-only | Inside the CipherTrust platform | If you want secrets in the key platform, not beside it |
Modular, priced by quote in USD (now a Veeam company) — TechBag scopes just the modules you need, adds INR/GST, and frames it against DPDP + the AI-governance frameworks.
Cloud providers encrypt data at rest by default, and it is genuinely useful — against a stolen disk. It does nothing about the provider itself, because they hold the key. When a regulator asks about data protection they are asking whether you can demonstrate that a third party cannot decrypt your data, and provider-managed encryption cannot answer that. Get clear on which question you are being asked before you buy anything.
CipherTrust as-a-Service runs in Europe and North America. There is no India region, and no amount of Indian engineering presence changes that — people in India and data in India are different things, and the Noida centre is people. If Indian residency binds you, plan for on-premises or virtual deployment from the start rather than discovering the constraint after a cloud proof of concept.
An HSM is not software you install and forget. It is a physical appliance requiring firmware maintenance, backup of the security domain, separation of duties between administrators, and — if you want to survive a site failure — a second one somewhere else. Every one of those is manageable. None is free, and teams that budget only the appliance are surprised twice.
Encryption projects scoped against an asset inventory rather than a discovery scan consistently miss stores nobody remembered: the reporting replica, the analytics extract, the file share a department set up years ago. Those are exactly where a breach or a DPDP complaint originates. Discovery first is slower to start and considerably faster to finish.
They solve different problems. Encryption protects data while preserving the ability to recover it with a key. Tokenisation replaces a sensitive value with a stand-in so downstream systems never hold the real thing at all — which is usually the better answer for cardholder data flowing through systems that have no business seeing it. Choosing the wrong one produces either weak protection or an unnecessarily painful integration.
The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Six trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*Directionally consistent with public analyst forecasts; verify exact figures before quoting. The takeaway: safe AI and AI governance compound fastest — exactly where Securiti (Gencore AI, LLM Firewall, Agent Commander) is placed.
Indian regulators increasingly ask who can decrypt, not merely whether data is encrypted.
What it means for you
Provider-managed encryption stops being an acceptable answer, and customer-held keys move from best practice to requirement.
The Act's practical first question is where personal data lives, which most organisations cannot answer.
What it means for you
Discovery and classification budgets are being approved ahead of encryption budgets, reversing the usual order.
Hardware bought today will still be in service when post-quantum algorithms are mandated.
What it means for you
Crypto-agility is becoming a purchase criterion rather than a roadmap conversation — ask what a firmware path looks like.
Machine credentials and human privileged access are increasingly bought as distinct problems.
What it means for you
Expect to evaluate secrets platforms against engineering-led tools rather than against your PAM vendor.
Buyers adopt cloud services while insisting the key root stays in their own building.
What it means for you
Hold-your-own-key architectures grow, along with the functional trade-offs they impose on cloud services.
Application-level and database-level protection is displacing perimeter-only thinking.
What it means for you
The blast radius of a compromised network shrinks, at the cost of more integration work per system.
Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — module scoping, honest OneTrust/Wiz/Collibra/Palo Alto comparison, the India DPDP/AI-governance framing, GST invoicing and support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.