Vendor hubAI · Discovery · Privacy · DSPM · GovernTechBag Intel Hub

Thales

The pioneer of the Data + AI Command Center — discover, secure, govern & safely USE all your data and AI on one graph, with Gencore AI to build safe enterprise AI. Now part of Veeam. This hub is your complete intel file.

5 intel pages insideData + AI on one graphIndia DPDP via TechBag

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

Founded2019 · San Jose
Now part ofVeeam (~$1.725B)
FoundationDataAI Command Graph
AI flagshipGencore AI
IndiaBangalore R&D · DPDP

Quick answer

Thales is a French aerospace, defence and technology group whose cybersecurity arm — Thales Cloud Protection & Licensing — sells the thing most Indian regulated buyers actually need and rarely get: encryption where the customer holds the keys. The portfolio splits into two halves. CipherTrust Data Security Platform is the software layer: a central key manager plus transparent encryption for files and databases, application-level protection, tokenisation, data discovery and classification, and secrets management. Luna HSM is the hardware layer — a physical appliance that generates and stores keys in tamper-resistant hardware and never lets the key material out. Together they answer the question a regulator asks and a cloud provider cannot: who can decrypt this data, and can you prove it is not us. On analyst standing, Thales is the strongest vendor in this guide. It is an Overall Leader in the 2025 KuppingerCole Leadership Compass for Data Security Platforms, and an Overall Leader in the 2025 Compass for Enterprise Secrets Management. Note what does not exist rather than inferring silence means absence: Gartner publishes no Magic Quadrant for hardware security modules or key management at all — only Market Guides, which have no Leader quadrant — so nobody in this category can claim one, and any vendor implying otherwise is misleading you. The India position is unusually concrete. Thales runs two engineering competence centres in the country, and Noida is specifically the Cyber and Digital centre; it reports more than 2,200 staff in India and has said it is hiring around 450 more during 2026. It publishes its own India-specific compliance material mapped to SEBI's CSCRF and RBI's NBFC outsourcing directions, which is a stronger signal of genuine India go-to-market than a partner logo. One honest constraint, and it is the first thing to establish: CipherTrust as-a-Service runs in Europe and North America only — there is no India region. For a regulated Indian buyer that pushes you to on-premises or virtual CipherTrust Manager with Luna HSM in your own data centre, which is very likely what you wanted anyway, because it puts the keys in your building rather than in a vendor's. Read more ↓ Show less ↑
The portfolio

Five intel pages. One data + AI graph.

The complete Thales platform — every linked card is a full intel page, from the Gencore AI flagship to data discovery, all on one graph.

The key authorityIntel page →

CipherTrust Manager

One place that decides who can decrypt what.

The central key-management authority for the whole CipherTrust platform: it generates, stores, rotates and controls access to keys, and enforces the policy that decides which application, user or workload may use them. Deployable as a virtual appliance or as physical hardware, and it can be rooted in a Luna HSM so the master keys never exist in software at all. For an Indian regulated buyer this is the component that answers the auditor's question — not "is the data encrypted" but "who holds the key, and can they prove the cloud provider cannot decrypt it".

Virtual or hardware · HSM-rootableExplore
Encrypt without rewritingIntel page →

CipherTrust Transparent Encryption

Files and databases, encrypted without touching the application.

An agent sits between the application and storage, encrypting data at rest and enforcing access policy without any change to the application itself — which is the entire point, because rewriting a working line-of-business system to add encryption is how encryption projects die. It also enforces privileged-user access control, so a root or DBA account can administer a system without reading the data inside it. That separation is exactly what an RBI or SEBI reviewer asks about when they ask who can see production data.

No application changes requiredExplore
Hardware key custodyIntel page →

Luna HSM

Keys generated in hardware that never leaves your building.

A tamper-resistant hardware appliance that generates and stores cryptographic keys and performs operations inside the device — key material never leaves in usable form. This is the strongest available answer to a key-custody question and the one Indian BFSI and government buyers most often need: the key exists in a physical box in your data centre, and no cloud provider, no vendor and no administrator can extract it. Luna also underpins the wider platform, since CipherTrust Manager can be rooted in it.

Key material never leaves the deviceExplore
Find it before you protect itIntel page →

CipherTrust Data Discovery & Classification

You cannot encrypt what nobody knows exists.

Scans structured and unstructured stores to find sensitive data and classify it, which is the unglamorous prerequisite to every other product on this page. Under India's DPDP Act the first genuine question is not how you protect personal data but where it is, and most organisations cannot answer that from an inventory. Discovery output feeds the encryption and access policy directly, so classification becomes an input to protection rather than a report nobody acts on.

The DPDP starting pointExplore
Machine credentialsIntel page →

CipherTrust Secrets Management

The credentials your applications use, held properly.

Centralised management of the API keys, database passwords, certificates and tokens that applications and pipelines need — the credentials that in most organisations sit in configuration files, environment variables and, regularly, source control. KuppingerCole named Thales an Overall Leader in its 2025 Leadership Compass for Enterprise Secrets Management. Worth knowing that TechBag also sells HashiCorp Vault in this space; which one fits depends on whether you want secrets inside your key-management platform or as a separate engineering-led service.

KuppingerCole Overall Leader 2025Explore

CipherTrust Cloud Key Manager

Platform & engine

Bring-your-own-key across cloud providers, from one console

Imperva

Platform & engine

Acquired Dec 2023 for $3.6B — data and application security, a separate portfolio

Thales is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide shows how the category splits and which part is yours. →

The thesis

Why “who holds the key” is the whole story

Cloud providers encrypt data at rest by default, and it genuinely helps — against a stolen disk. It does nothing about the provider, because they hold the key. When an Indian regulator asks about data protection, the question underneath is not whether the data is encrypted but whether you can demonstrate that a third party cannot decrypt it— and provider-managed encryption cannot answer that at all. Thales exists to invert the arrangement: keys generated inside a Luna HSM in your own data centre, under a CipherTrust Manager your people operate, so the answer to the auditor is evidence rather than a contractual assurance. Everything else on this page — transparent encryption, discovery, secrets — is built on that one idea.

01
Key custody

Customer-held keys, which is the whole argument

Most cloud encryption answers the question "is this data encrypted" and leaves the more important one untouched: who can decrypt it. If the provider holds the key, the honest answer is that they can, and a lawful order to them does not involve you. Thales exists to invert that. Keys generated in a Luna HSM in your data centre, under a CipherTrust Manager you operate, mean the answer to the auditor is demonstrable rather than contractual.

02
Transparent

Encryption that does not require rewriting the application

The reason encryption projects stall is rarely the cryptography — it is that protecting data properly seems to require changing every application that touches it. Transparent Encryption puts an agent between the application and storage, so the application is unchanged and the data on disk is protected. That is what makes it deployable against legacy line-of-business systems nobody will refactor.

03
Separation

Privileged users administering without reading

A root account or a DBA needs to keep a system running. It does not need to read customer records to do that, yet in most estates the two are the same permission. Transparent Encryption separates them, so administrators can operate a system without seeing the data inside it — which is precisely the control an RBI or SEBI reviewer is probing when they ask who has access to production data.

04
Recognition

Analyst standing, stated precisely

Thales is an Overall Leader in the 2025 KuppingerCole Leadership Compass for Data Security Platforms, and an Overall Leader in the 2025 Compass for Enterprise Secrets Management. Note what does not exist, because the absence is easy to misread: Gartner publishes no Magic Quadrant for hardware security modules or key management — Market Guides only, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any that implies one is misleading you.

05
The India case

India, concretely rather than decoratively

Two engineering competence centres in India, with Noida specifically the Cyber and Digital centre; more than 2,200 staff and around 450 more being hired during 2026. Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's NBFC outsourcing directions. That is a materially stronger signal than a distributor logo — it means the vendor has already done the work of understanding what an Indian regulator expects.

Start with the Data Command Center (discover & map your data — the foundation), then add Privacy, DSPM and Governance, and build safe AI with Gencore. All on one DataAI Command Graph.

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

KuppingerCole 2025

Overall Leader

Leadership Compass, Data Security Platforms

KuppingerCole 2025

Overall Leader

Leadership Compass, Enterprise Secrets Management

India

2,200+ staff

Two engineering centres; Noida is Cyber & Digital

India hiring

~450 more in 2026

Growing, not consolidating

India compliance

SEBI CSCRF & RBI NBFC

Thales publishes its own mapped material

Dec 2023

Imperva, $3.6B

Cyber business expanded, not divested

Gartner

No MQ exists

None for HSM or key management — Market Guides only

The constraint

No India SaaS region

CipherTrust as-a-Service is EU/NA — go on-premises

By the numbers

The company in six figures

2,200+ staff
In India, across two engineering centres
Thales India
~450 more
India hires planned during 2026
Thales India
2 Leader awards
KuppingerCole Overall Leader, 2025
KuppingerCole
$3.6B
Imperva acquisition, completed Dec 2023
Thales
0 India SaaS regions
CipherTrust as-a-Service is EU/NA only
Thales docs
0 Gartner MQs
None exists for HSM or key management
Gartner

See the platform, hear the pitch

Thales (official)·Overview

CipherTrust Data Security Platform — Overview

The platform, presented by Thales.

Thales (official)·Hardware

Introducing Thales Luna HSM 8 — Quantum-Safe

The hardware key custody layer.

Thales (official)·Demo

CipherTrust Transparent Encryption — Demo

Encrypting without changing the application.

The market maps

Where Thales sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

Thales Across Its Platform

Each dot is a Thales product: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
CipherTrust ManagerThales

The key authority the rest is rooted in.

Grid 02 · The industry

The Build-Safe-AI × Breadth Map

Key custody vs the field — where Thales wins on hardware-rooted control.

Niche point toolsUnified data + AIPoint playersBroad but siloed
ThalesThales

Key custody, in hardware, with India engineering.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with Thales?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What is actually driving this?

2. How strong does key custody need to be?

3. Where must this run?

The acronym decoder

Every term on these pages, in one place
HSM
Hardware Security Module — a tamper-resistant appliance that generates and stores keys and performs cryptographic operations inside the device, so key material never leaves in usable form.
Key custody
Who physically holds and controls the keys. The distinction that decides whether your cloud provider can decrypt your data, and the question regulators actually ask.
BYOK
Bring Your Own Key — you generate keys and supply them to a cloud provider. Better than provider-generated keys, though the provider still handles them in use.
HYOK
Hold Your Own Key — keys stay in your HSM and never reach the provider. Stronger than BYOK, and usually more restrictive about what the cloud service can then do.
Transparent encryption
Encryption applied between the application and storage, so the application needs no modification. What makes encrypting legacy systems feasible.
Privileged-user access control
Letting an administrator operate a system without being able to read the data inside it — separating running a database from reading its contents.
Tokenisation
Replacing a sensitive value with a non-sensitive stand-in, so systems that never need the real value never hold it. Common for cardholder data.
Key rotation
Replacing keys on a schedule so a compromised key has a bounded blast radius. Easy to mandate in policy and hard to do without a key manager.
Root of trust
The hardware or component everything else's security depends on. Rooting CipherTrust Manager in a Luna HSM means master keys never exist in software.
Security World
Entrust's model for managing keys across a group of HSMs. Named here because buyers comparing Luna and nShield meet the term immediately.
DPDP Act
India's Digital Personal Data Protection Act. Its practical first question is where personal data lives, which is why discovery precedes encryption.
CipherTrust Manager
Thales's central key-management authority — generates, stores, rotates and controls access to keys, and can be rooted in a Luna HSM.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Decide what key custody you actually need

Software key management under your control, or keys that exist only inside tamper-resistant hardware? That single answer separates a CipherTrust Manager deployment from one rooted in a Luna HSM, and it usually comes from your regulator or your own risk appetite rather than from a feature comparison.

02

Settle the deployment model early

CipherTrust as-a-Service runs in Europe and North America only — there is no India region. If Indian residency binds you, the answer is on-premises or virtual CipherTrust Manager with Luna HSM in your own data centre. Establish this before a demo, because it changes the entire architecture.

03

Find the data before you plan the encryption

Discovery and classification is the step teams skip and then repeat. You cannot scope an encryption project against an inventory nobody trusts, and under DPDP the location of personal data is the first question you will be asked. Run discovery first, then size the rest against what it finds.

04

Work out who administers the HSM

Hardware key custody creates a role nobody had before, with genuine separation-of-duties requirements — the person who administers the appliance should not also be the person who approves key use. Name those people during procurement, because retrofitting the separation afterwards is considerably harder.

05

Test transparent encryption against a real legacy system

The promise is that the application needs no change. Test that against your least modern, most business-critical system rather than a clean one, because that is the system the project actually has to survive. Measure the performance overhead there too.

06

Price the hardware and the operations, not just the licence

An HSM is a physical appliance with a purchase cost, a support contract and, if you want resilience, more than one of them across sites. Add the operational work of running them. TechBag models the whole thing and quotes in INR with GST.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
CipherTrust ManagerQuote-onlyVirtual appliance or physical hardwareThe central key authority for everything else
Transparent EncryptionQuote-only, typically per protected hostAgent-based, no application changesLegacy systems nobody will rewrite
Luna HSMQuote-only — hardware purchase plus supportA physical appliance in your data centreWhen keys must never exist in software
Discovery & ClassificationQuote-onlyScans structured and unstructured storesDPDP scoping before you encrypt anything
Secrets ManagementQuote-onlyInside the CipherTrust platformIf you want secrets in the key platform, not beside it

Modular, priced by quote in USD (now a Veeam company) — TechBag scopes just the modules you need, adds INR/GST, and frames it against DPDP + the AI-governance frameworks.

Five pitfalls that cost buyers quarters

1

Answering "is it encrypted" when the question was "who holds the key"

Cloud providers encrypt data at rest by default, and it is genuinely useful — against a stolen disk. It does nothing about the provider itself, because they hold the key. When a regulator asks about data protection they are asking whether you can demonstrate that a third party cannot decrypt your data, and provider-managed encryption cannot answer that. Get clear on which question you are being asked before you buy anything.

2

Assuming there is an India SaaS region

CipherTrust as-a-Service runs in Europe and North America. There is no India region, and no amount of Indian engineering presence changes that — people in India and data in India are different things, and the Noida centre is people. If Indian residency binds you, plan for on-premises or virtual deployment from the start rather than discovering the constraint after a cloud proof of concept.

3

Buying hardware key custody without planning the operations

An HSM is not software you install and forget. It is a physical appliance requiring firmware maintenance, backup of the security domain, separation of duties between administrators, and — if you want to survive a site failure — a second one somewhere else. Every one of those is manageable. None is free, and teams that budget only the appliance are surprised twice.

4

Encrypting before you have found the data

Encryption projects scoped against an asset inventory rather than a discovery scan consistently miss stores nobody remembered: the reporting replica, the analytics extract, the file share a department set up years ago. Those are exactly where a breach or a DPDP complaint originates. Discovery first is slower to start and considerably faster to finish.

5

Treating tokenisation and encryption as interchangeable

They solve different problems. Encryption protects data while preserving the ability to recover it with a key. Tokenisation replaces a sensitive value with a stand-in so downstream systems never hold the real thing at all — which is usually the better answer for cardholder data flowing through systems that have no business seeing it. Choosing the wrong one produces either weak protection or an unnecessarily painful integration.

The evaluation kit

The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:

Skip the homework entirely

Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about Thales

Two layers, and they are easier to understand as a stack than as a product list. The hardware layer is Luna HSM: a tamper-resistant appliance that generates and stores cryptographic keys and performs operations inside the device, so key material never leaves in usable form. The software layer is the CipherTrust Data Security Platform, whose centre is CipherTrust Manager — the authority that generates, stores, rotates and controls access to keys, and enforces which application or user may use them. Around that sit the products that apply protection: Transparent Encryption for files and databases, application-level protection and tokenisation, Data Discovery and Classification to find sensitive data in the first place, and Secrets Management for the credentials applications use. The two layers connect: CipherTrust Manager can be rooted in a Luna HSM, so the master keys never exist in software at all. That combination is what lets you answer a regulator's question with evidence rather than a contractual assurance. On analyst standing, Thales is the strongest vendor in this guide — an Overall Leader in the 2025 KuppingerCole Leadership Compass for Data Security Platforms and an Overall Leader in the 2025 Compass for Enterprise Secrets Management. One thing worth stating because its absence is easy to misread: Gartner publishes no Magic Quadrant for hardware security modules or key management at all, only Market Guides, which have no Leader quadrant. So no vendor in this category has a Gartner Leader placement, and any that implies one is misleading you.

Ready to shortlist Thales?

Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — module scoping, honest OneTrust/Wiz/Collibra/Palo Alto comparison, the India DPDP/AI-governance framing, GST invoicing and support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.