Talk to us
by ThalesTechBag Intel Page

CipherTrust Manager

Not whether the data is encrypted — who can decrypt it. CipherTrust Manager generates, stores, rotates and gates access to your keys, so the answer to an auditor is evidence rather than a contractual assurance. Virtual or hardware, and rootable in a Luna HSM. building the DataAI Command Graph the whole platform runs off. Now part of Veeam.

Customer holds the keysVirtual or hardwareNo India SaaS region

Data residency & processing — two different questions

Where data lives

Yours — deploy on-premises in India

CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India SaaS region — and Noida is people, not data

CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Key custody
the whole point of the product
Customer-held
Deployment
on-premises where residency binds you
Virtual or hardware
India SaaS
CipherTrust as-a-Service is EU/NA only
None
Analyst
2025 Data Security Platforms
KC Overall Leader

Quick answer

CipherTrust Manager is the key-management authority at the centre of Thales's data-security platform. It generates, stores, rotates and controls access to cryptographic keys, and enforces the policy deciding which application, user or workload may use them — which makes it the component that answers the question a regulator actually asks. That question is not "is the data encrypted", because cloud providers encrypt at rest by default and it helps only against a stolen disk. It is "who can decrypt this, and can you demonstrate it is not your provider". If the provider holds the key, the honest answer is that they can, and a lawful order served on them does not involve you at all. CipherTrust Manager inverts that: the keys are yours, held under your policy, on infrastructure you operate. It deploys as a virtual appliance or as physical hardware, and it can be rooted in a Luna HSM so master keys never exist in software in the first place. For an Indian buyer the deployment question is the one to settle first, and the answer is unambiguous: CipherTrust as-a-Service runs in Europe and North America only, with no India region. So residency-bound buyers deploy on-premises or virtual, in their own data centre — which puts the keys in your building rather than a vendor's, and is very likely what you wanted if a regulator prompted the purchase. Thales is an Overall Leader in the 2025 KuppingerCole Leadership Compass for Data Security Platforms. Note what does not exist so you do not misread its absence: Gartner publishes no Magic Quadrant for key management at all, only Market Guides, which have no Leader quadrant. Read more ↓ Show less ↑
Part 01 · Orient

The Postman platform family

This page covers CipherTrust Manager — the foundation. The rest of the Securiti platform:

Quick facts

30-second orientation
Product
CipherTrust Manager — the key authority
What it does
Generates, stores, rotates and gates access to keys
Deployment
Virtual appliance or physical hardware
Root of trust
Can be rooted in a Luna HSM — keys never in software
Vendor
Thales — Chairman & CEO Patrice Caine
The cyber arm
Thales Cloud Protection & Licensing
Analyst standing
KuppingerCole Overall Leader 2025 — Data Security Platforms
Gartner
No MQ exists for HSM or key management — Market Guides only
India engineering
2,200+ staff; Noida is the Cyber & Digital centre
Data residency
Yours — deploy on-premises or virtual in India
Data processing
On your infrastructure; CipherTrust SaaS is EU/NA only
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, key-custody scoping
Part 02 · Learn

Understand data discovery before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

The central key-management authority for the CipherTrust platform — it generates, stores, rotates and controls access to cryptographic keys, and enforces who may use them.

Blind data sprawl vs discovered, classified & mapped (Securiti) — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailCipherTrust Manager
Data visibilityUnknown sprawl, blind spotsDiscovery across the whole estate
ClassificationBrittle keyword rulesSensitive Data Intelligence (accurate)
Unstructured dataMostly ignoredStructured AND unstructured covered
Shadow dataInvisibleShadow & dark data discovered
The mapStatic, siloed inventoriesOne DataAI Command Graph
Data to peopleNot linkedPeople Data Graph (identities)
DownstreamEach tool rebuilds its viewOne foundation powers all modules
Best fit(varies)See, classify & map all sensitive data

Securiti Data Command Center discovers, classifies and maps your sensitive data across multicloud, SaaS and on-prem — structured and unstructured, at petabyte scale — building the DataAI Command Graph and the People Data Graph (data linked to identities) that powers privacy, DSPM and AI governance. Now part of Veeam. Honest: competitive field — focused discovery alone? BigID. Catalog/governance? Collibra/Informatica. Microsoft-native? Purview. TechBag scopes the start, adds GST & the India DPDP framing.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The reach

Connect Everywhere

Multicloud, SaaS, on-prem

Connect to data across clouds, SaaS apps, on-prem systems, files and databases — structured AND unstructured — through a rich connector library, at petabyte scale. You can't map what you can't reach. Reach every data source you have.

02
The find

Discover Sensitive Data

Scan and find at scale

Scan your data everywhere and DISCOVER sensitive and regulated data — PII, PHI, PCI, secrets and IP — including shadow and dark data you didn't know you had. Find what's actually there. See all your sensitive data.

03
The label

Classify Accurately

Sensitive Data Intelligence

Classify discovered data accurately with Sensitive Data Intelligence — across structured and unstructured sources — so every element carries the right sensitivity and regulatory label. Accurate labels, not guesses. Classification you can act on.

04
The map

Map to the Graph

The DataAI Command Graph

MAP the classified data, its relationships, its flows and — via the People Data Graph — the individuals it belongs to, building the DataAI Command Graph: the know-it-all knowledge graph of your data. One graph of everything. Context, mapped.

05
The edge

Power Everything Downstream

Privacy, DSPM, AI, governance

Because the graph is one foundation, every downstream module — privacy, DSPM data security, AI governance, data governance — runs off the SAME discovery. Discover once, use everywhere. One foundation for the whole platform.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Discover, classify, map.

Securiti discovers, classifies and maps all your sensitive data — the know-it-all graph & foundation of portfolio, and paired with the human firewall.

Discover
Connectors

Rich Data Connector Library

Connect to data across clouds, SaaS, on-prem, files and databases — structured and unstructured — so discovery reaches your whole estate. Reach every source. Nothing left in the dark.

Discover
Petabyte scale

Discovery at Petabyte Scale

Scan and discover sensitive data across a petabyte-scale, multicloud, hybrid estate — without choking. Built for the size real enterprises are. Scale is not an excuse to stay blind.

Discover
Shadow data

Shadow & Dark Data Discovery

Surface shadow and dark data — the sensitive data in forgotten stores, copies and unmanaged systems you didn't know existed. You can't protect what you don't know you have. Find the unknown.

Discover
Structured + unstructured

Structured & Unstructured Coverage

Discover across BOTH structured (databases, warehouses) and unstructured (files, docs, tickets, chat) data — where most sensitive data actually hides. Cover the hard half too. Unstructured is where the risk is.

Classify
Sensitive Data Intelligence

Sensitive Data Intelligence

Accurately classify sensitive and regulated data — PII, PHI, PCI, secrets, IP — with deep intelligence, not brittle keyword rules, across every source. Accuracy is the whole game. Classify what matters, correctly.

Classify
Regulatory labels

Regulatory Classification

Tag data against the regulations that apply — DPDP, GDPR, HIPAA, PCI DSS and more — so classification is compliance-aware, not generic. Labels that map to the law. Know what rules each element carries.

Classify
AI-assisted

AI-Assisted Classification

Use AI and context — not just pattern-matching — to classify accurately and cut false positives, so downstream policy acts on trustworthy labels. Fewer false positives. Classification you can trust.

Classify
Catalog

Sensitive Data Catalog

Every discovered, classified element lands in a living catalog — searchable, up to date — so teams can find and reason about sensitive data instead of hunting. A catalog that stays current. Answers, not spreadsheets.

Map
The graph

DataAI Command Graph

Map classified data, its relationships and its flows into ONE knowledge graph — the know-it-all foundation the whole platform runs off. One graph for everything. Context is the product.

Map
People Data Graph

People Data Graph

Link sensitive data back to the individual IDENTITIES it belongs to — the distinctive piece for privacy: fulfil data-subject / DPDP rights, minimisation and residency with confidence. Data, tied to people. The privacy differentiator.

Map
Data flows & lineage

Data Flow & Lineage Mapping

Map how sensitive data FLOWS — across systems, borders and third parties — so you can reason about residency, transfers and cross-border rules (a DPDP nuance). See where data goes. Flows you can govern.

Map
One foundation

One Foundation for Everything

Because discovery + the graph is one foundation, privacy, DSPM, AI governance and data governance all run off the SAME map — the breadth few rivals match. Discover once, use everywhere. One graph, whole platform.

See it, don’t just read it

Watch Securiti in action

The overview, getting started, and the core workflows.

Thales (official)·Overview

CipherTrust Data Security Platform — Overview

The platform, presented by Thales.

Thales (official)·Walkthrough

CipherTrust Data Security Platform Walkthrough

The console in use.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why CipherTrust Manager

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Securiti apart (and where a point tool leads).

01

It answers the question regulators actually ask

Cloud providers encrypt data at rest by default. It is genuinely useful and it protects against exactly one thing: someone walking off with a disk. It does nothing whatsoever about the provider, because the provider holds the key — and a lawful order served on them is a conversation you are not part of. When an Indian regulator asks about data protection, the substance underneath is whether you can demonstrate that a third party cannot decrypt your data. Provider-managed encryption cannot answer that, and no amount of contractual assurance substitutes for key custody. CipherTrust Manager is the component that changes the answer from a promise to a demonstration.

02

One authority instead of scattered key stores

The realistic alternative to a key manager is not an absence of keys — it is keys in a dozen places: one cloud provider's KMS, another's, a database's own encryption, a configuration file somebody swore was temporary. Nobody can answer who holds what, rotation happens where it is easy rather than where it matters, and revoking access to data means finding every copy of a key first. Centralising the authority makes rotation a policy rather than a project, and makes the access question answerable in one place.

03

Rootable in hardware when the requirement demands it

CipherTrust Manager can run entirely in software, under your control, which is genuinely sufficient for many buyers. Where the requirement is that key material must never exist in software at all — a regulator asking specifically about hardware protection, a payments or PKI use case, or your own conclusion that a compromised host must not yield keys — it can be rooted in a Luna HSM so master keys are generated and held inside tamper-resistant hardware. The same platform serves both, so the hardware decision does not force a different product.

04

The honest constraint: no India SaaS region

CipherTrust as-a-Service runs in Europe and North America. There is no India region, and we would rather you hear that from us on the first page than discover it after a cloud proof of concept. For a residency-bound Indian buyer this is not really a limitation, though — it pushes you to on-premises or virtual deployment in your own data centre, which is a stronger custody position than any vendor-hosted region could offer. Be precise about a related fact this market blurs constantly: Thales has 2,200+ staff in India and Noida is its Cyber and Digital engineering centre. That is people, not a data region, and treating the two as equivalent is the error that surfaces during an audit.

05

The honest positioning

CipherTrust Manager is right when key custody is the actual problem: a regulator has asked who can decrypt, or you are moving to cloud and want the key root to stay in your building. It is not right if what you actually need is protecting documents that leave your organisation — that is rights management, and Seclore or Microsoft Purview is the answer, both of which TechBag sells. It is also more than you need if a single application requires encryption and nothing else; that is often solved within the application or database. Buy this when the answer to "who holds the keys" has to be an organisational answer rather than a per-system one.

See everything
Discover structured & unstructured
One graph
Foundation for the whole platform
Local via TechBag
Scoping, GST, DPDP framing
Proof, not promises

The numbers behind the platform

2200+ staff
Thales in India, across two engineering centres
Thales India
~450 more
India hires planned during 2026
Thales India
2 KC Leader awards
KuppingerCole Overall Leader, 2025
KuppingerCole
0 India SaaS regions
CipherTrust as-a-Service is EU/NA only
Thales docs
0 Gartner MQs
None exists for HSM or key management
Gartner
2000
Thales Group formed in its current form
Company

What your Securiti journey looks like

Week 1Assess

Settle key custody and deployment

Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.

Weeks 2–5Assess

Run discovery before scoping encryption

Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.

Weeks 4–10Deploy

Pilot on your least-modern system

Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.

Weeks 8–14Deploy

Name the HSM administrators and the approvers

Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.

OngoingOperate

Rotate on policy, and test the restore

Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
420+ reviews*
92% would recommend
Discovery & coverage4.6
Classification accuracy4.4
The graph (one foundation)4.6
Breadth vs point-tool depth4.1
5
61%
4
28%
3
7%
2
2%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.
Head of Information Security
Banking
Manufacturing
Deploying against systems nobody would let us modify was the whole reason this got approved.
Infrastructure Lead
Manufacturing
Insurance
Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.
Security Architect
Insurance
Non-Banking Financial Company
No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Data-discovery & intelligence market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ThalesThis page

Key custody in hardware, with India engineering.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
ThalesThis page

Deepest on key custody; not a document product.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Securiti vs the data-discovery field

BigID, Collibra, Microsoft Purview, Informatica and IBM Guardium — honest lanes; the edge is ONE discovery graph unifying data + AI + privacy + DSPM (a consolidation play), plus the People Data Graph. Focused discovery alone? BigID. Catalog/governance? Collibra/Informatica. Microsoft-native? Purview. We say so.

DimensionThalesEntrustMicrosoft PurviewSecloreHashiCorp Vault
What it actually isKey management + hardware custody + encryptionThe HSM and PKI peerDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
Who holds the keysYou — in hardware if you wantYou — in hardwareMicrosoft, unless you use Double Key EncryptionEither — SaaS or self-hostedYou
Protection travels with the fileNo — this protects infrastructure, not documentsNoYes — labels travel with the fileYes, with post-distribution revocationNo
Hardware key custodyLuna HSMnShield — holds BIS certificationDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
India data residencyDeploy on-premises — no India SaaS regionOn-premises appliances — no India SaaSIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Analyst standingKuppingerCole Overall Leader 2025 ×2No HSM/key-management Leader placement foundMicrosoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundHSM operations: firmware, backup, separation of dutiesScope: it exited public TLS in Sep 2025DKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitKey custody with hardware, on your own infrastructureWhere BIS certification is a procurement requirementMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Securiti if…

  • You want ONE discovery + graph foundation that powers privacy, DSPM, AI governance and data governance together (a consolidation play)
  • You need accurate Sensitive Data Intelligence across BOTH structured and unstructured data, at petabyte scale
  • You value the People Data Graph — data linked to identities — for privacy and DPDP data-principal rights
  • You value the backing — now part of Veeam — and the India DPDP data-mapping framing (via TechBag)

BigID if…

  • Your single priority is focused, best-of-breed data discovery & intelligence in its own lane

Collibra / Informatica if…

  • Your priority is a data CATALOG and data-governance / lineage programme (governance-led, less identity-centric)

Microsoft Purview if…

  • You're all-in on Microsoft and want the Microsoft-native discovery & governance option

IBM Guardium if…

  • Your priority is database activity monitoring and database security specifically

CipherTrust Manager is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (data sources; sensitive-data stores; hour cost as loaded rate). Estimates contrast blind data sprawl (unknown data, manual classification, siloed inventories) vs Securiti (automated discovery, Sensitive Data Intelligence, one graph, People Data Graph) — the wins are faster visibility, accurate classification and one foundation for privacy/DSPM/AI. Illustrative — TechBag scopes your estate.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes you to start with the foundation (discovery + the graph), then the modules you actually need (privacy, DSPM, AI governance, data governance), adds INR/GST, and frames it against DPDP data mapping — quote current figures for your estate.

Securiti (modular, by quote)

Best for a discovery + graph foundation

  • Data Command Center — discovery, classification, mapping (Sensitive Data Intelligence)
  • One DataAI Command Graph + People Data Graph — the foundation everything runs off
  • Now part of Veeam; powers privacy, DSPM, AI governance & data governance

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ scoping & DPDP framing

Best value with TechBag

  • Start-here scoping + honest BigID/Collibra/Purview/Informatica comparison
  • Securiti prices by quote in USD; broad platform — start with discovery
  • TechBag adds INR/GST, local support & the India DPDP data-mapping framing

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Key custody

Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?

2
Deployment

Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?

3
Residency

Are we clear that Thales's India engineering presence is people, not a data region?

4
Discovery

Have we scanned rather than relied on an asset inventory to scope this?

5
Performance

Have we measured the overhead on our least-modern business-critical system?

6
Separation of duties

Who administers the HSM, and who approves key use? They must not be the same person.

7
Resilience

Do we need a second appliance at another site, and is it budgeted?

8
Backup

Have we backed up the security domain AND tested restoring from it?

9
Scope

Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.

10
Commercials

Have we priced hardware, support, resilience and operations — not just the licence?

FAQ

Questions buyers ask

Through deployment rather than through a vendor region, and the distinction is the first thing to settle. CipherTrust as-a-Service runs in Europe and North America only — there is no India region, and we are not going to imply otherwise. For a residency-bound Indian buyer the answer is on-premises or virtual deployment in your own data centre, with keys under your control and, if the requirement demands it, inside a Luna HSM physically in your building. That is a stronger custody position than any vendor-hosted region could provide, and it is very likely what a regulator was pushing you toward in the first place. Be precise about a fact this market blurs constantly. Thales has more than 2,200 staff in India across two engineering competence centres, with Noida specifically the Cyber and Digital centre, and is hiring around 450 more during 2026. That is a genuine and unusual commitment — and it is people, not a data region. Treating an engineering presence as a residency answer is exactly the error that surfaces during an audit, and it is worth stating plainly because vendors on all sides encourage the confusion. What the India presence does buy you is real: Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's outsourcing directions for NBFCs, which means the vendor has already done the work of understanding what an Indian regulator expects rather than translating a US framework. On DPDP specifically, the sequence matters more than the product: find the personal data first, then protect it. Discovery before encryption, every time.

Ready to see all your sensitive data?

Scope Securiti Data Command Center (discover, classify and map sensitive data across multicloud, SaaS and on-prem — structured and unstructured — building the DataAI Command Graph and the People Data Graph the whole platform runs off, now Veeam-backed) — and let a TechBag advisor scope the starting point, compare vs BigID/Collibra/Purview/Informatica honestly, frame it against DPDP data mapping, and add INR/GST and local support.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.