Talk to us
by ThalesTechBag Intel Page

CipherTrust Secrets Management

The credentials your applications use, held properly — API keys, database passwords, certificates and tokens out of config files, environment variables and source control. KuppingerCole Overall Leader 2025 for Enterprise Secrets Management. Context-aware LLM Firewall, and governed on the DataAI Command Graph. Now part of Veeam.

KC Overall Leader 2025One authority with your keysCompare against Vault

Data residency & processing — two different questions

Where data lives

Yours — deploy on-premises in India

CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India SaaS region — and Noida is people, not data

CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Analyst
2025 Enterprise Secrets Management
KC Overall Leader
Coherence
secrets and keys under one authority
One platform
The trade
Vault is more engineering-team led
Security-team led
Rotation
rather than on somebody remembering
On policy

Quick answer

CipherTrust Secrets Management centralises the credentials applications and infrastructure use — API keys, database passwords, certificates, tokens — so they stop living in the places they usually live, which is configuration files, environment variables, CI/CD pipeline settings and, with unfortunate regularity, source control. That last one is not a hypothetical: leaked credentials in repositories are one of the most reliably exploited initial access vectors there is, and the credential is usually long-lived, widely shared and rotated never. Secrets management replaces that with credentials issued centrally, scoped to the workload that needs them, and rotated on policy rather than on somebody remembering. KuppingerCole named Thales an Overall Leader in its 2025 Leadership Compass for Enterprise Secrets Management. The reason to consider this version specifically, rather than a standalone secrets tool, is coherence: it sits inside the same platform as your key management, so machine credentials and cryptographic keys are governed under one authority with one audit trail, rather than as two systems that each believe they are the source of truth. We should be even-handed here, because TechBag also sells HashiCorp Vault and it is an excellent product with a large engineering following. The genuine choice is architectural rather than about feature checklists: do you want secrets inside your data-security platform, governed alongside your keys, or as a separate engineering-led service your development teams operate? Both are defensible, and the right answer usually follows from who will own it — a security team or a platform team. Read more ↓ Show less ↑
Part 01 · Orient

The Postman platform family

This page covers CipherTrust Secrets Management — the flagship. The rest of the Securiti platform:

Quick facts

30-second orientation
Product
CipherTrust Secrets Management
What it holds
API keys, database passwords, certificates, tokens
Analyst
KuppingerCole Overall Leader 2025 — Enterprise Secrets Management
The alternative
HashiCorp Vault — TechBag sells both; see the FAQ
Vendor
Thales — Chairman & CEO Patrice Caine
The cyber arm
Thales Cloud Protection & Licensing
Analyst standing
KuppingerCole Overall Leader 2025 — Data Security Platforms
Gartner
No MQ exists for HSM or key management — Market Guides only
India engineering
2,200+ staff; Noida is the Cyber & Digital centre
Data residency
Yours — deploy on-premises or virtual in India
Data processing
On your infrastructure; CipherTrust SaaS is EU/NA only
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, key-custody scoping
Part 02 · Learn

Understand AI security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Centralised management of the credentials applications use — API keys, database passwords, certificates and tokens — issued, scoped and rotated under one authority.

Risky DIY AI vs safe, governed AI (Securiti) — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailSecrets Management
Build safe AIRisky custom build (leak risk)Gencore — sanitise then build fast
AI guardrailsNone / generic DLPContext-aware LLM Firewall (OWASP)
AI visibilityShadow AI unknownAI & model discovery
Data + AISeparate tools, gapsOne DataAI Command Graph
AgentsUngovernedAgent Commander (govern agents)
ComplianceManual, ad hocEU AI Act + NIST AI RMF mapping
Vendor backing(startup risk)Now part of Veeam
Best fit(varies)Build + govern enterprise AI safely

Securiti Gencore AI builds safe enterprise AI from your data — connect, sanitise before the model, build fast, guard with a context-aware LLM Firewall (OWASP LLM Top 10) — governing data AND AI on one graph (Agent Commander for agents). Now part of Veeam. Honest: fast-moving field — deepest AI runtime alone? Palo Alto/Protecto. Cloud AI posture? Wiz. TechBag scopes modules, adds GST & the India DPDP framing.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The source

Connect Your Data

Rich connector library

Connect your proprietary data — across clouds, SaaS, on-prem, files and databases — through a rich connector library, so your enterprise AI is grounded in YOUR data, not just a generic model. Ground the AI in what you actually know. Your data, connected.

02
The safety

Curate & Sanitise

Strip or entitle sensitive data

Before data reaches the model, curate and SANITISE it — strip, mask or entitle sensitive data based on the DataAI Command Graph — so the AI only ever sees data it's allowed to. Safe by construction. The model never sees what it shouldn't.

03
The build

Build the AI System

Copilots, agents, knowledge apps

Vectorise and ingest the sanitised data and build enterprise AI systems — copilots, agents and knowledge apps — 'in minutes', on your governed data. From data to a safe AI app, fast. Build, don't wait.

04
The guardrail

Guard at Runtime

Context-aware LLM Firewalls

Protect the running AI with Context-aware LLM Firewalls — inline guardrails (OWASP-LLM-Top-10-aligned) that block prompt injection, jailbreaks and sensitive-data leaks, with awareness of the data context. Guard every prompt and response. Safe in production.

05
The edge

Govern on One Graph

The DataAI Command Graph

Everything — the data, the AI systems, the controls — is governed by ONE DataAI Command Graph, so you discover, secure and govern both the AI and the data feeding it together, mapped to the EU AI Act and NIST AI RMF. One graph for data AND AI. Governed as one.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Build, secure, govern.

Securiti lets you build safe enterprise AI from your data — sanitise, build, guard & govern — the AI-security flagship of portfolio, and paired with the human firewall.

Build
Data connectors

Rich Data Connector Library

Connect proprietary data across clouds, SaaS, on-prem, files and databases — so enterprise AI is grounded in your own data. Ground the AI in your knowledge. Connected to everything you have.

Build
Data curation

Curation & Sanitisation

Curate and sanitise data before it reaches the model — strip, mask or entitle sensitive data per the graph — so the AI never sees what it shouldn't. Safe by construction. Clean data in, safe AI out.

Build
Vectorise & ingest

Vectorisation & Ingestion

Vectorise and ingest the sanitised data into a knowledge base for retrieval — the RAG foundation for your AI systems — governed end to end. The safe knowledge layer. Retrieval you can trust.

Build
Build fast

Build Copilots, Agents & Apps

Build enterprise AI systems — copilots, agents and knowledge apps — 'in minutes' on your governed data, instead of a long, risky custom build. From data to safe AI app, fast. Ship AI, safely.

Secure
LLM Firewall

Context-Aware LLM Firewalls

Inline guardrails in the GenAI pipeline (OWASP-LLM-Top-10-aligned) block prompt injection, jailbreaks and sensitive-data leaks — with awareness of the data context. Guard every prompt and response. A firewall for your AI.

Secure
AI discovery

AI & Model Discovery

Discover and classify the AI and models in use across your organisation — sanctioned and shadow AI — so you know what AI you actually have. You can't govern AI you can't see. Find all your AI.

Secure
AI risk

AI Risk Assessment

Assess the risk of your AI systems and models — data exposure, safety, security, bias — so you understand and reduce AI risk before and after deployment. Know your AI risk. Deploy with eyes open.

Secure
Agent Commander

Agent Commander (Govern AI Agents)

Agent Commander (March 2026) extends governance to autonomous AI agents — the newest frontier — so as agents proliferate, they stay governed and safe. Govern the agents, not just the models. Control autonomous AI.

Govern
The graph

DataAI Command Graph

One knowledge graph maps sensitive data, its relationships and its controls — and powers AI governance off the same foundation — so data AND AI are governed together, not in silos. One graph for data and AI. Context is everything.

Govern
Compliance mapping

EU AI Act & NIST AI RMF Mapping

Map your AI systems to regulatory frameworks — the EU AI Act, NIST AI RMF and more — with built-in intelligence, so AI governance is compliance-ready, not ad hoc. Governance that maps to the law. Audit-ready AI.

Govern
Policies

AI Security Policies

Pre-built AI security policies and controls — so you enforce consistent guardrails across all your AI systems, not per-project reinvention. Consistent guardrails everywhere. Policy, not guesswork.

Govern
Data + AI, unified

Data + AI Governed as One

Because it's DSPM-for-AI fused with build-safe-AI on one graph, you govern the AI AND the data feeding it together — the breadth that few rivals match. Data and AI, one platform. Govern the whole picture.

See it, don’t just read it

Watch Securiti in action

The overview, getting started, and the core workflows.

Thales (official)·Platform

CipherTrust Data Security Platform — Overview

Where secrets management sits.

Thales (official)·Walkthrough

CipherTrust Data Security Platform Walkthrough

The platform in use.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Secrets Management

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Securiti apart (and where a point tool leads).

01

Credentials in config files are a reliably exploited vector

The realistic alternative to secrets management is not a different tool — it is credentials in configuration files, environment variables, pipeline settings and source control. Leaked repository credentials are among the most dependable initial-access routes attackers have, and the credential is typically long-lived, shared across systems, and rotated never, so a single leak stays valid indefinitely. Centralising issue and rotation replaces a permanent exposure with a bounded one, which is a larger security improvement than most controls of comparable cost.

02

Machine identity is now most of your identity problem

Human accounts get privileged access management, joiner-mover-leaver processes and access reviews. Machine credentials, which vastly outnumber them in any modern estate, frequently get a wiki page. As infrastructure becomes more automated the imbalance worsens, and the credentials with the broadest access are often the ones nobody has ever reviewed. Bringing them under a managed authority is the machine-identity equivalent of the governance you already apply to people.

03

Secrets and keys under one authority

This is the specific argument for the Thales version rather than a standalone tool. Because it sits inside the CipherTrust platform, machine credentials and cryptographic keys are governed by one system with one audit trail and one policy model. The common alternative — a secrets tool beside a key manager — produces two sources of truth that disagree in the way any two inventories eventually disagree, and an auditor's question about who could reach what then requires reconciling both. KuppingerCole rated Thales an Overall Leader here in 2025.

04

The honest comparison: HashiCorp Vault

We sell Vault too and it is genuinely excellent, so here is the even-handed version. Vault has deeper adoption among engineering teams, a very strong dynamic-secrets model, and a free self-hostable community edition — and it is operationally heavy, being a distributed system with unseal, replication and upgrade responsibilities that teams routinely underestimate. CipherTrust Secrets Management is lighter to operate and coherent with your key management, and it is less likely to be what your developers already know. The choice usually follows ownership: a security team that also runs key management leans one way, a platform-engineering team that already runs Vault-shaped infrastructure leans the other. Neither answer is wrong, and we will help you make it rather than pretend there is only one.

05

The honest positioning

Choose this when you are already deploying the CipherTrust platform and want secrets governed under the same authority as your keys, with a security team owning it. Choose Vault when engineering owns the problem, dynamic short-lived credentials are central to how you work, and you have the platform capacity to operate it. Choose neither, for now, if your actual problem is human privileged access rather than machine credentials — that is PAM, a different category, and TechBag sells CyberArk and Arcon for it. Buying a secrets platform to solve a PAM problem is a mistake we see often enough to raise unprompted.

Build safe AI
Sanitise before the model (Gencore)
LLM Firewall
OWASP-aligned, context-aware
Local via TechBag
Scoping, GST, DPDP framing
Proof, not promises

The numbers behind the platform

2200+ staff
Thales in India, across two engineering centres
Thales India
~450 more
India hires planned during 2026
Thales India
2 KC Leader awards
KuppingerCole Overall Leader, 2025
KuppingerCole
0 India SaaS regions
CipherTrust as-a-Service is EU/NA only
Thales docs
0 Gartner MQs
None exists for HSM or key management
Gartner
2000
Thales Group formed in its current form
Company

What your Securiti journey looks like

Week 1Assess

Settle key custody and deployment

Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.

Weeks 2–5Assess

Run discovery before scoping encryption

Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.

Weeks 4–10Deploy

Pilot on your least-modern system

Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.

Weeks 8–14Deploy

Name the HSM administrators and the approvers

Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.

OngoingOperate

Rotate on policy, and test the restore

Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
400+ reviews*
91% would recommend
Build safe AI (Gencore)4.6
LLM Firewall / guardrails4.5
Data + AI on one graph4.6
Breadth vs point-tool depth4.0
5
60%
4
29%
3
7%
2
2%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.
Head of Information Security
Banking
Manufacturing
Deploying against systems nobody would let us modify was the whole reason this got approved.
Infrastructure Lead
Manufacturing
Insurance
Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.
Security Architect
Insurance
Non-Banking Financial Company
No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI-security & governance market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ThalesThis page

Key custody in hardware, with India engineering.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
ThalesThis page

Deepest on key custody; not a document product.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Securiti vs the AI-security field

Palo Alto (Prisma AIRS), Protecto, Wiz (AI-SPM), BigID and OneTrust — honest lanes; the edge is build-safe-AI + governing DATA and AI together on one graph (a consolidation play). Deepest AI runtime alone? Palo Alto/Protecto. Cloud AI posture? Wiz. We say so.

DimensionThalesEntrustMicrosoft PurviewSecloreHashiCorp Vault
What it actually isKey management + hardware custody + encryptionThe HSM and PKI peerDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
Who holds the keysYou — in hardware if you wantYou — in hardwareMicrosoft, unless you use Double Key EncryptionEither — SaaS or self-hostedYou
Protection travels with the fileNo — this protects infrastructure, not documentsNoYes — labels travel with the fileYes, with post-distribution revocationNo
Hardware key custodyLuna HSMnShield — holds BIS certificationDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
India data residencyDeploy on-premises — no India SaaS regionOn-premises appliances — no India SaaSIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Analyst standingKuppingerCole Overall Leader 2025 ×2No HSM/key-management Leader placement foundMicrosoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundHSM operations: firmware, backup, separation of dutiesScope: it exited public TLS in Sep 2025DKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitKey custody with hardware, on your own infrastructureWhere BIS certification is a procurement requirementMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Securiti if…

  • You want to BUILD safe enterprise AI (copilots/agents) from your data — sanitised before the model (Gencore AI)
  • You want a context-aware LLM Firewall (OWASP-LLM-aligned) guarding AI in production
  • You want to govern DATA and AI on ONE graph — a consolidation play, not stitched point tools
  • You value the backing — now part of Veeam — and the India DPDP/AI-governance framing (via TechBag)

Palo Alto (Prisma AIRS) if…

  • Your single priority is the deepest AI RUNTIME security (and you're a Palo Alto shop)

Protecto / LLM specialists if…

  • You want a focused, best-of-breed LLM data-protection point tool

Wiz (AI-SPM) if…

  • You want AI security posture WITHIN your cloud-security platform (see the Qualys TotalCloud / Wiz comparison)

OneTrust / BigID if…

  • Your priority is pure privacy (OneTrust) or pure data-security depth (BigID) — see the Securiti privacy & DSPM pages
Do the math

What could this save you?

Drag the sliders (AI projects; sensitive-data sources; hour cost as loaded rate). Estimates contrast risky DIY GenAI (custom build, data-leak risk, no runtime guardrails, ungoverned) vs Securiti (Gencore build-safe-AI, sanitise before the model, LLM Firewall, one graph) — the wins are faster safe deployment and reduced leakage/compliance risk. Illustrative — TechBag scopes your estate.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes the modules you actually need (Gencore AI, DSPM, privacy, governance), adds INR/GST, and frames it against DPDP and the AI-governance frameworks — quote current figures for your estate.

Securiti (modular, by quote)

Best for building & governing enterprise AI

  • Gencore AI (build safe AI) + AI Security & Governance + LLM Firewall
  • One DataAI Command Graph — data AND AI governed together
  • Now part of Veeam; Agent Commander (Mar 2026) for AI agents

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ scoping & DPDP framing

Best value with TechBag

  • Module scoping + honest Palo Alto/Protecto/Wiz comparison
  • Securiti prices by quote in USD; broad platform — scope what you need
  • TechBag adds INR/GST, local support & the India DPDP framing

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Key custody

Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?

2
Deployment

Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?

3
Residency

Are we clear that Thales's India engineering presence is people, not a data region?

4
Discovery

Have we scanned rather than relied on an asset inventory to scope this?

5
Performance

Have we measured the overhead on our least-modern business-critical system?

6
Separation of duties

Who administers the HSM, and who approves key use? They must not be the same person.

7
Resilience

Do we need a second appliance at another site, and is it budgeted?

8
Backup

Have we backed up the security domain AND tested restoring from it?

9
Scope

Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.

10
Commercials

Have we priced hardware, support, resilience and operations — not just the licence?

FAQ

Questions buyers ask

Through deployment rather than through a vendor region, and the distinction is the first thing to settle. CipherTrust as-a-Service runs in Europe and North America only — there is no India region, and we are not going to imply otherwise. For a residency-bound Indian buyer the answer is on-premises or virtual deployment in your own data centre, with keys under your control and, if the requirement demands it, inside a Luna HSM physically in your building. That is a stronger custody position than any vendor-hosted region could provide, and it is very likely what a regulator was pushing you toward in the first place. Be precise about a fact this market blurs constantly. Thales has more than 2,200 staff in India across two engineering competence centres, with Noida specifically the Cyber and Digital centre, and is hiring around 450 more during 2026. That is a genuine and unusual commitment — and it is people, not a data region. Treating an engineering presence as a residency answer is exactly the error that surfaces during an audit, and it is worth stating plainly because vendors on all sides encourage the confusion. What the India presence does buy you is real: Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's outsourcing directions for NBFCs, which means the vendor has already done the work of understanding what an Indian regulator expects rather than translating a US framework. On DPDP specifically, the sequence matters more than the product: find the personal data first, then protect it. Discovery before encryption, every time.

Ready to build AI safely?

Scope Securiti Gencore AI (build safe enterprise AI from your data — sanitised before the model — guarded by a context-aware LLM Firewall, governed on the DataAI Command Graph, now Veeam-backed) — and let a TechBag advisor scope the modules, compare vs Palo Alto/Protecto/Wiz honestly, frame it against DPDP and the AI-governance frameworks, and add INR/GST and local support.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.