Talk to us
by ThalesTechBag Intel Page

CipherTrust Transparent Encryption

Encryption that does not require rewriting the application — an agent between the application and storage, so the fifteen-year-old system nobody will refactor becomes addressable. It also lets a DBA administer a system without reading the data inside it.identity & access (least-privilege), all on the DataAI Command Graph. Now part of Veeam.

No application changesAdmin without readingMeasure the overhead

Data residency & processing — two different questions

Where data lives

Yours — deploy on-premises in India

CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India SaaS region — and Noida is people, not data

CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Application changes
why legacy systems become addressable
None required
Privileged separation
administer without reading the data
Documented
Performance
test on your least-modern system, not a clean one
Measure it
Scope
not rights management — no travel, no revocation
At rest only

Quick answer

CipherTrust Transparent Encryption encrypts data at rest in files and databases without requiring any change to the application that uses them. An agent sits between the application and storage, encrypting on write and decrypting on read for authorised processes, and enforcing access policy at the same point. The word doing the work is transparent, and it is the entire commercial argument. Encryption projects rarely stall on cryptography; they stall because protecting data properly appears to require modifying every application that touches it — and nobody is going to refactor a fifteen-year-old line-of-business system that the business depends on and no current employee wrote. An agent that leaves the application untouched is what makes those systems addressable at all. The second capability matters as much and gets less attention: privileged-user access control. A root account or a DBA needs to keep a system running. It does not need to read customer records to do that, yet in most estates those are the same permission. Transparent Encryption separates them, so administrators can operate a system without seeing the data inside it — which is precisely the control an RBI or SEBI reviewer is probing when they ask who has access to production data. Two honest caveats. There is a performance overhead, and the only number that means anything is the one you measure on your own least-modern system rather than a clean test host. And this protects data at rest on infrastructure you control; it is not rights management, so a file copied out by an authorised process is plaintext once it leaves. Read more ↓ Show less ↑
Part 01 · Orient

The Postman platform family

This page covers CipherTrust Transparent Encryption. The rest of the Securiti platform:

Quick facts

30-second orientation
Product
CipherTrust Transparent Encryption
What it does
Encrypts files and databases at rest, no app changes
The other half
Privileged-user access control — admin without reading
Deployment
Agent on the protected host
Vendor
Thales — Chairman & CEO Patrice Caine
The cyber arm
Thales Cloud Protection & Licensing
Analyst standing
KuppingerCole Overall Leader 2025 — Data Security Platforms
Gartner
No MQ exists for HSM or key management — Market Guides only
India engineering
2,200+ staff; Noida is the Cyber & Digital centre
Data residency
Yours — deploy on-premises or virtual in India
Data processing
On your infrastructure; CipherTrust SaaS is EU/NA only
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, key-custody scoping
Part 02 · Learn

Understand DSPM before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

An agent between the application and storage that encrypts data at rest and enforces access policy — with no modification to the application itself.

Blind spots vs known, governed data (Securiti) — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailTransparent Encryption
Where is dataUnknown / partial mapDiscovery + classification everywhere
Shadow dataUntracked exposureShadow & dark data detected
Misconfig riskFound late (if ever)Data risk & misconfig, ranked
Who can accessUnknownData Access Intelligence (the edge)
Least-privilegeOver-broad standing accessAccess governance — cut it back
Data + privacy + AISeparate tools, gapsOne DataAI Command Graph
Vendor backing(startup risk)Now part of Veeam
Best fit(varies)Know, govern access, reduce risk

Securiti DSPM tells you where your sensitive data is, who can access it, and how to reduce the risk — discover & classify, find misconfigurations, tie data risk to identity/access (least-privilege), protect at rest & in motion — on the DataAI Command Graph (same graph as privacy + AI). GigaOm ‘Highest Rated’, Gartner Customers’ Choice. Now part of Veeam. Honest: competitive field — DSPM inside cloud security? Wiz. Deep file/access heritage? Varonis. TechBag scopes modules, adds GST & the India DPDP framing.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The source

Discover & Classify

Find sensitive data everywhere

Discover and classify sensitive data across clouds, SaaS, on-prem, files and databases — so you know WHAT sensitive data you have and WHERE it lives, structured and unstructured alike. You can't secure data you can't see. Find it all first.

02
The assess

Find the Risk

Misconfigurations & exposure

Surface data risk and misconfigurations — public buckets, over-shared files, unencrypted or mis-permissioned data, shadow copies — and prioritise by sensitivity. See where sensitive data is actually exposed. Risk, ranked by what matters.

03
The differentiator

Map the Access

Who can reach this data

Data Access Intelligence & Governance maps WHO can access each store of sensitive data — identities, entitlements, effective permissions — so you don't just find sensitive data, you know who can reach it, and can enforce least-privilege. Data risk, tied to identity. The core edge.

04
The protect

Reduce & Protect

At rest and in motion

Reduce the risk — remediate misconfigurations, cut over-broad access, protect data at rest and in motion across clouds and SaaS — and keep it reduced. Not just finding risk, but reducing it. Posture that improves, not just reports.

05
The edge

Govern on One Graph

The DataAI Command Graph

Everything — the data, the risk, the access, the controls — is governed by ONE DataAI Command Graph, the SAME graph that powers Securiti's privacy and AI governance, so DSPM isn't a silo but part of a unified data-command story. One graph for data, access and beyond. Governed as one.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Locate, assess, protect.

Securiti finds your sensitive data, ties the risk to who can access it & reduces it — data-centric security posture from portfolio, and paired with the human firewall.

Locate
Data discovery

Sensitive Data Discovery

Discover sensitive data across clouds, SaaS, on-prem, files and databases — structured and unstructured — so you know what you have and where it lives. You can't secure what you can't see. Find it all.

Locate
Classification

Accurate Data Classification

Classify data by sensitivity and type (PII, PHI, PCI, secrets, regulated data) with high accuracy on the graph — so risk is prioritised by what actually matters. Know what each store holds. Classification you can trust.

Locate
Data catalog

Unified Sensitive-Data Catalog

A single catalog of your sensitive data across the whole estate — built on the DataAI Command Graph — so you have one map of where sensitive data lives. One map of your sensitive data. The single source of truth.

Locate
Shadow data

Shadow & Dark Data Detection

Surface shadow copies, forgotten stores and dark data that no one's tracking — the exposure you didn't know you had. Find the data you forgot about. No blind spots.

Assess
Misconfigurations

Data Risk & Misconfigurations

Detect data risk and misconfigurations — public buckets, unencrypted stores, over-permissive settings — and rank by sensitivity. See where sensitive data is exposed. Risk, prioritised.

Assess
Access intelligence

Data Access Intelligence

Map WHO can access each store of sensitive data — identities, entitlements, effective permissions — so you don't just find sensitive data, you know who can reach it. The differentiator. Data risk, tied to identity.

Assess
Over-exposure

Over-Shared & Over-Permissioned

Find data that's over-shared or over-permissioned — files anyone can open, identities with far more access than they need — so you can cut it back. Too much access is risk. Right-size it.

Assess
Risk scoring

Risk Prioritisation & Posture

Score and prioritise data risk continuously, and track your data security POSTURE over time — so you fix what matters most and catch drift early. Posture you can measure. Improve, don't just report.

Protect
Least-privilege

Least-Privilege Governance

Data Access Governance lets you enforce least-privilege — cut over-broad access to sensitive data down to who genuinely needs it. From knowing who can reach data to reducing it. Least-privilege, enforced.

Protect
Data protection

Protect at Rest & in Motion

Protect sensitive data at rest and in motion across clouds and SaaS — encryption, masking, controls — so exposure is reduced, not just reported. Reduce the risk, don't just find it. Protection that follows the data.

Protect
Remediation

Remediation & Continuous Monitoring

Remediate misconfigurations and over-broad access, and continuously monitor posture so drift is caught early — posture that gets better and stays better. Fix and keep it fixed. Continuous, not one-shot.

Protect
One graph

DataAI Command Graph

One knowledge graph maps sensitive data, its access and its controls — the SAME graph that powers Securiti's privacy and AI governance — so DSPM is part of a unified data story, not a silo. One graph for data and access. Context is everything.

See it, don’t just read it

Watch Securiti in action

The overview, getting started, and the core workflows.

Thales (official)·Demo

CipherTrust Transparent Encryption — Demo

Encrypting without changing the application.

Thales (official)·Platform

CipherTrust Data Security Platform — Overview

Where it sits in the platform.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Transparent Encryption

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Securiti apart (and where a point tool leads).

01

It makes legacy systems addressable at all

Every encryption programme meets the same wall: the systems most in need of protection are the ones nobody will modify. A fifteen-year-old application that the business depends on, that no current employee wrote, and whose vendor support ended years ago is not getting refactored to add encryption, whatever the policy says. An agent between the application and storage sidesteps the question entirely — the application is unchanged, the data on disk is protected, and the project can actually include the systems that mattered most. That is a deployment argument rather than a cryptographic one, and it is why this product exists.

02

Administering a system without reading its data

In most estates, the permission to keep a database running and the permission to read every customer record inside it are the same permission. That is not a considered decision; it is an accident of how database privileges work. Privileged-user access control separates them, so a DBA or root account can perform its actual job without the data being readable. When an RBI or SEBI reviewer asks who has access to production data, this is the control they are probing — and "our administrators, necessarily" is a much weaker answer than a demonstrable separation.

03

Policy enforced where the data is, not at the perimeter

Perimeter thinking assumes the boundary holds. Encrypting and enforcing access at the storage layer means a compromised network, a stolen backup or an over-permissioned account does not automatically yield readable data. The blast radius of any single failure shrinks, which is the practical security argument distinct from the compliance one.

04

The honest caveat: measure the overhead on your worst system

There is a performance cost to encrypting and decrypting on every read and write. How much depends entirely on your workload — I/O patterns, record sizes, how much of the working set is hot — and any number a vendor or a reseller quotes you in the abstract is close to meaningless. Test on your least-modern, most business-critical system rather than a clean host, because that is the system the project must survive. If the overhead is unacceptable there, better to know during a proof of concept than after a rollout.

05

The honest positioning

This is right when you need data at rest protected on infrastructure you control, especially across systems you cannot modify. It is the wrong product if your problem is documents leaving the organisation — protection here stops at the boundary of the systems you control, and a file exported by an authorised process is plaintext the moment it lands elsewhere. For that you want rights management, and TechBag sells Seclore and Microsoft Purview. It is also not a substitute for a key manager: Transparent Encryption applies protection, CipherTrust Manager decides who holds the keys, and serious deployments use both.

Where is data
Discover & classify everywhere
Who can access
Data risk tied to identity
Local via TechBag
Scoping, GST, DPDP framing
Proof, not promises

The numbers behind the platform

2200+ staff
Thales in India, across two engineering centres
Thales India
~450 more
India hires planned during 2026
Thales India
2 KC Leader awards
KuppingerCole Overall Leader, 2025
KuppingerCole
0 India SaaS regions
CipherTrust as-a-Service is EU/NA only
Thales docs
0 Gartner MQs
None exists for HSM or key management
Gartner
2000
Thales Group formed in its current form
Company

What your Securiti DSPM journey looks like

Week 1Assess

Settle key custody and deployment

Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.

Weeks 2–5Assess

Run discovery before scoping encryption

Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.

Weeks 4–10Deploy

Pilot on your least-modern system

Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.

Weeks 8–14Deploy

Name the HSM administrators and the approvers

Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.

OngoingOperate

Rotate on policy, and test the restore

Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
400+ reviews*
92% would recommend
Discovery & classification4.6
Data access intelligence4.6
Data + AI on one graph4.6
Breadth vs point-tool depth4.0
5
61%
4
29%
3
6%
2
2%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.
Head of Information Security
Banking
Manufacturing
Deploying against systems nobody would let us modify was the whole reason this got approved.
Infrastructure Lead
Manufacturing
Insurance
Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.
Security Architect
Insurance
Non-Banking Financial Company
No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the DSPM market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ThalesThis page

Key custody in hardware, with India engineering.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
ThalesThis page

Deepest on key custody; not a document product.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Securiti vs the DSPM field

Wiz (DSPM), Varonis, Cyera, Sentra and BigID — honest lanes; the edge is DSPM tied to identity/access AND unified with privacy + AI governance on one graph (a consolidation play), backed by strong analyst recognition. DSPM inside cloud security? Wiz. Deep file/access heritage? Varonis. We say so — we sell Wiz too.

DimensionThalesEntrustMicrosoft PurviewSecloreHashiCorp Vault
What it actually isKey management + hardware custody + encryptionThe HSM and PKI peerDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
Who holds the keysYou — in hardware if you wantYou — in hardwareMicrosoft, unless you use Double Key EncryptionEither — SaaS or self-hostedYou
Protection travels with the fileNo — this protects infrastructure, not documentsNoYes — labels travel with the fileYes, with post-distribution revocationNo
Hardware key custodyLuna HSMnShield — holds BIS certificationDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
India data residencyDeploy on-premises — no India SaaS regionOn-premises appliances — no India SaaSIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Analyst standingKuppingerCole Overall Leader 2025 ×2No HSM/key-management Leader placement foundMicrosoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundHSM operations: firmware, backup, separation of dutiesScope: it exited public TLS in Sep 2025DKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitKey custody with hardware, on your own infrastructureWhere BIS certification is a procurement requirementMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Securiti if…

  • You want DSPM that ties data risk to IDENTITY & ACCESS — know who can reach sensitive data, enforce least-privilege
  • You want DSPM on the SAME graph as privacy + AI governance — a consolidation play, not stitched point tools
  • You value analyst recognition — GigaOm 'Highest Rated', Gartner Customers' Choice
  • You value the backing — now part of Veeam — and the India DPDP framing (via TechBag)

Wiz (DSPM) if…

  • You want DSPM WITHIN your cloud-security platform, where your cloud security already lives (TechBag sells Wiz too)

Varonis if…

  • Your priority is deep unstructured-file and data-ACCESS risk, especially on-prem (deep heritage)

Cyera / Sentra if…

  • You want a focused, best-of-breed DSPM specialist rather than a broad platform

BigID if…

  • Your priority is data-intelligence-led discovery and catalog depth — see the Securiti privacy pages too

CipherTrust Transparent Encryption is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (data stores; sensitive-data sources; hour cost as loaded rate). Estimates contrast blind-spot data security (unknown data map, unseen misconfigurations, no access intelligence, over-broad access) vs Securiti (discover & classify, find risk, tie to access, least-privilege) — the wins are faster risk reduction and fewer exposure/compliance incidents. Illustrative — TechBag scopes your estate.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes the modules you actually need (DSPM, data access governance, privacy, AI governance), adds INR/GST, and frames it against DPDP — quote current figures for your estate.

Securiti DSPM (modular, by quote)

Best for data security posture

  • DSPM + Data Access Intelligence & Governance (least-privilege)
  • One DataAI Command Graph — data, access, privacy & AI together
  • GigaOm ‘Highest Rated’ · Gartner Customers’ Choice · now part of Veeam

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ scoping & DPDP framing

Best value with TechBag

  • Module scoping + honest Wiz/Varonis/Cyera/Sentra comparison (we sell Wiz too)
  • Securiti prices by quote in USD; broad platform — scope what you need
  • TechBag adds INR/GST, local support & the India DPDP framing

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Key custody

Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?

2
Deployment

Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?

3
Residency

Are we clear that Thales's India engineering presence is people, not a data region?

4
Discovery

Have we scanned rather than relied on an asset inventory to scope this?

5
Performance

Have we measured the overhead on our least-modern business-critical system?

6
Separation of duties

Who administers the HSM, and who approves key use? They must not be the same person.

7
Resilience

Do we need a second appliance at another site, and is it budgeted?

8
Backup

Have we backed up the security domain AND tested restoring from it?

9
Scope

Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.

10
Commercials

Have we priced hardware, support, resilience and operations — not just the licence?

FAQ

Questions buyers ask

Through deployment rather than through a vendor region, and the distinction is the first thing to settle. CipherTrust as-a-Service runs in Europe and North America only — there is no India region, and we are not going to imply otherwise. For a residency-bound Indian buyer the answer is on-premises or virtual deployment in your own data centre, with keys under your control and, if the requirement demands it, inside a Luna HSM physically in your building. That is a stronger custody position than any vendor-hosted region could provide, and it is very likely what a regulator was pushing you toward in the first place. Be precise about a fact this market blurs constantly. Thales has more than 2,200 staff in India across two engineering competence centres, with Noida specifically the Cyber and Digital centre, and is hiring around 450 more during 2026. That is a genuine and unusual commitment — and it is people, not a data region. Treating an engineering presence as a residency answer is exactly the error that surfaces during an audit, and it is worth stating plainly because vendors on all sides encourage the confusion. What the India presence does buy you is real: Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's outsourcing directions for NBFCs, which means the vendor has already done the work of understanding what an Indian regulator expects rather than translating a US framework. On DPDP specifically, the sequence matters more than the product: find the personal data first, then protect it. Discovery before encryption, every time.

Ready to know where your data is?

Scope Securiti DSPM (know where your sensitive data is, who can access it, and reduce the risk — discovery & classification, data risk & misconfigurations, Data Access Intelligence & Governance for least-privilege, protection at rest & in motion, all on the DataAI Command Graph, now Veeam-backed) — and let a TechBag advisor scope the modules, compare vs Wiz/Varonis/Cyera/Sentra honestly, frame it against DPDP, and add INR/GST and local support.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.