Talk to us
by ThalesTechBag Intel Page

CipherTrust Data Discovery & Classification

You cannot encrypt what nobody knows exists — discovery scans structured and unstructured stores to find sensitive data and label it, and the output drives encryption policy directly rather than becoming a report nobody acts on. all discovery-driven, run off actual discovered data on the DataAI Command Graph. Now part of Veeam.

The DPDP starting pointFeeds policy, not a spreadsheetFinds — does not protect

Data residency & processing — two different questions

Where data lives

Yours — deploy on-premises in India

CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India SaaS region — and Noida is people, not data

CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
DPDP relevance
you cannot protect what you cannot find
The starting point
Integration
discovery drives policy, not a report
Feeds the platform
Scope
the input to a decision, not the decision
Finds, does not protect
Coverage
including the stores nobody remembers
Structured & unstructured

Quick answer

CipherTrust Data Discovery and Classification scans structured and unstructured data stores to find sensitive data and label what it finds. It is the least glamorous product on this page and the one most likely to determine whether the rest of your programme succeeds, because every other control here — encryption, access policy, key management — has to be pointed at something, and pointing it at an asset inventory nobody trusts is how encryption projects quietly miss the data that mattered. Under India's DPDP Act this stops being merely good practice. The Act's first practical question is not how you protect personal data but where it is, and most organisations genuinely cannot answer that: the answer lives in the reporting replica somebody stood up for a quarterly deadline, the analytics extract that was supposed to be temporary, the departmental file share created before anyone was governing file shares. Those are precisely the stores that produce breaches and complaints, and precisely the ones absent from the CMDB. A scan finds them; an inventory does not. What makes this version useful rather than another report is that the output feeds the platform directly — discovery results drive encryption and access policy in CipherTrust rather than arriving as a spreadsheet somebody is supposed to act on. Classification that does not trigger a protection decision is an audit artefact, and audit artefacts are where this category usually dies. One honest note: discovery finds and labels, it does not protect. It is the input, and it needs the encryption and key management alongside it to mean anything. Read more ↓ Show less ↑
Part 01 · Orient

The Postman platform family

This page covers CipherTrust Data Discovery & Classification — the PrivacyOps original core. The rest of the Securiti platform:

Quick facts

30-second orientation
Product
CipherTrust Data Discovery & Classification
What it does
Finds and classifies sensitive data across your stores
Why it matters first
DPDP's real first question is where personal data is
The point
Output drives encryption policy, not a spreadsheet
Vendor
Thales — Chairman & CEO Patrice Caine
The cyber arm
Thales Cloud Protection & Licensing
Analyst standing
KuppingerCole Overall Leader 2025 — Data Security Platforms
Gartner
No MQ exists for HSM or key management — Market Guides only
India engineering
2,200+ staff; Noida is the Cyber & Digital centre
Data residency
Yours — deploy on-premises or virtual in India
Data processing
On your infrastructure; CipherTrust SaaS is EU/NA only
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, key-custody scoping
Part 02 · Learn

Understand privacy automation before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Scanning that finds sensitive data across structured and unstructured stores and classifies what it finds — the prerequisite to every other control on this platform.

Survey-based privacy vs discovery-driven privacy (Securiti) — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailDiscovery & Classification
Data inventoryManual surveys, stale spreadsheetsDiscovered data on the graph
DSR / DSARManual scramble across systemsAutomated off real data
ConsentSeparate cookie / mobile toolsUniversal (1st + 3rd + mobile)
AssessmentsQuestionnaires from memoryPIA/DPIA off discovered data
BreachEmail + spreadsheetsNotification workflows w/ deadlines
PlatformFragmented point toolsOne graph (privacy + DSPM + AI)
Vendor backing(startup risk)Now part of Veeam
Best fit(varies)Discovery-driven privacy automation

Securiti Data Privacy Automation is PrivacyOps — automate DSR/DSAR, universal consent (1st + 3rd + mobile), PIA/DPIA and breach, all DISCOVERY-DRIVEN off actual discovered data on one graph (privacy grounded in reality, not stale surveys). Now part of Veeam. Honest: OneTrust leads pure privacy & consent breadth; Securiti’s edge is discovery-driven privacy on a unified data+AI platform. TechBag scopes modules, adds GST & the India DPDP framing.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The foundation

Discover the Data First

The DataAI Command Graph

Before any privacy task, Securiti discovers and maps personal data across your estate — clouds, SaaS, on-prem, files, databases — onto the DataAI Command Graph, so it KNOWS where personal data actually lives. Privacy grounded in reality, not a survey. Know your data first.

02
Fulfil

Fulfil DSRs Automatically

DSR / DSAR automation

When a data-subject or data-principal requests access, deletion or correction, Securiti runs the request off the discovered data — finding the person's data where it really lives and orchestrating fulfilment against the legal deadline. Rights honoured off real data. Automate the request, not the guesswork.

03
Consent

Capture Consent Everywhere

Universal Consent Management

Collect, store and honour consent across first-party, third-party and mobile — cookie banners, preference centres, mobile SDKs — with a single record of what each person agreed to. One source of consent truth. Honour what people actually agreed to.

04
Comply

Assess & Manage Breaches

PIA/DPIA + breach workflows

Run privacy assessments (PIA/DPIA) answered from real discovered data, and manage breaches with notification workflows that track regulatory deadlines (72-hour clocks, DPB notification). Assessments off reality; breaches under control. Comply with confidence.

05
The edge

Run It All Off One Graph

The DataAI Command Graph

Every privacy function — DSRs, consent, assessments, breach, Privacy Center — runs off ONE graph that also powers DSPM, governance and AI security, so privacy is grounded in the same data intelligence, not a siloed tool. One graph for privacy, security and AI. Grounded as one.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Fulfil, consent, comply.

Securiti automates the whole privacy program off real discovered data — DSR, consent, assessments & breach — the PrivacyOps original of portfolio, and paired with the human firewall.

Fulfil
DSR / DSAR

DSR / DSAR Automation

Automate data-subject and data-principal requests — access, deletion, correction — fulfilled off the actual discovered data, so you honour rights within the legal deadline without a manual scramble. Rights, automated. Off real data, not spreadsheets.

Fulfil
Deletion

Verified Deletion & Correction

Because Securiti knows where a person's data lives (from the graph), deletion and correction requests reach the data where it actually is — with verification — rather than hoping a survey caught every system. Delete for real. Verified across the estate.

Fulfil
Privacy Center

Self-Service Privacy Center

Give data principals a branded self-service portal to submit requests, manage preferences and see how their data is used — the front door to your privacy program. A privacy front door. Self-service, on brand.

Consent
Universal consent

Universal Consent Management

Collect, store and honour consent across first-party, third-party and mobile — one record of what each person agreed to — so downstream use stays lawful. Consent, unified. Honour every choice.

Consent
Cookie consent

Cookie Consent & Banners

Scan sites for cookies and trackers, serve compliant cookie banners and preference centres, and honour opt-outs — keeping first- and third-party tracking lawful. Lawful tracking. Banners that actually honour choices.

Consent
Preferences

Preference & Universal Opt-Out

Manage granular preferences and honour universal opt-out signals (like Global Privacy Control) — so a person's choice is respected everywhere it applies. Preferences, respected everywhere. One choice, honoured.

Comply
PIA / DPIA

Privacy Assessments (PIA/DPIA)

Run privacy impact and data-protection impact assessments answered from REAL discovered data — not a questionnaire filled in from memory — so assessments reflect data reality. Assessments off reality. Automated, not guessed.

Comply
Breach management

Breach & Incident Management

Manage privacy incidents with notification workflows that track regulatory deadlines (GDPR 72-hour clocks, India DPB notification) and generate the right disclosures. Breaches under control. Notify on time, every time.

Comply
Data mapping

Data Mapping & RoPA

Automate data mapping and Records of Processing Activities (RoPA / Article 30) off discovered data flows — so your processing records stay accurate as your estate changes. Living data maps. RoPA that stays true.

Comply
Policy management

Privacy Policy Management

Author, publish and keep privacy notices and policies current across sites and regions — so what you promise data subjects stays accurate and consistent. Policies that stay current. One source of truth.

Comply
Regulatory intel

Global Regulatory Intelligence

Built-in intelligence across DPDP, GDPR, CCPA/CPRA and hundreds of global privacy regimes — so obligations are pre-mapped, not researched from scratch. Compliance, pre-mapped. Global regimes, one platform.

Comply
Discovery-driven

Privacy Driven by Discovery

The differentiator: every privacy function runs off actual discovered data via the DataAI Command Graph — the same graph that powers DSPM, governance and AI — so privacy is grounded in what data you really have. Privacy off real data. One graph, one truth.

See it, don’t just read it

Watch Securiti privacy in action

The overview, getting started, and the core workflows.

Thales (official)·Platform

CipherTrust Data Security Platform — Overview

Where discovery sits in the platform.

Thales (official)·Encryption

CipherTrust — Advanced Encryption

What discovery output feeds into.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Discovery & Classification

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Securiti apart (and where OneTrust leads).

01

Every other control has to be pointed at something

Encryption, access policy and key management are all aimed. If the aim comes from an asset inventory, it inherits that inventory's blind spots — and every organisation's inventory has them, because inventories record what was provisioned deliberately and sensitive data accumulates by accident. The reporting replica, the analytics extract, the file share from before anyone governed file shares: none is in the CMDB, and all three are exactly where a breach or a DPDP complaint starts. Scanning finds them. Asking does not.

02

DPDP makes this the first question, not the third

India's DPDP Act obliges you to know what personal data you hold and where. That sounds like documentation and is actually discovery, because the honest state of most estates is that nobody can answer it. Teams that begin with an encryption project and treat discovery as a later phase consistently rediscover this halfway through and restart. Beginning with the scan is slower to start and considerably faster to finish, and it produces the evidence a regulator asks for as a by-product.

03

Classification that triggers protection, not a report

This category's usual failure mode is a beautifully detailed report that nobody acts on, because acting on it means a separate project with separate funding. Discovery inside the CipherTrust platform feeds encryption and access policy directly — a classification decision becomes a protection decision rather than a recommendation. That closes the loop that otherwise leaves classification as an audit artefact, and it is the main reason to prefer platform-integrated discovery over a standalone scanner.

04

The honest limit: this finds, it does not protect

Discovery and classification tell you where sensitive data is and what it is. They do not encrypt it, do not control who reaches it, and do not follow it anywhere. On its own this product improves your knowledge and nothing else — which is genuinely valuable, and is not protection. It is the input to a decision, so budget it alongside the encryption and key management rather than as a substitute, and be clear internally that finishing the scan is the start of the work rather than the end of it.

05

The honest positioning

Start here if you cannot confidently say where your personal or sensitive data lives — which, in our experience, is most organisations that have been operating for more than a few years. Start elsewhere if you already have a trustworthy data map and the problem is purely protection. And if you have already bought classification from another vendor and it is working, there is no strong reason to replace it; what matters is that the output reaches whatever applies protection, and we would rather integrate what you have than sell you a second scanner.

Discovery-driven
DSRs off real data, not surveys
One platform
DSR + consent + assessments + breach
Local via TechBag
Scoping, GST, DPDP framing
Proof, not promises

The numbers behind the platform

2200+ staff
Thales in India, across two engineering centres
Thales India
~450 more
India hires planned during 2026
Thales India
2 KC Leader awards
KuppingerCole Overall Leader, 2025
KuppingerCole
0 India SaaS regions
CipherTrust as-a-Service is EU/NA only
Thales docs
0 Gartner MQs
None exists for HSM or key management
Gartner
2000
Thales Group formed in its current form
Company

What your Securiti privacy journey looks like

Week 1Assess

Settle key custody and deployment

Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.

Weeks 2–5Assess

Run discovery before scoping encryption

Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.

Weeks 4–10Deploy

Pilot on your least-modern system

Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.

Weeks 8–14Deploy

Name the HSM administrators and the approvers

Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.

OngoingOperate

Rotate on policy, and test the restore

Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
420+ reviews*
90% would recommend
DSR/DSAR automation4.5
Consent management4.4
Discovery-driven privacy4.7
Pure-privacy breadth (vs OneTrust)4.1
5
59%
4
29%
3
8%
2
2%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.
Head of Information Security
Banking
Manufacturing
Deploying against systems nobody would let us modify was the whole reason this got approved.
Infrastructure Lead
Manufacturing
Insurance
Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.
Security Architect
Insurance
Non-Banking Financial Company
No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Data privacy automation market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ThalesThis page

Key custody in hardware, with India engineering.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
ThalesThis page

Deepest on key custody; not a document product.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Securiti vs the privacy field

OneTrust, TrustArc, BigID, Osano and DataGrail — honest lanes. OneTrust is the privacy MARKET LEADER (deeper in pure privacy & consent); Securiti’s edge is discovery-driven privacy (off real data) on a unified data+AI platform (one graph, a consolidation play). Pure privacy leadership? OneTrust. We say so.

DimensionThalesEntrustMicrosoft PurviewSecloreHashiCorp Vault
What it actually isKey management + hardware custody + encryptionThe HSM and PKI peerDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
Who holds the keysYou — in hardware if you wantYou — in hardwareMicrosoft, unless you use Double Key EncryptionEither — SaaS or self-hostedYou
Protection travels with the fileNo — this protects infrastructure, not documentsNoYes — labels travel with the fileYes, with post-distribution revocationNo
Hardware key custodyLuna HSMnShield — holds BIS certificationDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
India data residencyDeploy on-premises — no India SaaS regionOn-premises appliances — no India SaaSIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Analyst standingKuppingerCole Overall Leader 2025 ×2No HSM/key-management Leader placement foundMicrosoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundHSM operations: firmware, backup, separation of dutiesScope: it exited public TLS in Sep 2025DKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitKey custody with hardware, on your own infrastructureWhere BIS certification is a procurement requirementMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Securiti if…

  • You want privacy automation DRIVEN BY DISCOVERY — DSRs and assessments off actual discovered data, not stale surveys
  • You want the whole privacy program on one platform (DSR, consent, PIA/DPIA, breach, Privacy Center)
  • You want privacy grounded in the SAME graph as DSPM, governance and AI — a consolidation play
  • You value the backing — now part of Veeam — and the India DPDP framing (via TechBag)

OneTrust if…

  • Your priority is pure privacy & consent LEADERSHIP and depth — the most entrenched, feature-complete privacy platform (honest: OneTrust leads pure privacy)

TrustArc / BigID if…

  • You want a long-standing privacy specialist (TrustArc) or privacy grounded in data-discovery heritage (BigID)

Osano / DataGrail if…

  • You want a lighter, mid-market-friendly (Osano) or developer-friendly (DataGrail) privacy tool

Other Securiti modules…

  • Also need DSPM, governance or AI security? Privacy runs off the same graph — see the Securiti DSPM and Gencore AI pages

CipherTrust Data Discovery & Classification is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (data-subject requests per month; sensitive-data sources; hour cost as loaded rate). Estimates contrast survey-based DIY privacy (stale inventories, manual DSR scrambles, questionnaire assessments) vs Securiti (discovery-driven DSRs off real data, universal consent, assessments from reality, one graph) — the wins are faster, more accurate fulfilment and reduced compliance risk. Illustrative — TechBag scopes your estate.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes the privacy modules you actually need (DSR/DSAR, consent, assessments, breach, Privacy Center), adds INR/GST, and frames it against DPDP — quote current figures for your estate.

Securiti (modular, by quote)

Best for discovery-driven privacy automation

  • DSR/DSAR + universal consent + PIA/DPIA + breach + Privacy Center
  • Discovery-driven — runs off actual discovered data (one graph)
  • Now part of Veeam; privacy on the same graph as DSPM & AI

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ scoping & DPDP framing

Best value with TechBag

  • Module scoping + honest OneTrust/TrustArc/BigID comparison
  • Securiti prices by quote in USD; broad platform — scope what you need
  • TechBag adds INR/GST, local support & the India DPDP framing

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Key custody

Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?

2
Deployment

Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?

3
Residency

Are we clear that Thales's India engineering presence is people, not a data region?

4
Discovery

Have we scanned rather than relied on an asset inventory to scope this?

5
Performance

Have we measured the overhead on our least-modern business-critical system?

6
Separation of duties

Who administers the HSM, and who approves key use? They must not be the same person.

7
Resilience

Do we need a second appliance at another site, and is it budgeted?

8
Backup

Have we backed up the security domain AND tested restoring from it?

9
Scope

Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.

10
Commercials

Have we priced hardware, support, resilience and operations — not just the licence?

FAQ

Questions buyers ask

Through deployment rather than through a vendor region, and the distinction is the first thing to settle. CipherTrust as-a-Service runs in Europe and North America only — there is no India region, and we are not going to imply otherwise. For a residency-bound Indian buyer the answer is on-premises or virtual deployment in your own data centre, with keys under your control and, if the requirement demands it, inside a Luna HSM physically in your building. That is a stronger custody position than any vendor-hosted region could provide, and it is very likely what a regulator was pushing you toward in the first place. Be precise about a fact this market blurs constantly. Thales has more than 2,200 staff in India across two engineering competence centres, with Noida specifically the Cyber and Digital centre, and is hiring around 450 more during 2026. That is a genuine and unusual commitment — and it is people, not a data region. Treating an engineering presence as a residency answer is exactly the error that surfaces during an audit, and it is worth stating plainly because vendors on all sides encourage the confusion. What the India presence does buy you is real: Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's outsourcing directions for NBFCs, which means the vendor has already done the work of understanding what an Indian regulator expects rather than translating a US framework. On DPDP specifically, the sequence matters more than the product: find the personal data first, then protect it. Discovery before encryption, every time.

Ready to automate privacy off real data?

Scope Securiti Data Privacy Automation (automate DSR/DSAR, universal consent, PIA/DPIA and breach — all discovery-driven, run off actual discovered data on the DataAI Command Graph, now Veeam-backed) — and let a TechBag advisor scope the modules, compare vs OneTrust honestly, frame it against DPDP, and add INR/GST and local support.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.