You cannot encrypt what nobody knows exists — discovery scans structured and unstructured stores to find sensitive data and label it, and the output drives encryption policy directly rather than becoming a report nobody acts on. all discovery-driven, run off actual discovered data on the DataAI Command Graph. Now part of Veeam.
Data residency & processing — two different questions
Where data lives
Yours — deploy on-premises in India
CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.
The constraint, stated plainly
No India SaaS region — and Noida is people, not data
CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.
For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers CipherTrust Data Discovery & Classification — the PrivacyOps original core. The rest of the Securiti platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Scanning that finds sensitive data across structured and unstructured stores and classifies what it finds — the prerequisite to every other control on this platform.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | Discovery & Classification |
|---|---|---|
| Data inventory | Manual surveys, stale spreadsheets | Discovered data on the graph |
| DSR / DSAR | Manual scramble across systems | Automated off real data |
| Consent | Separate cookie / mobile tools | Universal (1st + 3rd + mobile) |
| Assessments | Questionnaires from memory | PIA/DPIA off discovered data |
| Breach | Email + spreadsheets | Notification workflows w/ deadlines |
| Platform | Fragmented point tools | One graph (privacy + DSPM + AI) |
| Vendor backing | (startup risk) | Now part of Veeam |
| Best fit | (varies) | Discovery-driven privacy automation |
Securiti Data Privacy Automation is PrivacyOps — automate DSR/DSAR, universal consent (1st + 3rd + mobile), PIA/DPIA and breach, all DISCOVERY-DRIVEN off actual discovered data on one graph (privacy grounded in reality, not stale surveys). Now part of Veeam. Honest: OneTrust leads pure privacy & consent breadth; Securiti’s edge is discovery-driven privacy on a unified data+AI platform. TechBag scopes modules, adds GST & the India DPDP framing.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Before any privacy task, Securiti discovers and maps personal data across your estate — clouds, SaaS, on-prem, files, databases — onto the DataAI Command Graph, so it KNOWS where personal data actually lives. Privacy grounded in reality, not a survey. Know your data first.
When a data-subject or data-principal requests access, deletion or correction, Securiti runs the request off the discovered data — finding the person's data where it really lives and orchestrating fulfilment against the legal deadline. Rights honoured off real data. Automate the request, not the guesswork.
Collect, store and honour consent across first-party, third-party and mobile — cookie banners, preference centres, mobile SDKs — with a single record of what each person agreed to. One source of consent truth. Honour what people actually agreed to.
Run privacy assessments (PIA/DPIA) answered from real discovered data, and manage breaches with notification workflows that track regulatory deadlines (72-hour clocks, DPB notification). Assessments off reality; breaches under control. Comply with confidence.
Every privacy function — DSRs, consent, assessments, breach, Privacy Center — runs off ONE graph that also powers DSPM, governance and AI security, so privacy is grounded in the same data intelligence, not a siloed tool. One graph for privacy, security and AI. Grounded as one.
One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.
Securiti automates the whole privacy program off real discovered data — DSR, consent, assessments & breach — the PrivacyOps original of portfolio, and paired with the human firewall.
Automate data-subject and data-principal requests — access, deletion, correction — fulfilled off the actual discovered data, so you honour rights within the legal deadline without a manual scramble. Rights, automated. Off real data, not spreadsheets.
Because Securiti knows where a person's data lives (from the graph), deletion and correction requests reach the data where it actually is — with verification — rather than hoping a survey caught every system. Delete for real. Verified across the estate.
Give data principals a branded self-service portal to submit requests, manage preferences and see how their data is used — the front door to your privacy program. A privacy front door. Self-service, on brand.
Collect, store and honour consent across first-party, third-party and mobile — one record of what each person agreed to — so downstream use stays lawful. Consent, unified. Honour every choice.
Scan sites for cookies and trackers, serve compliant cookie banners and preference centres, and honour opt-outs — keeping first- and third-party tracking lawful. Lawful tracking. Banners that actually honour choices.
Manage granular preferences and honour universal opt-out signals (like Global Privacy Control) — so a person's choice is respected everywhere it applies. Preferences, respected everywhere. One choice, honoured.
Run privacy impact and data-protection impact assessments answered from REAL discovered data — not a questionnaire filled in from memory — so assessments reflect data reality. Assessments off reality. Automated, not guessed.
Manage privacy incidents with notification workflows that track regulatory deadlines (GDPR 72-hour clocks, India DPB notification) and generate the right disclosures. Breaches under control. Notify on time, every time.
Automate data mapping and Records of Processing Activities (RoPA / Article 30) off discovered data flows — so your processing records stay accurate as your estate changes. Living data maps. RoPA that stays true.
Author, publish and keep privacy notices and policies current across sites and regions — so what you promise data subjects stays accurate and consistent. Policies that stay current. One source of truth.
Built-in intelligence across DPDP, GDPR, CCPA/CPRA and hundreds of global privacy regimes — so obligations are pre-mapped, not researched from scratch. Compliance, pre-mapped. Global regimes, one platform.
The differentiator: every privacy function runs off actual discovered data via the DataAI Command Graph — the same graph that powers DSPM, governance and AI — so privacy is grounded in what data you really have. Privacy off real data. One graph, one truth.
The overview, getting started, and the core workflows.
Where discovery sits in the platform.
What discovery output feeds into.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Securiti apart (and where OneTrust leads).
Encryption, access policy and key management are all aimed. If the aim comes from an asset inventory, it inherits that inventory's blind spots — and every organisation's inventory has them, because inventories record what was provisioned deliberately and sensitive data accumulates by accident. The reporting replica, the analytics extract, the file share from before anyone governed file shares: none is in the CMDB, and all three are exactly where a breach or a DPDP complaint starts. Scanning finds them. Asking does not.
India's DPDP Act obliges you to know what personal data you hold and where. That sounds like documentation and is actually discovery, because the honest state of most estates is that nobody can answer it. Teams that begin with an encryption project and treat discovery as a later phase consistently rediscover this halfway through and restart. Beginning with the scan is slower to start and considerably faster to finish, and it produces the evidence a regulator asks for as a by-product.
This category's usual failure mode is a beautifully detailed report that nobody acts on, because acting on it means a separate project with separate funding. Discovery inside the CipherTrust platform feeds encryption and access policy directly — a classification decision becomes a protection decision rather than a recommendation. That closes the loop that otherwise leaves classification as an audit artefact, and it is the main reason to prefer platform-integrated discovery over a standalone scanner.
Discovery and classification tell you where sensitive data is and what it is. They do not encrypt it, do not control who reaches it, and do not follow it anywhere. On its own this product improves your knowledge and nothing else — which is genuinely valuable, and is not protection. It is the input to a decision, so budget it alongside the encryption and key management rather than as a substitute, and be clear internally that finishing the scan is the start of the work rather than the end of it.
Start here if you cannot confidently say where your personal or sensitive data lives — which, in our experience, is most organisations that have been operating for more than a few years. Start elsewhere if you already have a trustworthy data map and the problem is purely protection. And if you have already bought classification from another vendor and it is working, there is no strong reason to replace it; what matters is that the output reaches whatever applies protection, and we would rather integrate what you have than sell you a second scanner.
Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.
Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.
Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.
Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.
Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.”
“Deploying against systems nobody would let us modify was the whole reason this got approved.”
“Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.”
“No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Data privacy automation market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Key custody in hardware, with India engineering.
The grid nobody publishes — how deep the core capability is vs how broad the wider platform.
Deepest on key custody; not a document product.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
OneTrust, TrustArc, BigID, Osano and DataGrail — honest lanes. OneTrust is the privacy MARKET LEADER (deeper in pure privacy & consent); Securiti’s edge is discovery-driven privacy (off real data) on a unified data+AI platform (one graph, a consolidation play). Pure privacy leadership? OneTrust. We say so.
| Dimension | Thales | Entrust | Microsoft Purview | Seclore | HashiCorp Vault |
|---|---|---|---|---|---|
| What it actually is | Key management + hardware custody + encryption | The HSM and PKI peer | Document rights management | India-built EDRM | Secrets and encryption-as-a-service |
| Who holds the keys | You — in hardware if you want | You — in hardware | Microsoft, unless you use Double Key Encryption | Either — SaaS or self-hosted | You |
| Protection travels with the file | No — this protects infrastructure, not documents | No | Yes — labels travel with the file | Yes, with post-distribution revocation | No |
| Hardware key custody | Luna HSM | nShield — holds BIS certification | DKE holds one key; not an HSM product | Not an HSM vendor | Can integrate with an HSM |
| India data residency | Deploy on-premises — no India SaaS region | On-premises appliances — no India SaaS | India region via Advanced Data Residency | India-built; SaaS or self-hosted | Self-host anywhere, including India |
| Analyst standing | KuppingerCole Overall Leader 2025 ×2 | No HSM/key-management Leader placement found | Microsoft, evaluated broadly elsewhere | Specialist — no Gartner EDRM MQ exists | Widely recognised in its category |
| Published pricing | Quote-only | Quote-only | $12/user/mo Purview add-on; E5 $60 | Quote (INR) | Free community edition |
| The thing to plan around | HSM operations: firmware, backup, separation of duties | Scope: it exited public TLS in Sep 2025 | DKE breaks co-authoring, search and Copilot | Adoption — manual protection is rarely applied | Operationally heavy to run well |
| Best fit | Key custody with hardware, on your own infrastructure | Where BIS certification is a procurement requirement | Microsoft estates with E5 needing document labels | Documents shared outside, India-built vendor | Engineering-owned secrets and encryption services |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
CipherTrust Data Discovery & Classification is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (data-subject requests per month; sensitive-data sources; hour cost as loaded rate). Estimates contrast survey-based DIY privacy (stale inventories, manual DSR scrambles, questionnaire assessments) vs Securiti (discovery-driven DSRs off real data, universal consent, assessments from reality, one graph) — the wins are faster, more accurate fulfilment and reduced compliance risk. Illustrative — TechBag scopes your estate.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes the privacy modules you actually need (DSR/DSAR, consent, assessments, breach, Privacy Center), adds INR/GST, and frames it against DPDP — quote current figures for your estate.
Best for discovery-driven privacy automation
Best for a broader rollout
Best value with TechBag
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?
Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?
Are we clear that Thales's India engineering presence is people, not a data region?
Have we scanned rather than relied on an asset inventory to scope this?
Have we measured the overhead on our least-modern business-critical system?
Who administers the HSM, and who approves key use? They must not be the same person.
Do we need a second appliance at another site, and is it budgeted?
Have we backed up the security domain AND tested restoring from it?
Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.
Have we priced hardware, support, resilience and operations — not just the licence?
Scope Securiti Data Privacy Automation (automate DSR/DSAR, universal consent, PIA/DPIA and breach — all discovery-driven, run off actual discovered data on the DataAI Command Graph, now Veeam-backed) — and let a TechBag advisor scope the modules, compare vs OneTrust honestly, frame it against DPDP, and add INR/GST and local support.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.