A key in a physical box in your data centre — Luna HSM generates and stores keys inside tamper-resistant hardware, and key material never leaves in usable form. No cloud provider, no vendor and no administrator can extract it.regulatory library (GDPR, CCPA, DPDP, PCI-DSS) — all off the DataAI Command Graph. Now part of Veeam.
Data residency & processing — two different questions
Where data lives
Yours — deploy on-premises in India
CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.
The constraint, stated plainly
No India SaaS region — and Noida is people, not data
CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.
For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Luna HSM — catalog, govern, comply. The rest of the Securiti platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A tamper-resistant hardware appliance that generates and stores cryptographic keys and performs operations inside the device. Key material never leaves in usable form.
What consolidation actually replaces, dimension by dimension.
| Dimension | Unprotected / signature email | Luna HSM |
|---|---|---|
| The catalog | Hand-maintained, drifting | Built off the discovery graph, current |
| Lineage | Manual / unknown | Automated data lineage |
| Access | Over-permissive, unclear | Data Access Governance |
| Unstructured data | Ungoverned files & docs | Unstructured Data Governance |
| Compliance | Manual, per-law, siloed | Hundreds of laws, one library |
| India DPDP | Ad hoc, over-localised | Automated (negative-list transfers) |
| Vendor backing | (startup risk) | Now part of Veeam |
| Best fit | (varies) | Catalog, govern & comply on one graph |
Securiti Data Governance & Compliance catalogs, governs and complies with your data — catalog, lineage, quality; access & unstructured governance; and a deep regulatory library (hundreds of laws, DPDP + global) — all off one discovery graph. Now part of Veeam. Honest: Collibra & Alation LEAD pure data governance — Securiti’s edge is govern-plus-comply on one graph. TechBag scopes modules, adds GST & the accurate India DPDP framing.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Governance rides on the SAME discovery graph that finds and classifies your sensitive data — so the catalog, lineage and access controls draw on real, live data context, not a hand-maintained inventory that drifts. Govern what you actually have. One graph underneath it all.
Build a Data Catalog with automated Lineage (where data comes from and flows to) and Data Quality — so people can find, trust and understand data across the estate. Know your data, and trust it. A catalog that stays current.
Enforce Data Access Governance (who can access what, entitled to the right controls) and Unstructured Data Governance (files, docs and shadow data, not just structured databases). Right data, right people, everywhere. Govern structured AND unstructured.
Automate compliance across HUNDREDS of global laws — GDPR, CCPA/CPRA, India's DPDP Act, PCI-DSS and more — with built-in regulatory intelligence that maps each obligation to your actual data. Compliance, mapped to your data. Every law, one library.
Because governance and compliance run off the same graph as Securiti's privacy, DSPM and AI governance, you govern data, comply with law and secure it — all in one context, not stitched silos. Govern, comply and secure as one. The consolidation play.
One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.
Securiti lets you catalog, govern and comply with your data — on one discovery graph, across hundreds of laws — the governance & compliance suite of portfolio, and paired with the human firewall.
A living catalog of your data assets across clouds, SaaS, on-prem and files — built off the discovery graph, so people can find and trust data. A catalog that stays current, not a stale spreadsheet.
See where data comes from and where it flows — automated lineage across systems — so you can trace impact, prove provenance and answer 'where did this data go?'. Trace every flow. Provenance you can prove.
Profile and monitor data quality — completeness, validity, freshness — so the data people govern and report on is data they can trust. Govern good data, not garbage. Quality you can measure.
The catalog, lineage and access controls all ride on the SAME graph that discovers and classifies sensitive data — so governance reflects real, live data context, not a drifting manual inventory. Govern what you actually have.
Govern who can access what — entitlements, over-permissive access, and the controls each dataset needs — so the right people get the right data and nobody gets more than they should. Right data, right people. Least privilege, at scale.
Govern files, documents and shadow data — not just structured databases — where so much sensitive data actually lives. Govern the messy 80%. Files and docs, not just tables.
Define and enforce governance policies — consistent controls, roles and stewardship — across the estate, so governance is systematic, not per-team reinvention. Consistent policy everywhere. Stewardship at scale.
Assign owners and stewards, route approvals, and run governance workflows — so accountability for data is clear and operational, not just documented. Owners for every dataset. Governance that runs, not sits.
Built-in intelligence for HUNDREDS of global laws — GDPR, CCPA/CPRA, DPDP, PCI-DSS and more — mapping each obligation to your actual data. The deepest regulatory library, mapped to your data.
Automate DPDP obligations — consent, data-principal rights, breach notification to the Data Protection Board, and the data mapping underneath — alongside global regimes. India-ready compliance. (DPDP is NOT blanket localisation — negative-list transfers.)
Run automated assessments against each regulation, track gaps, and generate audit-ready reports — so proving compliance is systematic, not a fire drill. Audit-ready by design. Prove it, don't scramble.
Because it's governance PLUS the deepest regulatory library on the same discovery graph — unified with privacy, DSPM and AI — you catalog, govern and comply in one context, not stitched silos. The consolidation play.
The overview, getting started, and the core workflows.
The appliance, presented by Thales.
The category, explained.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Securiti apart (and where a pure-governance leader leads).
Software key management is genuinely good and often enough. Its limit is architectural rather than a flaw: keys exist in memory on a host, and a sufficiently compromised host can yield them. An HSM removes that possibility by construction — the key is generated inside tamper-resistant hardware, used inside it, and never leaves in usable form. Compromising the application server that calls the HSM gets an attacker the ability to request operations while that access lasts; it does not get them the key. That distinction is what a regulator is reaching for when they ask specifically about hardware key protection.
Data residency debates usually end in a discussion of vendor regions and contractual assurances. Hardware key custody ends them differently: the key is in a physical box, in your data centre, in India, under your administrators. No cloud provider can produce it, no vendor can extract it, and the evidence you show an auditor is a serial number and an access log rather than a clause. For IRDAI-regulated insurers, RBI-regulated entities and government buyers, that is a materially different conversation from any software answer.
CipherTrust Manager can be rooted in a Luna HSM, which means the master keys protecting everything else are generated and held in hardware and never exist in software at all. That matters because a key hierarchy is only as strong as its root — protecting a thousand data keys with a master key sitting in a virtual machine's memory is a weaker arrangement than most architecture diagrams admit. If you are buying the platform and hardware custody is available, rooting it properly is the decision that makes the rest coherent.
Budgets for HSM projects go wrong in a predictable way — the appliance price is captured and everything around it is not. There is a support contract. There is firmware maintenance on a security-critical device. There is backup of the security domain, which is its own discipline and genuinely unforgiving if neglected. There is separation of duties: hardware key custody creates roles nobody previously had, and the person administering the device should not be the person approving key use. And if you want to survive a data-centre failure you need more than one unit, in more than one place. None of this is exotic. All of it is real, and we would rather cost it with you now than have you meet it in month three.
Buy an HSM when the requirement is that keys must never exist in software, and be honest with yourself about whether that requirement is real. It usually arrives from a regulator asking specifically about hardware protection, from a payments or PKI use case with an explicit mandate, or from a risk assessment concluding a compromised host must not yield key material. If none of those applies, virtual CipherTrust Manager under your control satisfies the actual need at a fraction of the cost and operational burden, and we will tell you so. One procurement note worth raising early: Entrust's nShield holds Bureau of Indian Standards certification. If BIS certification is a requirement in your process, that is a deciding fact rather than a preference, and we sell Entrust too.
Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.
Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.
Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.
Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.
Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.”
“Deploying against systems nobody would let us modify was the whole reason this got approved.”
“Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.”
“No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Data-governance & compliance market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Key custody in hardware, with India engineering.
The grid nobody publishes — how deep the core capability is vs how broad the wider platform.
Deepest on key custody; not a document product.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Collibra, Alation, Informatica, OneTrust and Microsoft Purview — honest lanes: Collibra & Alation LEAD pure data-governance/catalog; Securiti’s edge is govern-PLUS-comply on one discovery graph (esp. DPDP + global). Deepest pure governance? Collibra/Alation. Inside Microsoft? Purview. We say so.
| Dimension | Thales | Entrust | Microsoft Purview | Seclore | HashiCorp Vault |
|---|---|---|---|---|---|
| What it actually is | Key management + hardware custody + encryption | The HSM and PKI peer | Document rights management | India-built EDRM | Secrets and encryption-as-a-service |
| Who holds the keys | You — in hardware if you want | You — in hardware | Microsoft, unless you use Double Key Encryption | Either — SaaS or self-hosted | You |
| Protection travels with the file | No — this protects infrastructure, not documents | No | Yes — labels travel with the file | Yes, with post-distribution revocation | No |
| Hardware key custody | Luna HSM | nShield — holds BIS certification | DKE holds one key; not an HSM product | Not an HSM vendor | Can integrate with an HSM |
| India data residency | Deploy on-premises — no India SaaS region | On-premises appliances — no India SaaS | India region via Advanced Data Residency | India-built; SaaS or self-hosted | Self-host anywhere, including India |
| Analyst standing | KuppingerCole Overall Leader 2025 ×2 | No HSM/key-management Leader placement found | Microsoft, evaluated broadly elsewhere | Specialist — no Gartner EDRM MQ exists | Widely recognised in its category |
| Published pricing | Quote-only | Quote-only | $12/user/mo Purview add-on; E5 $60 | Quote (INR) | Free community edition |
| The thing to plan around | HSM operations: firmware, backup, separation of duties | Scope: it exited public TLS in Sep 2025 | DKE breaks co-authoring, search and Copilot | Adoption — manual protection is rarely applied | Operationally heavy to run well |
| Best fit | Key custody with hardware, on your own infrastructure | Where BIS certification is a procurement requirement | Microsoft estates with E5 needing document labels | Documents shared outside, India-built vendor | Engineering-owned secrets and encryption services |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Luna HSM is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (data sources / systems; regulations in scope; hour cost as loaded rate). Estimates contrast manual governance (hand-maintained catalog that drifts, per-law compliance by hand, ungoverned unstructured data) vs Securiti (catalog off the discovery graph, hundreds of laws in one library, access & unstructured governance) — the wins are current governance and audit-ready compliance. Illustrative — TechBag scopes your estate.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes the modules you actually need (Catalog, Lineage, Quality, Access Governance, Unstructured Governance, Compliance), adds INR/GST, and frames it against DPDP accurately — quote current figures for your estate.
Best for governing & complying at scale
Best for a broader rollout
Best value with TechBag
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?
Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?
Are we clear that Thales's India engineering presence is people, not a data region?
Have we scanned rather than relied on an asset inventory to scope this?
Have we measured the overhead on our least-modern business-critical system?
Who administers the HSM, and who approves key use? They must not be the same person.
Do we need a second appliance at another site, and is it budgeted?
Have we backed up the security domain AND tested restoring from it?
Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.
Have we priced hardware, support, resilience and operations — not just the licence?
Scope Securiti Data Governance & Compliance (catalog, lineage and quality; Data Access Governance and Unstructured Data Governance; and regulatory compliance across hundreds of laws — GDPR, CCPA, DPDP, PCI-DSS — all off the DataAI Command Graph, now Veeam-backed) — and let a TechBag advisor scope the modules, compare vs Collibra/Alation/Purview honestly, frame it against DPDP accurately, and add INR/GST and local support.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.