by ThalesTechBag Intel Page

Luna HSM

A key in a physical box in your data centre — Luna HSM generates and stores keys inside tamper-resistant hardware, and key material never leaves in usable form. No cloud provider, no vendor and no administrator can extract it.regulatory library (GDPR, CCPA, DPDP, PCI-DSS) — all off the DataAI Command Graph. Now part of Veeam.

Keys never leave the deviceThe strongest residency answerBudget the operations

Data residency & processing — two different questions

Where data lives

Yours — deploy on-premises in India

CipherTrust Manager deploys as a virtual appliance or physical hardware in your own data centre, and Luna HSM is a box you own. Keys, ciphertext and policy stay on infrastructure you control — the strongest available answer to an Indian residency question, where the evidence is a serial number and an access log rather than a contract clause.

The constraint, stated plainly

No India SaaS region — and Noida is people, not data

CipherTrust as-a-Service runs in Europe and North America only. Thales has 2,200+ staff in India with Noida as its Cyber & Digital engineering centre, and that is a genuine commitment — but people in India and data in India are different facts. Treating an engineering presence as a residency answer is the error that surfaces during an audit.

For a residency-bound Indian buyer this pushes you to on-premises deployment, which is very likely what your regulator wanted anyway. Under the DPDP Act the sequence matters more than the product: find the personal data first, then protect it. For RBI-regulated entities the question behind the question is usually who can decrypt, and whether administrators can read production data — both answerable here with evidence rather than assurance. And note what does not exist, so its absence is not misread: Gartner publishes no Magic Quadrant for HSM or key management at all, only Market Guides, which have no Leader quadrant. No vendor in this category has a Gartner Leader placement, and any implying one is misleading you.

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Key custody
hardware, in your own building
Strongest available
India residency
the appliance is physically yours
Yours entirely
Operational cost
firmware, backup, separation of duties, resilience
Real
Peer
which holds BIS certification — check your procurement
Entrust nShield

Quick answer

Luna HSM is a hardware security module: a tamper-resistant physical appliance that generates and stores cryptographic keys and performs operations inside the device, so key material never leaves in usable form. That last clause is the entire product. Software key management can be excellent, and for many buyers it is sufficient — but its keys exist in memory on a host, and a sufficiently compromised host can yield them. An HSM makes that structurally impossible: the key is generated inside the device, used inside the device, and cannot be extracted, so compromising the server that calls it does not give an attacker the key. For Indian BFSI, government and defence-adjacent buyers this is frequently not a preference but a requirement, arriving from a regulator asking specifically about hardware key protection, from a payments or PKI use case with an explicit HSM mandate, or from an internal risk assessment. It is also what lets you place the key physically in your own building, which is the strongest possible answer to an Indian residency question — no cloud provider, no vendor and no administrator can extract it. Luna also underpins the rest of the platform, since CipherTrust Manager can be rooted in it so master keys never exist in software. The honest cost is that this is an appliance, not software: a purchase price, a support contract, firmware maintenance, backup of the security domain, separation of duties between the people who administer the device and those who approve key use, and a second unit elsewhere if you want to survive a site failure. All manageable, none free, and consistently absent from a first budget. Read more ↓ Show less ↑
Part 01 · Orient

The Postman platform family

This page covers Luna HSM — catalog, govern, comply. The rest of the Securiti platform:

Quick facts

30-second orientation
Product
Luna HSM — hardware key custody
What it is
A tamper-resistant physical appliance
The guarantee
Key material never leaves the device in usable form
Also
CipherTrust Manager can be rooted in it
Vendor
Thales — Chairman & CEO Patrice Caine
The cyber arm
Thales Cloud Protection & Licensing
Analyst standing
KuppingerCole Overall Leader 2025 — Data Security Platforms
Gartner
No MQ exists for HSM or key management — Market Guides only
India engineering
2,200+ staff; Noida is the Cyber & Digital centre
Data residency
Yours — deploy on-premises or virtual in India
Data processing
On your infrastructure; CipherTrust SaaS is EU/NA only
Pricing
Quote-only — no published list price
Buy in India via
TechBag — INR, GST, key-custody scoping
Part 02 · Learn

Understand data governance before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

A tamper-resistant hardware appliance that generates and stores cryptographic keys and performs operations inside the device. Key material never leaves in usable form.

Drifting manual governance vs governed, compliant data (Securiti) — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailLuna HSM
The catalogHand-maintained, driftingBuilt off the discovery graph, current
LineageManual / unknownAutomated data lineage
AccessOver-permissive, unclearData Access Governance
Unstructured dataUngoverned files & docsUnstructured Data Governance
ComplianceManual, per-law, siloedHundreds of laws, one library
India DPDPAd hoc, over-localisedAutomated (negative-list transfers)
Vendor backing(startup risk)Now part of Veeam
Best fit(varies)Catalog, govern & comply on one graph

Securiti Data Governance & Compliance catalogs, governs and complies with your data — catalog, lineage, quality; access & unstructured governance; and a deep regulatory library (hundreds of laws, DPDP + global) — all off one discovery graph. Now part of Veeam. Honest: Collibra & Alation LEAD pure data governance — Securiti’s edge is govern-plus-comply on one graph. TechBag scopes modules, adds GST & the accurate India DPDP framing.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The foundation

Discover on One Graph

The DataAI Command Graph

Governance rides on the SAME discovery graph that finds and classifies your sensitive data — so the catalog, lineage and access controls draw on real, live data context, not a hand-maintained inventory that drifts. Govern what you actually have. One graph underneath it all.

02
The catalog

Catalog & Understand

Catalog, lineage, quality

Build a Data Catalog with automated Lineage (where data comes from and flows to) and Data Quality — so people can find, trust and understand data across the estate. Know your data, and trust it. A catalog that stays current.

03
The govern

Govern Access & Files

Data Access + Unstructured Governance

Enforce Data Access Governance (who can access what, entitled to the right controls) and Unstructured Data Governance (files, docs and shadow data, not just structured databases). Right data, right people, everywhere. Govern structured AND unstructured.

04
The comply

Comply Across Laws

Regulatory intelligence library

Automate compliance across HUNDREDS of global laws — GDPR, CCPA/CPRA, India's DPDP Act, PCI-DSS and more — with built-in regulatory intelligence that maps each obligation to your actual data. Compliance, mapped to your data. Every law, one library.

05
The edge

Unify With Privacy, DSPM & AI

One platform, one context

Because governance and compliance run off the same graph as Securiti's privacy, DSPM and AI governance, you govern data, comply with law and secure it — all in one context, not stitched silos. Govern, comply and secure as one. The consolidation play.

One map of where sensitive data lives and who touches it — risk governed at the source, not at the perimeter.

Part 03 · Evaluate

Twelve capabilities. Catalog, govern, comply.

Securiti lets you catalog, govern and comply with your data — on one discovery graph, across hundreds of laws — the governance & compliance suite of portfolio, and paired with the human firewall.

Catalog
Data catalog

Data Catalog

A living catalog of your data assets across clouds, SaaS, on-prem and files — built off the discovery graph, so people can find and trust data. A catalog that stays current, not a stale spreadsheet.

Catalog
Lineage

Automated Data Lineage

See where data comes from and where it flows — automated lineage across systems — so you can trace impact, prove provenance and answer 'where did this data go?'. Trace every flow. Provenance you can prove.

Catalog
Data quality

Data Quality

Profile and monitor data quality — completeness, validity, freshness — so the data people govern and report on is data they can trust. Govern good data, not garbage. Quality you can measure.

Catalog
Discovery graph

Governance on the Discovery Graph

The catalog, lineage and access controls all ride on the SAME graph that discovers and classifies sensitive data — so governance reflects real, live data context, not a drifting manual inventory. Govern what you actually have.

Govern
Access governance

Data Access Governance

Govern who can access what — entitlements, over-permissive access, and the controls each dataset needs — so the right people get the right data and nobody gets more than they should. Right data, right people. Least privilege, at scale.

Govern
Unstructured

Unstructured Data Governance

Govern files, documents and shadow data — not just structured databases — where so much sensitive data actually lives. Govern the messy 80%. Files and docs, not just tables.

Govern
Policies

Governance Policies & Controls

Define and enforce governance policies — consistent controls, roles and stewardship — across the estate, so governance is systematic, not per-team reinvention. Consistent policy everywhere. Stewardship at scale.

Govern
Roles & stewardship

Roles, Stewardship & Workflows

Assign owners and stewards, route approvals, and run governance workflows — so accountability for data is clear and operational, not just documented. Owners for every dataset. Governance that runs, not sits.

Comply
Regulatory library

Multi-Jurisdiction Regulatory Intelligence

Built-in intelligence for HUNDREDS of global laws — GDPR, CCPA/CPRA, DPDP, PCI-DSS and more — mapping each obligation to your actual data. The deepest regulatory library, mapped to your data.

Comply
DPDP

India DPDP Act Compliance

Automate DPDP obligations — consent, data-principal rights, breach notification to the Data Protection Board, and the data mapping underneath — alongside global regimes. India-ready compliance. (DPDP is NOT blanket localisation — negative-list transfers.)

Comply
Assessments

Compliance Assessments & Reporting

Run automated assessments against each regulation, track gaps, and generate audit-ready reports — so proving compliance is systematic, not a fire drill. Audit-ready by design. Prove it, don't scramble.

Comply
Govern + comply, unified

Govern & Comply on One Graph

Because it's governance PLUS the deepest regulatory library on the same discovery graph — unified with privacy, DSPM and AI — you catalog, govern and comply in one context, not stitched silos. The consolidation play.

See it, don’t just read it

Watch Securiti in action

The overview, getting started, and the core workflows.

Thales (official)·Hardware

Introducing Thales Luna HSM 8 — Quantum-Safe

The appliance, presented by Thales.

Thales (official)·Concept

What is a Hardware Security Module (HSM)?

The category, explained.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Luna HSM

Perimeters leak. Govern the data itself.

Here’s what genuinely sets Securiti apart (and where a pure-governance leader leads).

01

Keys that cannot be extracted, structurally

Software key management is genuinely good and often enough. Its limit is architectural rather than a flaw: keys exist in memory on a host, and a sufficiently compromised host can yield them. An HSM removes that possibility by construction — the key is generated inside tamper-resistant hardware, used inside it, and never leaves in usable form. Compromising the application server that calls the HSM gets an attacker the ability to request operations while that access lasts; it does not get them the key. That distinction is what a regulator is reaching for when they ask specifically about hardware key protection.

02

The strongest possible answer to an Indian residency question

Data residency debates usually end in a discussion of vendor regions and contractual assurances. Hardware key custody ends them differently: the key is in a physical box, in your data centre, in India, under your administrators. No cloud provider can produce it, no vendor can extract it, and the evidence you show an auditor is a serial number and an access log rather than a clause. For IRDAI-regulated insurers, RBI-regulated entities and government buyers, that is a materially different conversation from any software answer.

03

It is the root the rest of the platform stands on

CipherTrust Manager can be rooted in a Luna HSM, which means the master keys protecting everything else are generated and held in hardware and never exist in software at all. That matters because a key hierarchy is only as strong as its root — protecting a thousand data keys with a master key sitting in a virtual machine's memory is a weaker arrangement than most architecture diagrams admit. If you are buying the platform and hardware custody is available, rooting it properly is the decision that makes the rest coherent.

04

The honest cost: this is an appliance, not software

Budgets for HSM projects go wrong in a predictable way — the appliance price is captured and everything around it is not. There is a support contract. There is firmware maintenance on a security-critical device. There is backup of the security domain, which is its own discipline and genuinely unforgiving if neglected. There is separation of duties: hardware key custody creates roles nobody previously had, and the person administering the device should not be the person approving key use. And if you want to survive a data-centre failure you need more than one unit, in more than one place. None of this is exotic. All of it is real, and we would rather cost it with you now than have you meet it in month three.

05

The honest positioning

Buy an HSM when the requirement is that keys must never exist in software, and be honest with yourself about whether that requirement is real. It usually arrives from a regulator asking specifically about hardware protection, from a payments or PKI use case with an explicit mandate, or from a risk assessment concluding a compromised host must not yield key material. If none of those applies, virtual CipherTrust Manager under your control satisfies the actual need at a fraction of the cost and operational burden, and we will tell you so. One procurement note worth raising early: Entrust's nShield holds Bureau of Indian Standards certification. If BIS certification is a requirement in your process, that is a deciding fact rather than a preference, and we sell Entrust too.

Catalog on the graph
Reflects live data context
Regulatory library
Hundreds of laws (DPDP + global)
Local via TechBag
Scoping, GST, DPDP framing
Proof, not promises

The numbers behind the platform

2200+ staff
Thales in India, across two engineering centres
Thales India
~450 more
India hires planned during 2026
Thales India
2 KC Leader awards
KuppingerCole Overall Leader, 2025
KuppingerCole
0 India SaaS regions
CipherTrust as-a-Service is EU/NA only
Thales docs
0 Gartner MQs
None exists for HSM or key management
Gartner
2000
Thales Group formed in its current form
Company

What your Securiti governance journey looks like

Week 1Assess

Settle key custody and deployment

Software key management under your control, or keys that exist only in hardware? And on-premises or cloud — remembering CipherTrust as-a-Service has no India region. These two answers determine the architecture and most of the cost, so establish them before any demo.

Weeks 2–5Assess

Run discovery before scoping encryption

Scope an encryption project against a scan rather than an asset inventory. Inventories record what was provisioned deliberately; sensitive data accumulates by accident, in the reporting replica and the forgotten file share. Those are the stores that produce breaches, and they are never in the CMDB.

Weeks 4–10Deploy

Pilot on your least-modern system

Test transparent encryption and measure performance overhead against your oldest business-critical system, not a clean host. That is the system the rollout has to survive, and an unacceptable overhead is far cheaper to discover now.

Weeks 8–14Deploy

Name the HSM administrators and the approvers

Hardware key custody creates roles nobody previously had, and they must be different people. Assign them during the project rather than retrofitting separation of duties afterwards, which is considerably harder and tends to get waived under delivery pressure.

OngoingOperate

Rotate on policy, and test the restore

Key rotation is easy to mandate and easy to skip. Equally, back up the security domain and then actually test recovering from it — an untested HSM backup is a assumption, and it is the assumption that ends organisations rather than merely inconveniencing them.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
380+ reviews*
89% would recommend
Catalog, lineage & quality4.3
Access & unstructured governance4.4
Regulatory compliance library4.6
Vs pure-governance leaders4.0
5
56%
4
31%
3
8%
2
3%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
The auditor stopped asking whether the data was encrypted and started asking who held the key. This is what answered that.
Head of Information Security
Banking
Manufacturing
Deploying against systems nobody would let us modify was the whole reason this got approved.
Infrastructure Lead
Manufacturing
Insurance
Budget the operational side properly. The appliance is the easy part; the separation of duties took longer than the install.
Security Architect
Insurance
Non-Banking Financial Company
No India SaaS region, so we went on-premises. Honestly that is what our regulator wanted anyway.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Data-governance & compliance market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Data-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
ThalesThis page

Key custody in hardware, with India engineering.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how deep the core capability is vs how broad the wider platform.

Point scannersBest-of-breed DSPMLegacy DLP suitesHeavy governance platforms
ThalesThis page

Deepest on key custody; not a document product.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Securiti vs the data-governance field

Collibra, Alation, Informatica, OneTrust and Microsoft Purview — honest lanes: Collibra & Alation LEAD pure data-governance/catalog; Securiti’s edge is govern-PLUS-comply on one discovery graph (esp. DPDP + global). Deepest pure governance? Collibra/Alation. Inside Microsoft? Purview. We say so.

DimensionThalesEntrustMicrosoft PurviewSecloreHashiCorp Vault
What it actually isKey management + hardware custody + encryptionThe HSM and PKI peerDocument rights managementIndia-built EDRMSecrets and encryption-as-a-service
Who holds the keysYou — in hardware if you wantYou — in hardwareMicrosoft, unless you use Double Key EncryptionEither — SaaS or self-hostedYou
Protection travels with the fileNo — this protects infrastructure, not documentsNoYes — labels travel with the fileYes, with post-distribution revocationNo
Hardware key custodyLuna HSMnShield — holds BIS certificationDKE holds one key; not an HSM productNot an HSM vendorCan integrate with an HSM
India data residencyDeploy on-premises — no India SaaS regionOn-premises appliances — no India SaaSIndia region via Advanced Data ResidencyIndia-built; SaaS or self-hostedSelf-host anywhere, including India
Analyst standingKuppingerCole Overall Leader 2025 ×2No HSM/key-management Leader placement foundMicrosoft, evaluated broadly elsewhereSpecialist — no Gartner EDRM MQ existsWidely recognised in its category
Published pricingQuote-onlyQuote-only$12/user/mo Purview add-on; E5 $60Quote (INR)Free community edition
The thing to plan aroundHSM operations: firmware, backup, separation of dutiesScope: it exited public TLS in Sep 2025DKE breaks co-authoring, search and CopilotAdoption — manual protection is rarely appliedOperationally heavy to run well
Best fitKey custody with hardware, on your own infrastructureWhere BIS certification is a procurement requirementMicrosoft estates with E5 needing document labelsDocuments shared outside, India-built vendorEngineering-owned secrets and encryption services
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which data security & privacy approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Securiti if…

  • You want governance PLUS the deepest multi-jurisdiction compliance library on ONE discovery graph
  • You want the catalog, lineage and access to reflect live sensitive-data context (structured AND unstructured)
  • India's DPDP Act is a driver — and you want it framed accurately (compliance automation, not blanket localisation)
  • You value consolidation (govern + comply + privacy + DSPM + AI on one graph) and Veeam backing — via TechBag

Collibra if…

  • Your single priority is the deepest pure data-GOVERNANCE and stewardship program (governance heritage)

Alation if…

  • Your single priority is the deepest data CATALOG / data intelligence (catalog heritage)

Informatica if…

  • You want broad data management and data-quality depth alongside governance/catalog

OneTrust / Microsoft Purview if…

  • Your priority is privacy-led governance (OneTrust) or governance inside the Microsoft/Azure estate (Purview) — see the Securiti privacy pages

Luna HSM is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What could this save you?

Drag the sliders (data sources / systems; regulations in scope; hour cost as loaded rate). Estimates contrast manual governance (hand-maintained catalog that drifts, per-law compliance by hand, ungoverned unstructured data) vs Securiti (catalog off the discovery graph, hundreds of laws in one library, access & unstructured governance) — the wins are current governance and audit-ready compliance. Illustrative — TechBag scopes your estate.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Securiti is priced by QUOTE (annual, modular — scales with data volume, estate size and modules; enterprise license agreements), in USD; no public list. Now a Veeam company. TechBag scopes the modules you actually need (Catalog, Lineage, Quality, Access Governance, Unstructured Governance, Compliance), adds INR/GST, and frames it against DPDP accurately — quote current figures for your estate.

Securiti (modular, by quote)

Best for governing & complying at scale

  • Data Catalog + Lineage + Quality + Access & Unstructured Governance
  • Deep regulatory library — hundreds of laws (GDPR, CCPA, DPDP, PCI-DSS)
  • Now part of Veeam; all on the DataAI Command Graph

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ scoping & DPDP framing

Best value with TechBag

  • Module scoping + honest Collibra/Alation/Purview comparison
  • Securiti prices by quote in USD; broad platform — scope what you need
  • TechBag adds INR/GST, local support & the accurate India DPDP framing

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Key custody

Do keys need to exist only in tamper-resistant hardware, or is software key management under our control enough?

2
Deployment

Have we accepted that CipherTrust as-a-Service is EU/NA only, and planned on-premises if residency binds us?

3
Residency

Are we clear that Thales's India engineering presence is people, not a data region?

4
Discovery

Have we scanned rather than relied on an asset inventory to scope this?

5
Performance

Have we measured the overhead on our least-modern business-critical system?

6
Separation of duties

Who administers the HSM, and who approves key use? They must not be the same person.

7
Resilience

Do we need a second appliance at another site, and is it budgeted?

8
Backup

Have we backed up the security domain AND tested restoring from it?

9
Scope

Is our actual problem key custody, or is it documents leaving the organisation? Those are different products.

10
Commercials

Have we priced hardware, support, resilience and operations — not just the licence?

FAQ

Questions buyers ask

Through deployment rather than through a vendor region, and the distinction is the first thing to settle. CipherTrust as-a-Service runs in Europe and North America only — there is no India region, and we are not going to imply otherwise. For a residency-bound Indian buyer the answer is on-premises or virtual deployment in your own data centre, with keys under your control and, if the requirement demands it, inside a Luna HSM physically in your building. That is a stronger custody position than any vendor-hosted region could provide, and it is very likely what a regulator was pushing you toward in the first place. Be precise about a fact this market blurs constantly. Thales has more than 2,200 staff in India across two engineering competence centres, with Noida specifically the Cyber and Digital centre, and is hiring around 450 more during 2026. That is a genuine and unusual commitment — and it is people, not a data region. Treating an engineering presence as a residency answer is exactly the error that surfaces during an audit, and it is worth stating plainly because vendors on all sides encourage the confusion. What the India presence does buy you is real: Thales publishes its own compliance material mapped to SEBI's CSCRF and RBI's outsourcing directions for NBFCs, which means the vendor has already done the work of understanding what an Indian regulator expects rather than translating a US framework. On DPDP specifically, the sequence matters more than the product: find the personal data first, then protect it. Discovery before encryption, every time.

Ready to govern and comply on one graph?

Scope Securiti Data Governance & Compliance (catalog, lineage and quality; Data Access Governance and Unstructured Data Governance; and regulatory compliance across hundreds of laws — GDPR, CCPA, DPDP, PCI-DSS — all off the DataAI Command Graph, now Veeam-backed) — and let a TechBag advisor scope the modules, compare vs Collibra/Alation/Purview honestly, frame it against DPDP accurately, and add INR/GST and local support.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.