Data at Rest Encryption and Key Management

Centralize and simplify data security policies and key management anywhere

CipherTrust Manager

CipherTrust Manager offers the industry leading enterprise key management solution enabling organizations to centrally manage encryption keys, provide granular access control and configure security policies. It manages key lifecycle tasks including generation, rotation, destruction, import and export, provides role-based access control to keys and policies, supports robust auditing and reporting, and offers developer friendly REST API.


CipherTrust Manager is available in both virtual and physical appliances that are FIPS 140-2 compliant for securely storing keys with the highest root of trust. These appliances can be deployed on-premises in physical or virtualized infrastructures and in public cloud environments to efficiently address compliance requirements, regulatory mandates and industry best practices for data security. With a unified management console, it makes it easy to set policies, discover and classify data, and protect sensitive data wherever it resides using an integrated set of Thales data protection connectors.



Encrypt Everything, Everywhere

Thales data encryption products reduce enterprise time and cost to implement best practices for data security and compliance on-premises and across clouds. Learn how to control sensitive data and address your unique security and compliance requirements in data center, cloud, big data, and containers as well as other virtual environments.


  • Centralized Key Lifecycle Management
    • Simplifies management of encryption keys across their entire lifecycle, including secure key generation, backup/restore, clustering, deactivation and deletion. It unifies key management operations with role-based access control using existing Active Directory and LDAP credentials, and provides full audit log review.
  • Unified Management Console
    • Provides a single pane of glass for discovering and classifying sensitive data and an integrated set of Thales Data Protection Connectors to encrypt or tokenize data to reduce business risk and satisfy compliance regulations. It streamlines provisioning of connector licenses through a new self-service licensing for better visibility and control of licenses.
  • Developer Friendly REST APIs
    • Offers new REST interfaces in addition to KMIP and NAE-XML APIs, for developers to simplify deployment of applications integrated with key management capabilities and automate testing and development of administrative operations.


  • Simplified Management
    • CipherTrust Manager provides a unified management console that enables you to discover and classify sensitive data, and protect data using integrated set of Thales Data Protection connectors across on-premises data stores and multi-cloud deployments. It offers advanced self-service licensing for improved visibility and control of licenses.
  • Cloud Friendly Deployment
    • It offers users with additional hosting options, and can run as a native virtual machine on AWS, Microsoft Azure, Google Cloud, VMware, Microsoft HyperV, and more. Additionally, native support of CipherTrust Cloud Key Manager on CipherTrust Manager streamlines key management across multiple cloud infrastructures and SaaS applications.
  • Flexible Form Factors
    • It is available in both virtual and physical form factors and FIPS 140-2 levels. Flexible deployment options can easily scale to provide key management at remote facilities or in cloud infrastructures.