Summary
- CipherTrust Data Security Posture Management combines sensitive data discovery with direct protection controls.
- Thales is targeting the broader data access created by AI applications and autonomous agents.
- The product reflects a shift from identifying exposed information towards enforcing controls around the data itself.
Thales is bringing data discovery and data protection into the same platform as enterprises give AI applications and autonomous agents access to a wider range of corporate information.
French technology group Thales has launched CipherTrust Data Security Posture Management, which maps sensitive information and combines that view with access rights, entitlements, activity, and user behaviour to identify exposures requiring attention.
Customers can then apply encryption, masking, or tokenisation through the same environment across cloud, on-premise, and hybrid systems. The approach moves posture management beyond producing another inventory of risky data and towards applying controls directly after a problem has been identified.
AI has made that distinction more pressing because companies are connecting assistants and agents to systems accumulated over years of cloud adoption. Databases, file stores, SaaS applications, analytics platforms, and internal business software can become accessible through one conversational or automated layer even when the underlying information remains distributed across many systems.
Discovery has become the beginning of the job
Data Security Posture Management emerged partly from the difficulty of locating sensitive information across large cloud estates. Security teams cannot protect a dataset reliably if they do not know where it resides, who can reach it, or whether copies have moved into systems with weaker controls.
Discovery tools can nevertheless create their own backlog. Finding a database containing customer records does not determine whether access should be restricted, whether selected fields need to be hidden, or whether the information should remain readable only to particular workloads.
CipherTrust DSPM is designed to connect those decisions with protection mechanisms already present in Thales’s data security portfolio. Encryption leaves information unusable without the appropriate keys; masking obscures selected values where a user or application does not need the originals; tokenisation replaces sensitive data with substitutes that carry no useful meaning outside authorised systems.
Each technique brings implementation choices. Encryption depends on reliable key management, masking can affect applications expecting original values, and tokenisation can create integration work where multiple systems need to reconcile records. Bringing the controls into one platform can shorten the path between identifying an exposure and addressing it, but it does not remove those design decisions.
Agents create more routes into the same information
Traditional access controls were largely designed around recognisable users and applications. An AI workflow can combine a human instruction, an autonomous agent, several software tools, and information retrieved dynamically from multiple repositories, making the eventual output harder to map against the access model of any single system.
An agent does not need to bypass security to expose information if it has been granted more access than the employee using it should ultimately receive. It can also combine several pieces of individually permissible data into a response that reveals something more sensitive.
Persistent classification and controls around the data become more useful in that environment because policy can continue to apply when information is reached through a new interface. The principle is established security practice rather than an invention created by generative AI, but automated systems increase the volume and speed at which corporate information can be traversed.
The commercial DSPM market now overlaps with data governance, cloud security, identity, and AI security as vendors compete to become the layer that tells organisations which information can safely be exposed to models and agents. Thales argues that its advantage lies in combining discovery with existing CipherTrust controls rather than leaving remediation to separate products.
Its claim that CipherTrust DSPM is the first purpose-built platform to join those functions should be treated as vendor positioning rather than an independently established market boundary. Customers are more likely to judge the product on whether integration reduces the time and organisational effort required to protect a dataset after risk has been identified.
That organisational effort can remain considerable. Security teams, application owners, infrastructure groups, legal departments, and data governance functions may all have a role in deciding what happens to sensitive information, leaving a technically unified product to operate inside a business process that is still divided between teams.
As AI expands the number of systems capable of retrieving information autonomously, those delays become more exposed. Enterprises will still need to decide who and what can access data, but the number of access decisions is moving beyond what can reasonably be reviewed one request at a time. Thales is betting that protection applied to the data itself will become a larger part of that control model.










