DuoKey

KMS client

An independent KMS your cloud does not own

Applications get keys through a familiar interface, while authority stays outside the operator that stores the data.

The Cockpit

Every key, tagged by algorithm and status

Active, disabled, or compromised, every key across every vault, with its algorithm called out, not buried in metadata.

Cockpit, Keys
DuoKey Cockpit keys list showing active, disabled and compromised keys with their cryptographic algorithms

The problem

Key volume outruns the systems meant to govern it

More encrypted data means more keys, environments and regulatory overlays.

As estates scale, KMS fleets fragment across clouds, regions and applications. The result is operational overhead, inconsistent policy and no single answer to who can unwrap what.

  • A KMS per system

    Each new app stands up another island of keys.

  • Dev / test / prod drift

    Policy is rewritten in each environment.

  • Conflicting regimes

    Each jurisdiction wants a different custody story.

  • Rotation backlog

    Reviews cannot keep up with key volume.

Security leadership

What the board is asking

KMS client

Four questions surface in every security review.

Talk to our security architects

What changes

Customer-held key service for applications

Client-side encryption is the act of encrypting data before sending it to Amazon S3.

  • Always client-side encryption is performed

  • No third-party can ever access your data

  • Dedicated tenant and vault for storing your keys

  • Monitor who uses your keys

In detail

What changes for platform and security teams

Centralize Key Management

DuoKey EKM offers a centralized platform to efficiently manage and control encryption keys for your SQL databases. Easily create, store and rotate keys while maintaining complete visibility and control over the key lifecycle.

Products

Check out the other DuoKey products

AWS S3 Encryption

Objects stay in S3 for scale. Decryption still requires a key share you hold outside AWS.

View product

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.