01
ICT risk and outsourcing owners
Need to show that cloud or SaaS access does not equal plaintext access to critical data.

Meet DORA's expectations for encryption and key management with keys your organisation controls—not only encryption toggles in the cloud.
Who it is for
01
Need to show that cloud or SaaS access does not equal plaintext access to critical data.
02
Need one custody model across Microsoft 365, AWS, secrets platforms and databases.
03
Need evidence of who can unlock data, under which policy, for supervisors and internal audit.
Articles 9–13
DORA ICT security focus areas where encryption and key management support confidentiality and integrity
Customer-controlled keys
Custody outside the cloud operator so encryption measures are yours to govern and evidence
One programme
Same custody idea across M365, AWS XKS, OpenBAO/Vault, SQL and ServiceNow

The Digital Operational Resilience Act (DORA - EU Regulation 2022/2554) and its delegated act raise expectations for ICT security. Encryption matters; who controls the keys determines whether that control is real or delegated to the cloud operator.
Financial entities must protect confidentiality and integrity of data and systems, manage third-party ICT risk, and produce evidence for testing and incidents. Customer-controlled keys close the gap when data sits in vendor environments.
How it works
DuoKey connects to each platform’s supported external-key or customer-key path. You keep the applications; you move decryption authority.

Double Key Encryption and Customer Key so Microsoft cannot unlock regulated collaboration content alone.
Keep KMS APIs in applications while cryptographic operations run in an external key store outside Amazon.

Vault-compatible secrets management with MPC auto-unseal instead of a single physical unseal HSM dependency.

External key management for SQL Server EKM and ServiceNow CLE / Edge Encryption for operational and structured data.
Outcomes tied to ICT risk, outsourcing and evidence—not generic security slogans.
Show that a provider compromise or lawful access channel at the operator does not automatically mean plaintext access to your data.
Concrete integrations for M365, AWS, OpenBAO, SQL and ServiceNow instead of a single abstract KMS slide.
Key use, approval and custody that you govern and can produce in ICT risk and outsourcing reviews.
Next step
Bring the constraint. We’ll map the shortest practical path.
Review the DORA compliance page and product integrations for your estate, or schedule a scoped architecture discussion.
Vertrauen
Kundenprogramme