01
Cloud and data owners
Need AWS, Microsoft 365 and databases in production without giving the operator the last key.

Protect customer and operational data in cloud and SaaS with encryption keys the institution controls.
Who it is for
01
Need AWS, Microsoft 365 and databases in production without giving the operator the last key.
02
Need a product path that maps to DORA ICT risk and outsourcing reviews.
03
Need external key management that integrates with existing stacks—not a rip-and-replace.
AWS XKS
External Key Store keeps cryptographic operations outside Amazon for protected keys
M365 DKE / Customer Key
Collaboration data with independent or customer-operated key authority
SQL EKM
Database encryption keys outside the database host

Financial institutions need cloud storage and SaaS. Default encryption often leaves keys with the operator. DuoKey connects to supported external-key and customer-key paths so regulated datasets stay usable while decryption authority stays with the institution.
How it works
Start from where data already lives. Apply customer-controlled keys on those platforms.
External key store for KMS-backed workloads; S3 encryption options with customer-controlled keys where required.

DKE and Customer Key for regulated collaboration content.

External key management for structured and operational data in databases and ITSM.
Outcomes tied to financial cloud programmes.
Support DORA, NIS2, GDPR and PCI narratives with keys you govern.
Limit scenarios where a cloud account or vendor channel yields bulk decryption.
Keep familiar AWS, M365 and database workflows while custody changes.
Next step
Bring the constraint. We’ll map the shortest practical path.
Map AWS, M365 and database workloads to customer-controlled keys, or schedule a scoped review.
Vertrauen
Kundenprogramme