01
Public sector and regulated enterprises
Sensitive or confidential data in Microsoft 365 and hyperscale cloud where provider-accessible keys are insufficient.

Place cryptographic control where the organisation has committed it to sit—while still using major cloud and SaaS platforms.
Who it is for
01
Sensitive or confidential data in Microsoft 365 and hyperscale cloud where provider-accessible keys are insufficient.
02
Need one custody model across AWS, Microsoft 365 and secrets platforms—not a different story per vendor.
03
Need evidence of who can unlock data under GDPR, FADP, DORA and related frameworks.
External keys
Cryptographic operations for protected workloads run outside the cloud operator trust boundary
Same platforms
Keep AWS, Microsoft 365 and OpenBAO usable while custody moves
Audit path
Named authority over key use for supervisors and internal audit

Hosting in a preferred region or data boundary helps with residency. It does not by itself remove provider access to keys. Sovereignty programmes fail the practical test when the operator can still decrypt.
DuoKey focuses on customer-controlled keys for the platforms you already run: Microsoft 365 (DKE and Customer Key), AWS External Key Store, and OpenBAO with DuoKey SD-HSM.
How it works
Apply custody where the data lives. Do not rip out the productivity or cloud platforms the business depends on.

DKE for high-sensitivity content; Customer Key for stronger service encryption under your authority.
Keep KMS APIs in applications while cryptographic operations run in an external key store.

Vault-compatible secrets management with MPC auto-unseal under your authority.
Outcomes for sovereignty programmes—not generic cloud security.
Demonstrate that a provider channel does not automatically yield plaintext.
One model across SaaS and IaaS instead of fragmented BYOK exceptions.
Keep using major clouds while keys stay outside their sole control.
Next step
Bring the constraint. We’ll map the shortest practical path.
Review DKE vs Customer Key, XKS vs native KMS, or schedule a scoped architecture discussion.
Vertrauen
Kundenprogramme