DuoKey
Compliance

ISO 27001

International standard for information security management systems. DuoKey is ISO/IEC 27001 certified.

Requirements

What the regulation expects

ISO/IEC 27001 is the international standard for information security management systems. DuoKey is certified. That covers the ISMS for how DuoKey runs security, not a substitute for the customer's own Annex A control mapping. In RFPs, state certification status, offer the certificate, and map product cryptographic and access controls to the buyer's Statement of Applicability where asked.
What the regulation expects

Almost every enterprise RFP asks for it

Universal compliance requirement. Lead with certified status and the scope of the ISMS.

Cryptographic controls in Annex A

Policies, key lifecycle, access control and logging that support A.8 / cryptography-related controls in ISO 27001:2022.

Incident and continuity

Incident management and business continuity procedures under the certified ISMS.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Enforced key policy, lifecycle, access reviews and exportable audit evidence for customer SoA mapping.

Learn more

Cloud BYOK / XKS / DKE

Customer-held keys so cloud processing stays within the customer's cryptographic boundary.

Learn more

Key themes

Where independent key control fits

Status: certified. Certificate available on request. Product pages below show how DuoKey helps customers map their own ISO control objectives for cryptography and access.

Information security policies

Customer key and access policy enforced as configuration, not only as a document.

Relevant products

Access control management

Leaf-level permissions, MFA for privileged access, JIT elevation and periodic access review output.

Relevant products

Cryptographic controls

Approved algorithms and key types, lifecycle states, custody backends and inventory for auditor evidence.

Relevant products

Incident management and continuity

Key disablement, rotation and recovery procedures that feed the customer's incident and continuity playbooks.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.