DuoKey
Compliance

PCI DSS

Payment Card Industry Data Security Standard. Key custody, split knowledge and encryption for account data environments.

Requirements

What the regulation expects

PCI DSS (including v4.0.1) requires strong cryptography for stored account data and data in transit. Requirement 3.7 covers cryptographic key management: protect keys against disclosure and misuse, document custodians, and use split knowledge or dual control for key-encrypting keys where required. DuoKey supports that with enforced lifecycle, inventory, dual-control style approvals and MPC or HSM custody. DuoKey is not a substitute for the merchant or service provider's full PCI assessment.
What the regulation expects

Requirements 3 and 4 still decide KMS deals

Stored account data and data in transit. Key management under 3.7 is where auditors dig in.

Split knowledge and dual control

MPC key shares and dual-control workflows support the spirit of split knowledge without spreadsheet ceremonies.

Evidence for QSAs

Key inventory, custodian records, rotation history and audit logs QSAs actually ask for.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Custodian-visible ownership, lifecycle states, dual-control style approvals and exportable inventory.

Learn more

MPC custody

Distribute key shares so no single operator or node holds a usable key alone.

Learn more

Database and payment data encryption

External keys for stores that hold PAN or sensitive authentication data under the customer's CDE design.

Learn more

Key themes

Where independent key control fits

Map to the customer's PCI DSS version and ROC scope. Product evidence below covers cryptography and key management, not the full standard.

Encryption of stored account data

Strong encryption with keys outside the application trust boundary where the CDE design requires it.

Encryption in transit

TLS on service-to-service paths that carry or unwrap account data keys.

Relevant products

Key management (Req. 3.7)

Documented custodians, generation, distribution, storage, rotation, retirement and destruction with audit history.

Relevant products

Split knowledge / dual control

MPC shares and approval workflows so key-encrypting material is not under one person's sole control.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.