Requirements
What the regulation expects

Critical for SaaS and US enterprise deals
Many buyers require a SOC 2 report early. Request NDA sharing in the security review kickoff.
What buyers usually check
Availability SLAs, processing integrity, confidentiality of customer data and privacy controls.
Product evidence that helps the questionnaire
Tamper-evident audit trails, access governance and customer-held keys for confidentiality narratives.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Access policies, key inventory and hash-chained activity logs for auditor packages.
Learn moreMicrosoft 365 DKE / AWS XKS
Customer-held keys so DuoKey and cloud hosts are not the sole path to plaintext.
Learn moreKey themes
Where independent key control fits
Status: aligned. Report under NDA. Audit on roadmap. Match RFP language to that status.
Security
Authentication, authorization, encryption and monitoring controls mapped to the trust service criteria.
Availability
Documented SLAs and custody models that keep key services recoverable without a single point of compromise.
Confidentiality
Customer-held keys, TLS on service paths and least-privilege access to key material.
Privacy controls
Access logging and key location options that support privacy and residency commitments in the contract.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
