Microsoft Double Key Encryption
Protect Microsoft 365 documents with customer-controlled encryption keys.

DuoKey holds the keys behind the SaaS, cloud, database and infrastructure platforms you already run.
Catalogue
Filter by category or search by platform. Product pages explain the business case; the documentation covers setup in detail.
Protect Microsoft 365 documents with customer-controlled encryption keys.
Microsoft 365 Customer Key, so Microsoft cannot unlock regulated content alone.
External Key Management for Salesforce with full control over encryption keys.
MPC-powered key management for ServiceNow encryption.
Call recording encryption for Genesys Cloud contact centers.
Encrypt the sensitive data Varonis discovers and classifies.
Register your cloud KMS keys as OpenAI EKM external keys.
External Key Store integration for AWS KMS.
Server-side and client-side encryption options for Amazon S3.
External Key Manager integration for Azure Managed HSM.
Tri-Secret Secure for Snowflake with DuoKey AWS XKS and MPC.
Format-preserving tokenization for Databricks with Spark / Unity Catalog UDFs.
Keep Oracle's TDE master key off the database host with DuoKey's PKCS#11 library.
Extensible Key Management that keeps SQL Server keys outside the database.
Client-side column encryption; DuoKey custodies the Column Master Key.
InnoDB tablespace encryption with a DuoKey-backed keyring plugin.
pg_tde encryption backed by the KMIP server in DuoKey Cockpit.
Client-side field-level encryption; DuoKey custodies the master key.
Encrypted fields that stay queryable; DuoKey custodies the Customer Master Key.
SSTable and commitlog encryption with a rotation runbook that avoids downtime.
DuoKey provides the key encryption key behind Couchbase Encryption at Rest.
Bind Nutanix Data-at-Rest Encryption to a DuoKey-held key over KMIP.
DuoKey as a vCenter key provider over KMIP for VM, vTPM and vSAN encryption.
LUKS, Prim'X Cryhod and BitLocker with a DuoKey-held key encryption key.
Format-preserving tokenization for application data.
Auto-unseal OpenBao with DuoKey MPC; a Vault-compatible migration path.
Integrate the DuoKey PKCS#11 provider with HashiCorp Vault Enterprise.
Connect CyberArk Conjur to DuoKey Cockpit as a secret manager backend.
Certificate authority and certificate lifecycle with vault- or HSM-protected keys.
Server-side PDF signing API; the certificate never leaves the tenant keystore.
An OASIS KMIP 2.1 server for KMIP-compliant clients over TLS.
A Cryptoki 3.2 provider that proxies every operation to DuoKey Cockpit.
Named cryptographic identity and revocation for autonomous agents.
Keep encryption keys under your authority across cloud and hybrid estates.
Tell us where control is difficult today. We will help you identify a practical next step.