DuoKey

AWS S3 Encryption

Encrypt S3 without handing Amazon the last key

Objects stay in S3 for scale. Decryption still requires a key share you hold outside AWS.

The problem

S3 encryption is not the same as independent control

Cloud-native keys still leave unwrap authority with the hyperscaler.

Buckets can be encrypted and still be readable by the account, the provider, or anyone who inherits IAM. For regulated data, the question is who can compel or inherit the unwrap.

  • AWS-managed KMS

    SSE with AWS keys keeps AWS on the unwrap path.

  • IAM inheritance

    A broad role can decrypt without anyone intending it.

  • Shared landing zones

    Account structure often blurs who owns the key.

  • Encrypted ≠ exclusive

    Audits ask who can unwrap, not whether SSE is on.

Security leadership

What the board is asking

AWS S3 Encryption

Four questions surface in every security review.

Talk to our security architects

What changes

Client-side control for Amazon S3

DuoKey provides robust Amazon S3 encryption using Multi-Party Computation (MPC) technology that divides cryptographic keys among multiple parties, eliminating single points of f…

  • Always client-side encryption is performed

  • No third-party can ever access your data

  • Dedicated tenant and vault for storing your keys

  • Monitor who uses your keys

Key benefits

Secure your data. Stay compliant.

Protecting cloud data protection and ensuring regulatory compliance and business continuity with DuoKey's AWS S3 encryption

  • Advanced Data Protection

    Encrypts sensitive data both at rest and in transit, ensuring unauthorised users cannot access sensitive information even if they breach cloud storage or intercept data transfers.

  • Operational Resilience

    Maintains customer confidence and business operations by preventing costly data breaches, minimising downtime from security incidents and preserving brand reputation

  • Compliance Assurance

    Meets strict regulatory requirements like GDPR, HIPAA and PCI DSS by implementing encryption standards that protect customer data and reduce legal liability risks

In detail

What changes for cloud storage programmes

Encrypt

Unlike traditional server-side encryption done with AWS KMS, which involves the AWS infrastructure having access to your encryption keys, DuoKey's client-side encryption ensures that the encryption process is performed locally on your client device. This approach provides an extra layer of security by keeping the encryption keys under your control, reducing the risk of unauthorized access to your sensitive data.

Products

Check out the other DuoKey products

Microsoft Double Key Encryption (DKE)

Keep Microsoft from unlocking regulated mail, files and Teams content alone, without leaving M365.

View product

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.