
Full Control Over Encryption Keys
With DuoKey, you have full control over your encryption keys, ensuring that only authorized personnel can access sensitive data.
AWS XKS Encryption
Keep using AWS KMS in applications, while an external key store holds the authority Amazon lacks.
The problem
XKS only matters when the external KMS is independent of AWS.
Storing objects in AWS while leaving key control in the same cloud, or in a weakly isolated HSM, does not answer compelled-access or sovereignty questions.
An external endpoint in AWS’s trust domain is not independent.
The key must live where policy says the data lives.
Hardware ops stall teams that should be shipping.
If the external KMS is down, objects cannot be read.
Security leadership
AWS XKS Encryption
Four questions surface in every security review.
What changes
DuoKey for AWS XKS uses secure multi-party computation (MPC) to generate and protect root key material for AWS KMS, ensuring no single entity including AWS can access complete encryption keys while maintaining full data confidentiality.
Always client-side encryption is performed
No third-party can ever access your data
Dedicated tenant and vault for storing your keys
Monitor who uses your keys
Key benefits
Protecting cloud data protection and ensuring regulatory compliance and business continuity with DuoKey' AWS XKS
Meets strict regulatory requirements like GDPR, HIPAA and PCI DSS by implementing encryption standards that protect customer data and reduce legal liability risks
Maintains customer confidence and business operations by preventing costly data breaches, minimising downtime from security incidents and preserving brand reputation
Encrypts sensitive data both at rest and in transit, ensuring unauthorised users cannot access sensitive information even if they breach cloud storage or intercept data transfers.
Proof in practice
Deep dives
Encryption Key Management

With DuoKey, you have full control over your encryption keys, ensuring that only authorized personnel can access sensitive data.
Products
Keep Microsoft from unlocking regulated mail, files and Teams content alone, without leaving M365.
Tell us where control is difficult today. We will help you identify a practical next step.