DuoKey

AWS XKS Encryption

AWS XKS with keys Amazon cannot complete alone

Keep using AWS KMS in applications, while an external key store holds the authority Amazon lacks.

The problem

External keys still fail if you do not own the unwrap

XKS only matters when the external KMS is independent of AWS.

Storing objects in AWS while leaving key control in the same cloud, or in a weakly isolated HSM, does not answer compelled-access or sovereignty questions.

  • XKS in the same cloud

    An external endpoint in AWS’s trust domain is not independent.

  • Wrong jurisdiction

    The key must live where policy says the data lives.

  • Self-run HSM

    Hardware ops stall teams that should be shipping.

  • XKS outage = dark data

    If the external KMS is down, objects cannot be read.

Security leadership

What the board is asking

AWS XKS Encryption

Four questions surface in every security review.

Talk to our security architects

What changes

External Key Store for regulated AWS workloads

DuoKey for AWS XKS uses secure multi-party computation (MPC) to generate and protect root key material for AWS KMS, ensuring no single entity including AWS can access complete encryption keys while maintaining full data confidentiality.

  • Always client-side encryption is performed

  • No third-party can ever access your data

  • Dedicated tenant and vault for storing your keys

  • Monitor who uses your keys

Key benefits

Secure your data. Stay compliant.

Protecting cloud data protection and ensuring regulatory compliance and business continuity with DuoKey' AWS XKS

  • Compliance Assurance

    Meets strict regulatory requirements like GDPR, HIPAA and PCI DSS by implementing encryption standards that protect customer data and reduce legal liability risks

  • Operational Resilience

    Maintains customer confidence and business operations by preventing costly data breaches, minimising downtime from security incidents and preserving brand reputation

  • Advanced Data Protection

    Encrypts sensitive data both at rest and in transit, ensuring unauthorised users cannot access sensitive information even if they breach cloud storage or intercept data transfers.

Encryption Key Management

What changes for AWS sovereignty programmes

Full Control Over Encryption Keys

With DuoKey, you have full control over your encryption keys, ensuring that only authorized personnel can access sensitive data.

Products

Other Encryption Key Management Solutions

Microsoft Double Key Encryption (DKE)

Keep Microsoft from unlocking regulated mail, files and Teams content alone, without leaving M365.

View product

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.