DuoKey

Microsoft Double Key Encryption (DKE)

Double Key Encryption for Microsoft 365

Keep Microsoft from unlocking regulated mail, files and Teams content alone, without leaving M365.

Product demo

Watch DuoKey for DKE Demo

Experience true data security for Microsoft 365

The Cockpit

See the double-key path, end to end

Client, Azure RMS, your zero-trust policy layer, DKE Cockpit and the vault holding the key that never leaves your control, traced as one flow.

Cockpit, DKE Service
DuoKey Cockpit Double Key Encryption flow diagram tracing a request from Microsoft 365 through Azure RMS, policy enforcement, DKE Cockpit and the vault-held key

The problem

Microsoft still sits inside the trust boundary

Default M365 encryption does not keep the provider off the key.

When the same party stores content and can unwrap it, sovereignty and compelled-access risk stay with the SaaS vendor. Sensitive mail, files and meetings are only as independent as the keys.

  • Microsoft can unwrap

    If Microsoft holds a wrapping key, it can reach the content.

  • Tenant ≠ custody

    Admin settings do not keep the provider off the key.

  • Vendor legal process

    A request can target Microsoft, not your organisation.

  • DKE gap

    Without a second key you control, M365 encryption is not independent.

Security leadership

What the board is asking

Microsoft Double Key Encryption (DKE)

Four questions surface in every security review.

Talk to our security architects

What changes

Independent key control inside Microsoft 365

DuoKey for Double Encryption (DKE) uses distributed MPC technology and zero-trust controls to ensure Microsoft has zero access to your encryption keys, delivering complete data sovereignty with flexible deployment options and HSM integration.

  • Always client-side encryption is performed

  • No third-party can ever access your data

  • Dedicated tenant and vault for storing your keys

  • Manage key access with granular rules outside of Microsoft

Key benefits

Secure your data. Stay compliant.

Protecting cloud data, ensuring regulatory compliance and business continuity with DuoKey's DKE for Microsoft.

  • Compliance Assurance

    Meets strict regulatory requirements like GDPR, HIPAA and PCI DSS by implementing encryption standards that protect customer data and reduce legal liability risks

  • Operational Resilience

    Maintains customer confidence and business operations by preventing costly data breaches, minimising downtime from security incidents and preserving brand reputation

  • Advanced Data Protection

    Encrypts sensitive data both at rest and in transit, ensuring unauthorised users cannot access sensitive information even if they breach cloud storage or intercept data transfers.

In detail

What changes for collaboration and compliance

Advanced Zero Trust Access Controls

Enforce strict authorisation for every key access request through role-based permissions and multi-factor verification (eg. IP, Azure groups, location, user). Only verified users can access encryption keys, with continuous monitoring of all access attempts.

Learn more

Products

Related products

AWS XKS Encryption

Keep using AWS KMS in applications, while an external key store holds the authority Amazon lacks.

View product

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.