Business stakes
Challenges leaders recognise
Provider-accessible keys are no longer enough
Guidance for sensitive and legally confidential data increasingly requires that the cloud operator cannot decrypt alone.
Residency is not custody
Hosting in-country or in an EU data boundary does not remove extraterritorial access risk when the operator can still use the keys.
Mixed sensitivity in one tenant
Not every mailbox needs the same control. Programmes need labelled DKE for high-sensitivity content and clearer Customer Key governance for broader service encryption.
Audit and accountability
Supervisors and data-protection officers ask who can unlock content, under which policy, with which evidence, not only whether encryption is enabled.
Solutions
How DuoKey addresses the sector
Microsoft Double Key Encryption (DKE)
Apply DKE so Microsoft holds one key and your administration holds the external key required to unlock.
Learn moreMicrosoft 365 Customer Key
Run Customer Key under your authority for regulated collaboration workloads.
Learn moreAWS External Key Store (XKS)
Keep AWS KMS APIs in applications while cryptographic operations run in an external key store.
Learn moreOpenBAO + DuoKey SD-HSM
Govern keys with MPC-based auto-unseal without depending on a single physical unseal HSM.
Learn moreCompliance
Regulatory context
Swiss FADP
Technical and organisational measures that show you control access to plaintext, not only that a vendor encrypts data.
GDPR
Encryption and key custody as part of proportionate security for personal data in public services.
Sovereignty and cloud concentration
Separate data hosting from decryption authority when using hyperscale SaaS and IaaS.
Parlons des décisions qui comptent pour votre programme de sécurité.
Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.
