DuoKey

Key Management System

A KMS your cloud never fully holds

Every key is split across independent shards with multi-party computation (MPC). No cloud provider, no single DuoKey operator, and no compromised host ever holds a complete key. Applications talk to a familiar KMS interface; the cryptography stays out of any one party's hands, by construction, not by policy.

Three key shares, split with multi-party computation, converging to a single lock that no single share can open alone

How it actually works

2-of-3 threshold signing: the full key is never assembled

A sign request reaches all key shards at once, but only two need to respond to produce a valid signature. No shard, agent, operator or cloud provider ever holds enough of the key to act alone, and the combine step never reconstructs the full private key in memory, on disk, or on the network. Steal one shard and you have nothing usable.

  • No single point of compromise: one stolen shard cannot produce a valid signature
  • No HSM hardware to rack, patch, renew or run out of capacity
  • Works the same way whether the shards sit in one cloud or three
  • Every signature traceable to a named requester, not a shared service credential
Compare MPC to HSM-based key management
2-of-3 threshold signing: the full key is never assembled

Le Cockpit

Chaque clé, taguée par algorithme et statut

Active, désactivée ou compromise : chaque clé de chaque vault, avec son algorithme clairement affiché, pas noyé dans les métadonnées.

Cockpit, Clés
Liste des clés DuoKey Cockpit montrant clés actives, désactivées et compromises avec leurs algorithmes cryptographiques
Distributed key generation across independent cloud parties, with no party ever holding the full key

Key generation

The key never exists whole, not even at birth

Generation is distributed the same way signing is: independent parties compute their own shard, and no single party, including DuoKey, ever observes the assembled private key. Rotation and revocation replace shards without ever reconstituting the key they protect.

Engagement

Stop trusting the cloud vault as the final word on keys

See the threshold signing model in your own environment, with keys that are never assembled, on any side.

Request a demo

Parlons des décisions qui comptent pour votre programme de sécurité.

Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.