DuoKey

Your secrets manager has one secret it can't manage itself

Every vault needs a master key to unseal and that key can't be stored in the vault it protects. DuoKey externalizes vault master keys to MPC or HSM, so auto-unseal doesn't depend on a key sitting on disk or in a single operator's hands.

The chicken-and-egg problem

Secrets managers protect everything except the one secret that protects them.

01

Master key protection

Store the master key in the vault and the vault can't unseal itself. Store it elsewhere in a single place and that location becomes the single point of failure the vault was meant to prevent.

02

Kubernetes secrets at scale

Cloud-native workloads generate and rotate secrets faster than manual key ceremonies can keep up with.

03

Vault licensing and lock-in

Commercial secrets-management licensing and vendor lock-in push teams toward open alternatives like OpenBao, which still need a hardened way to auto-unseal.

Externalize the master key, not the risk

DuoKey protects HashiCorp Vault, OpenBao and similar secrets managers by moving the master key out of the vault entirely, into an MPC KMS or HSM. The vault auto-unseals using distributed key shares instead of a key sitting on disk or with a single administrator.

  • MPC or HSM-backed: choose software-defined MPC or hardware HSM protection for the master key

  • Auto-unseal without a single point of failure: no operator holds the whole key and no single node can reconstruct it

  • Kubernetes and cloud-native ready: works with vault instances running in containers and across cloud environments

Externalize the master key, not the risk

Key Benefits

What externalizing the master key gets you

  • No single point of failure

    The master key is never stored whole in one place, MPC distributes it, HSM hardens it.

  • Vault-agnostic protection

    Works with HashiCorp Vault, OpenBao and other secrets managers that support external auto-unseal.

  • Kubernetes and cloud-native fit

    Secures secrets management for containerized and multi-cloud workloads without manual key ceremonies.

  • Lower total cost than dedicated HSM fleets

    A software-defined MPC option removes the need for a hardware HSM at every vault instance.

Next step

Still weighing the control model?

Bring the constraint. We’ll map the shortest practical path.

Give your vault a master key it can't leak

Talk to us about MPC or HSM-backed auto-unseal for Vault or OpenBao.