DuoKey

Sovereign Cloud & Data Sovereignty

Place cryptographic control where the organisation has committed it to sit—while still using major cloud and SaaS platforms.

Who it is for

Programmes that cannot treat residency as custody

For organisations that must show the cloud or SaaS operator cannot decrypt alone.

01

Public sector and regulated enterprises

Sensitive or confidential data in Microsoft 365 and hyperscale cloud where provider-accessible keys are insufficient.

02

Multi-cloud architecture teams

Need one custody model across AWS, Microsoft 365 and secrets platforms—not a different story per vendor.

03

Compliance and data-protection officers

Need evidence of who can unlock data under GDPR, FADP, DORA and related frameworks.

External keys

Cryptographic operations for protected workloads run outside the cloud operator trust boundary

Same platforms

Keep AWS, Microsoft 365 and OpenBAO usable while custody moves

Audit path

Named authority over key use for supervisors and internal audit

Residency is not custody

Residency is not custody

Hosting in a preferred region or data boundary helps with residency. It does not by itself remove provider access to keys. Sovereignty programmes fail the practical test when the operator can still decrypt.

DuoKey focuses on customer-controlled keys for the platforms you already run: Microsoft 365 (DKE and Customer Key), AWS External Key Store, and OpenBAO with DuoKey SD-HSM.

How it works

External key paths on the stack you already use

Apply custody where the data lives. Do not rip out the productivity or cloud platforms the business depends on.

Microsoft 365

Microsoft 365

DKE for high-sensitivity content; Customer Key for stronger service encryption under your authority.

AWS XKS

AWS XKS

Keep KMS APIs in applications while cryptographic operations run in an external key store.

OpenBAO + SD-HSM

OpenBAO + SD-HSM

Vault-compatible secrets management with MPC auto-unseal under your authority.

What changes

Outcomes for sovereignty programmes—not generic cloud security.

  • Control that survives the operator

    Demonstrate that a provider channel does not automatically yield plaintext.

  • Consistent custody story

    One model across SaaS and IaaS instead of fragmented BYOK exceptions.

  • Cloud without surrendering unlock authority

    Keep using major clouds while keys stay outside their sole control.

Next step

Still weighing the control model?

Bring the constraint. We’ll map the shortest practical path.

Map your sovereignty product path

Review DKE vs Customer Key, XKS vs native KMS, or schedule a scoped architecture discussion.