Requirements
What the regulation expects

Critical for SaaS and US enterprise buyers
Many organizations require a SOC 2 report early in security review. DuoKey shares the latest report under NDA on request.
What buyers usually check
Availability SLAs, processing integrity, confidentiality of customer data and privacy controls.
Product evidence for security reviews
Tamper-evident audit trails, access governance and customer-held keys for confidentiality narratives.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Access policies, key inventory and hash-chained activity logs for auditor packages.
Learn moreMicrosoft 365 DKE / AWS XKS
Customer-held keys so DuoKey and cloud hosts are not the sole path to plaintext.
Learn moreKey themes
Where independent key control fits
Status: aligned. Report available under NDA. Formal audit on roadmap.
Security
Authentication, authorization, encryption and monitoring controls mapped to the trust service criteria.
Availability
Documented SLAs and custody models that keep key services recoverable without a single point of compromise.
Confidentiality
Customer-held keys, TLS on service paths and least-privilege access to key material.
Privacy controls
Access logging and key location options that support privacy and residency commitments in the contract.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
