Skip to main content
Agentic KMS · Crypto Agility Plane

One control plane for enterprise cryptography

DuoKey unifies key management, post-quantum readiness and crypto agility behind a single, AI-operable control plane. Declare what you protect — the platform resolves the algorithm, key and backend, and keeps your estate compliant from source code to production.

Agentic control planeAI + MCP operate crypto in natural language
Crypto agilitySwap algorithms with a policy edit, zero rewrite
PQC-nativeHybrid post-quantum by default
Flagship products of the month
New this monthCrypto Agility Plane

Crypto Agility Plane SDK

Declare what you protect, never how. Central policy resolves the algorithm, post-quantum posture, key and backend at runtime — flip a fleet to PQC with a policy edit.

  • Intent-based API for Java and .NET
  • Post-quantum by default (ML-KEM / ML-DSA)
Learn more
DuoKey Cockpit · Crypto Assets
Crypto Agility Plane SDK

A platform, not a point solution

Six capabilities that turn scattered encryption products into one governed, agile and quantum-ready control plane.

Agentic control plane

An AI agent — or your IDE copilot — operates cryptography over MCP across dev, CI and runtime: scan, decide, remediate and open a pull request in natural language.

Crypto agility by policy

Applications declare a business intent, never an algorithm. Deprecating a cipher or flipping a fleet to post-quantum becomes a central policy edit — no recompile, no code change.

Post-quantum native

Hybrid PQC by default with ML-KEM and ML-DSA. Reuse DuoKey CPM (Cryptographic Posture Management, formerly the PQC Scanner), the CBOM and the Quantum Readiness Score to plan and prove your migration to NIST FIPS 203/204/205.

Sovereign key management

Keys distributed across a 3-node Multi-Party Computation cluster running in sovereign clouds (EU, Switzerland, US) — no single entity ever holds a complete key.

Vendor-agnostic backends

One integration layer for HSMs, cloud KMS and vaults — Securosys, Azure Key Vault, AWS KMS, Google Cloud KMS, HashiCorp Vault, OpenBao and more, through PKCS#11 and KMIP.

Governance & audit

A closed CBOM-to-runtime loop reconciles what your code declares with what actually runs. Drift raises an alert and a remediation plan — governed and audit-ready.

New product

Crypto Agility Plane SDK

Declare what you protect — never how. Your code states a business intent; the Crypto Agility Plane resolves the algorithm, post-quantum posture, key and backend from your central policy at runtime.

  • Intent-based API for Java / Spring Boot and .NET / EF Core
  • Flip a fleet to post-quantum with one policy edit — zero application code change
  • Bootstrap from standard templates: PCI-DSS 4.0, FINMA, ENISA, NIST CNSA 2.0, FIPS/FedRAMP, GDPR
Customer.java
// Declare WHAT you protect — never the algorithm.
@Protect(dataClass = PII, purpose = SIGN, residency = EU)
private byte[] signature;

// The plane resolves HOW, at runtime, from central policy:
CapDecision d = cap.resolve("pii", "sign");
// d.algorithm() -> "hybrid-ml-dsa65-ecdsa-p256"
// d.posture()   -> "hybrid"   (post-quantum ready)

// Close the loop: report what actually ran.
cap.observe("pii", "sign", "ecdsa-p256", "payments-svc");

How the Crypto Agility Plane works

From a one-line intent to a governed, post-quantum-ready operation — in four steps.

1

Declare intent

The developer states a data class and purpose — no algorithm, mode or key in code.

2

Policy resolves

The tenant policy maps the intent to an algorithm, PQC posture, key reference and backend.

3

Run on the resolved backend

The operation executes on the chosen KMS or HSM — sovereign, vendor-agnostic, audited.

4

Observe & close the loop

Runtime telemetry is reconciled against the CBOM; drift triggers an alert and remediation.

Keys stay protected by a 3-node Multi-Party Computation cluster across three sovereign clouds, so no single entity ever holds a complete key.

Sovereign Cloud EU Sovereign Cloud Switzerland Sovereign Cloud US

Ready to make your estate crypto-agile?

Start with the Crypto Agility Plane SDK, or explore the full DuoKey product suite.