Crypto Agility Plane SDK
Declare what you protect, never how. Central policy resolves the algorithm, post-quantum posture, key and backend at runtime — flip a fleet to PQC with a policy edit.
- Intent-based API for Java and .NET
- Post-quantum by default (ML-KEM / ML-DSA)

A platform, not a point solution
Six capabilities that turn scattered encryption products into one governed, agile and quantum-ready control plane.
Agentic control plane
An AI agent — or your IDE copilot — operates cryptography over MCP across dev, CI and runtime: scan, decide, remediate and open a pull request in natural language.
Crypto agility by policy
Applications declare a business intent, never an algorithm. Deprecating a cipher or flipping a fleet to post-quantum becomes a central policy edit — no recompile, no code change.
Post-quantum native
Hybrid PQC by default with ML-KEM and ML-DSA. Reuse DuoKey CPM (Cryptographic Posture Management, formerly the PQC Scanner), the CBOM and the Quantum Readiness Score to plan and prove your migration to NIST FIPS 203/204/205.
Sovereign key management
Keys distributed across a 3-node Multi-Party Computation cluster running in sovereign clouds (EU, Switzerland, US) — no single entity ever holds a complete key.
Vendor-agnostic backends
One integration layer for HSMs, cloud KMS and vaults — Securosys, Azure Key Vault, AWS KMS, Google Cloud KMS, HashiCorp Vault, OpenBao and more, through PKCS#11 and KMIP.
Governance & audit
A closed CBOM-to-runtime loop reconciles what your code declares with what actually runs. Drift raises an alert and a remediation plan — governed and audit-ready.
Crypto Agility Plane SDK
Declare what you protect — never how. Your code states a business intent; the Crypto Agility Plane resolves the algorithm, post-quantum posture, key and backend from your central policy at runtime.
- Intent-based API for Java / Spring Boot and .NET / EF Core
- Flip a fleet to post-quantum with one policy edit — zero application code change
- Bootstrap from standard templates: PCI-DSS 4.0, FINMA, ENISA, NIST CNSA 2.0, FIPS/FedRAMP, GDPR
// Declare WHAT you protect — never the algorithm.
@Protect(dataClass = PII, purpose = SIGN, residency = EU)
private byte[] signature;
// The plane resolves HOW, at runtime, from central policy:
CapDecision d = cap.resolve("pii", "sign");
// d.algorithm() -> "hybrid-ml-dsa65-ecdsa-p256"
// d.posture() -> "hybrid" (post-quantum ready)
// Close the loop: report what actually ran.
cap.observe("pii", "sign", "ecdsa-p256", "payments-svc");How the Crypto Agility Plane works
From a one-line intent to a governed, post-quantum-ready operation — in four steps.
Declare intent
The developer states a data class and purpose — no algorithm, mode or key in code.
Policy resolves
The tenant policy maps the intent to an algorithm, PQC posture, key reference and backend.
Run on the resolved backend
The operation executes on the chosen KMS or HSM — sovereign, vendor-agnostic, audited.
Observe & close the loop
Runtime telemetry is reconciled against the CBOM; drift triggers an alert and remediation.
Keys stay protected by a 3-node Multi-Party Computation cluster across three sovereign clouds, so no single entity ever holds a complete key.
Ready to make your estate crypto-agile?
Start with the Crypto Agility Plane SDK, or explore the full DuoKey product suite.



