Overview
How Cockpit v2 stores and uses key material — the unified vault interface, per-tenant/per-app vault selection, supported key types, the PQC/FIPS capability matrix and vault management.
Software & DuoKey MPC KMS
The two DuoKey-operated software backends — the in-memory Software Vault (development) and the DuoKey Software HSM, an MPC key-management service that splits keys across a 3+ node cluster (the default DuoKey KMS).
Securosys HSM
The Securosys Primus / CloudsHSM backend in Cockpit v2 — connected over the Transaction Security Broker (TSB) REST API, with hardware post-quantum support and full HSM operations (encrypt, sign, HMAC, wrap/unwrap, CSR, TRNG).
Sepior (Blockdaemon)
The Sepior (now Blockdaemon) threshold-MPC vault in Cockpit v2 — key shares split across TSM nodes, integrated through the DuoKey KMS API with OAuth2 and a session-based crypto flow.
HSM Agent
Connect your own on-premises HSM to Cockpit v2 without opening any inbound connection — a hardened on-site agent, an outbound-only tunnel, a three-gate authorization model, and a tamper-evident local audit log.