DuoKey Cockpit (Platform)
The web console and REST API behind every DuoKey integration — the shared foundation for key management and PKI.
What is the Cockpit?
The Cockpit is DuoKey's Enterprise Key Management & PKI platform: the web console and REST API that sit behind all DuoKey integrations — DKE 365, Office 365 Customer Key, Oracle TDE, SQL EKM, AWS XKS, Salesforce / Workday / SAP BYOK, PKI / SSL, Vault / OpenBao / CyberArk, the PQC Scanner, and more.
Rather than reimplement security in every product, the Cockpit provides — once — the cross-cutting capabilities each integration reuses:
Multi-tenancy
Row-level isolation so every tenant's keys, policies and audit trail stay strictly separated.
Access policies
RBAC and ABAC access control governing who may perform which cryptographic operation, and when.
Key custody
Vault and HSM backends holding key material, with the Securosys HSM available for FIPS-validated custody.
Tamper-evident audit
A cryptographically chained audit log recording every security-relevant action across every product.
PKI / CA
Certificate authority and certificate lifecycle services shared by the PKI, SSL and PQC integrations.
Post-quantum tooling
Discovery and migration tooling for post-quantum readiness, surfaced through the same console and API.
This section documents the platform itself. The individual product guides — Oracle TDE, DKE 365, and the others — link here for the shared platform behaviour instead of repeating it.
Platform at a glance
| Dimension | DuoKey Cockpit |
|---|---|
| Web console | Modern web console and REST API |
| Access control | RBAC + attribute-based access control (ABAC) |
| Deployment | Single self-contained container image |
| Multi-tenancy | Row-level tenancy with per-tenant identity providers and vaults |
Any throughput, latency, memory or image-size figures quoted for the Cockpit in DuoKey material are indicative targets, not independently benchmarked guarantees. Validate against your own environment before relying on them for capacity planning.
Explore the platform
Foundations
Architecture
How the platform is built — its layers and the request flow through the platform.
Security
Authentication, encryption at rest, and the tamper-evident audit model shared across products.
Capabilities
The cross-cutting capabilities every DuoKey integration reuses.
Access Policies
The RBAC + ABAC model governing who may perform which operation.
Vaults & HSM
How key material is stored and used — software, MPC, HSM and cloud KMS backends.
SSH Certificate Authority
Vault-backed short-lived host and user SSH certificates that replace static keys and authorized_keys files.
Deployment
How the Cockpit is packaged, deployed and operated.
Platform modules
Administration
Users, roles and permissions, organizational units, identity providers and authentication.
Tenants
Row-level multi-tenancy, tenant lifecycle and OU sub-scoping.
Host
System administration above the tenant tier — settings, dashboard and monitoring.
Editions
Data-driven product tiers that grant features and limits to tenants.
Features
The entitlement catalog and the app-type / product registry.
MCP
Connect Claude Code, Claude.ai or Claude Desktop to your tenant's data over the Model Context Protocol.