Skip to main content
Applies to:
DuoKey CockpitKey ManagementPKI

What is the Cockpit?​

The Cockpit is DuoKey's Enterprise Key Management & PKI platform: the web console and REST API that sit behind all DuoKey integrations — DKE 365, Office 365 Customer Key, Oracle TDE, SQL EKM, AWS XKS, Salesforce / Workday / SAP BYOK, PKI / SSL, Vault / OpenBao / CyberArk, the PQC Scanner, and more.

Rather than reimplement security in every product, the Cockpit provides — once — the cross-cutting capabilities each integration reuses:

Multi-tenancy

Row-level isolation so every tenant's keys, policies and audit trail stay strictly separated.

Access policies

RBAC and ABAC access control governing who may perform which cryptographic operation, and when.

Key custody

Vault and HSM backends holding key material, with the Securosys HSM available for FIPS-validated custody.

Tamper-evident audit

A cryptographically chained audit log recording every security-relevant action across every product.

PKI / CA

Certificate authority and certificate lifecycle services shared by the PKI, SSL and PQC integrations.

Post-quantum tooling

Discovery and migration tooling for post-quantum readiness, surfaced through the same console and API.

One platform, many products

This section documents the platform itself. The individual product guides — Oracle TDE, DKE 365, and the others — link here for the shared platform behaviour instead of repeating it.

Platform at a glance​

DimensionDuoKey Cockpit
Web consoleModern web console and REST API
Access controlRBAC + attribute-based access control (ABAC)
DeploymentSingle self-contained container image
Multi-tenancyRow-level tenancy with per-tenant identity providers and vaults
Performance figures

Any throughput, latency, memory or image-size figures quoted for the Cockpit in DuoKey material are indicative targets, not independently benchmarked guarantees. Validate against your own environment before relying on them for capacity planning.

Explore the platform​

Foundations

Platform modules