Skip to main content

overview

encrypted dataGenesysKey Managementwrap / unwrapkey controlDuoKey Cockpityour key (BYOK)vault APIVault / HSMkey never exportedRevoke the key → instant lockout
Genesys keeps the data; DuoKey keeps the key. You stay in control — revoke the key and the data goes dark, everywhere.
Applies to:
Genesys Cloud CXRecording Encryption

DuoKey for Genesys Cloud connects a Genesys app in DuoKey Cockpit to Genesys Cloud's key management configuration. Genesys Cloud calls the app's endpoint directly to wrap and unwrap the encryption key it uses to protect contact center recordings and PII data, so the key material is generated, stored, and rotated in DuoKey Cockpit.

What is the Genesys Integration?​

An administrator creates a Genesys app in DuoKey Cockpit with the Genesys Cloud organization ID and region, selects which Genesys divisions may use the key, and links the app to a vault and an AES-256 key. Genesys Cloud is then configured (in Genesys Admin > Organization > Key Management) to call that app's endpoint to wrap and unwrap the key material it uses for recording encryption.

Key Features​

Centralized Key Management

The encryption key protecting Genesys Cloud recordings is generated, stored, and rotated in DuoKey Cockpit.

Direct Integration

Genesys Cloud calls the DuoKey Cockpit app's endpoint directly to wrap and unwrap the key - no additional platform or proxy is required.

Division-Scoped Access

Restrict which Genesys Cloud divisions can use the key by selecting allowed divisions when configuring the app.

Complete Audit Trail

Every wrap and unwrap operation is logged in DuoKey Cockpit's audit log.

Configuration Fields​

FieldDescription
App NameA label for this Genesys integration.
DescriptionOptional free-text description.
Organization IDYour Genesys Cloud organization ID.
RegionYour Genesys Cloud region, e.g. `mypurecloud.com`.
Allowed DivisionsThe Genesys Cloud divisions permitted to use this encryption key.
Vault & KeyThe vault and AES-256 key that Genesys Cloud wraps/unwraps against.

Deploying the app generates an endpoint and a connector secret (shown once), which are entered into Genesys Cloud's key management configuration.

Use Cases​

Centralized Key Custody

Keep the key protecting Genesys Cloud recordings under the same key-management program as your other apps.

Division-Scoped Deployments

Limit key access to specific Genesys divisions, e.g. a regulated business unit, without affecting the rest of the organization.

Key Rotation

Rotate the linked key and the app's connector secret from DuoKey Cockpit without redeploying Genesys Cloud.

Compliance & Audit

Correlate DuoKey's wrap/unwrap audit log with Genesys Cloud's own recording and access records.

Prerequisites​

Prerequisites

  • Genesys Cloud admin access with permission to configure key management
  • Your Genesys Cloud organization ID and region
  • A DuoKey Cockpit vault with an AES-256 key available to link to the app
  • DuoKey Cockpit account with permission to create Apps
  • Network connectivity (HTTPS) between Genesys Cloud and DuoKey Cockpit

Security Considerations​

  • The connector secret generated for this app authenticates only Genesys Cloud's wrap/unwrap calls to this app; it does not grant access to other apps or keys in Cockpit.
  • The connector secret is shown once at deployment - store it securely, and use the rotate action in Cockpit to mint a replacement if it may have been exposed.
  • Scope allowed divisions to only what this integration needs.

Getting Started​

Ready to connect Genesys Cloud to DuoKey Cockpit? Follow the setup guide:

  1. Getting Started - Create the app and link a key

Support​

For technical support or questions about DuoKey for Genesys Cloud: