Compliance & Audit
On-premise DuoKey is built to satisfy the evidence and governance requirements of regulated and defense customers: complete audit trails, SIEM integration, and alignment with recognized frameworks.
What gets audited
| Layer | Audited events |
|---|---|
| Application | Authentication, authorization, key lifecycle operations (create/use/rotate/delete), policy changes |
| Platform (OpenShift) | API server audit log: every privileged action, RBAC change, secret access |
| Secret manager | Auth attempts, secret reads, policy changes (Vault/OpenBao/CyberArk audit devices) |
| Network | WAF events, load balancer / firewall logs, denied connections |
| HSM | Key usage and administrative operations (per vendor) |
SIEM integration
All logs are forwarded to your SIEM for correlation, alerting, and long-term retention.
DuoKey app logs
OpenShift audit log
Secret manager audit
WAF / FW logs
VictoriaLogs
Log forwarder · Vector
SIEMSplunk · Sentinel · QRadar · Elastic
Application, audit, secret-manager, and network logs are collected by the Vector forwarder and streamed to your SIEM for correlation and retention.
- Forwarders: Vector (bundled) or the OpenShift Cluster Logging operator can ship to Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or any syslog/CEF endpoint.
- Formats: JSON, CEF, and syslog are supported for SIEM ingestion.
Tamper-evidence & retention
- Immutable forwarding — logs are streamed off the cluster in near real time, so a compromised node cannot erase the central record.
- Write-once storage — archive audit data to WORM / object-lock storage where required.
- Retention — configurable per policy (commonly 1–7 years for regulated and defense workloads).
- Integrity — optionally hash-chain or sign archived audit batches for tamper-evidence.
Frameworks & standards
The deployment provides controls that map to common frameworks. (DuoKey supplies the technical controls; certification of your deployment is performed by your auditors.)
| Framework / standard | How the deployment helps |
|---|---|
| FIPS 140-2 / 140-3 | FIPS cryptographic mode + validated HSM |
| ISO/IEC 27001 | Access control, logging, encryption, BCP/DR controls |
| SOC 2 | Security, availability, and confidentiality controls + audit trail |
| GDPR / data residency | All data remains on-premise within your jurisdiction |
| NIST 800-53 / 800-171 | Mapped technical controls (AC, AU, SC, SI families) |
| DISA STIG / CIS Benchmark | Enforced via the Compliance Operator (see Hardening) |
| Common Criteria | HSM and platform components with CC-evaluated options |
Access recertification & separation of duties
- Periodic access recertification of IdP group-to-role mappings (see Identity & SSO).
- Separation of duties enforced via RBAC: operators, administrators, and auditors hold disjoint privileges.
- Break-glass accounts are sealed in your privileged-access vault and their use is alerted on.
Evidence you can produce on demand
- Who accessed which key, when, and under what policy.
- Every administrative and RBAC change on the platform.
- Proof of encryption at rest and in transit.
- Backup success/restore-test history (see Backup & Disaster Recovery).
- CIS/STIG scan results and remediation status.