Skip to main content

Compliance & Audit

On-premise DuoKey is built to satisfy the evidence and governance requirements of regulated and defense customers: complete audit trails, SIEM integration, and alignment with recognized frameworks.

What gets audited​

LayerAudited events
ApplicationAuthentication, authorization, key lifecycle operations (create/use/rotate/delete), policy changes
Platform (OpenShift)API server audit log: every privileged action, RBAC change, secret access
Secret managerAuth attempts, secret reads, policy changes (Vault/OpenBao/CyberArk audit devices)
NetworkWAF events, load balancer / firewall logs, denied connections
HSMKey usage and administrative operations (per vendor)

SIEM integration​

All logs are forwarded to your SIEM for correlation, alerting, and long-term retention.

SIEM integration
DuoKey app logs
OpenShift audit log
Secret manager audit
WAF / FW logs
VictoriaLogs
Log forwarder · Vector
SIEMSplunk · Sentinel · QRadar · Elastic

Application, audit, secret-manager, and network logs are collected by the Vector forwarder and streamed to your SIEM for correlation and retention.

  • Forwarders: Vector (bundled) or the OpenShift Cluster Logging operator can ship to Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or any syslog/CEF endpoint.
  • Formats: JSON, CEF, and syslog are supported for SIEM ingestion.

Tamper-evidence & retention​

  • Immutable forwarding — logs are streamed off the cluster in near real time, so a compromised node cannot erase the central record.
  • Write-once storage — archive audit data to WORM / object-lock storage where required.
  • Retention — configurable per policy (commonly 1–7 years for regulated and defense workloads).
  • Integrity — optionally hash-chain or sign archived audit batches for tamper-evidence.

Frameworks & standards​

The deployment provides controls that map to common frameworks. (DuoKey supplies the technical controls; certification of your deployment is performed by your auditors.)

Framework / standardHow the deployment helps
FIPS 140-2 / 140-3FIPS cryptographic mode + validated HSM
ISO/IEC 27001Access control, logging, encryption, BCP/DR controls
SOC 2Security, availability, and confidentiality controls + audit trail
GDPR / data residencyAll data remains on-premise within your jurisdiction
NIST 800-53 / 800-171Mapped technical controls (AC, AU, SC, SI families)
DISA STIG / CIS BenchmarkEnforced via the Compliance Operator (see Hardening)
Common CriteriaHSM and platform components with CC-evaluated options

Access recertification & separation of duties​

  • Periodic access recertification of IdP group-to-role mappings (see Identity & SSO).
  • Separation of duties enforced via RBAC: operators, administrators, and auditors hold disjoint privileges.
  • Break-glass accounts are sealed in your privileged-access vault and their use is alerted on.

Evidence you can produce on demand​

  • Who accessed which key, when, and under what policy.
  • Every administrative and RBAC change on the platform.
  • Proof of encryption at rest and in transit.
  • Backup success/restore-test history (see Backup & Disaster Recovery).
  • CIS/STIG scan results and remediation status.