Why DuoKey Software-Defined HSM?
DuoKey Software-Defined HSM
A Software-Defined HSM delivers the same security guarantees as a traditional Hardware Security Module — but entirely in software, powered by Multi-Party Computation (MPC). Instead of locking keys inside a single physical appliance, DuoKey distributes AES key shares across multiple independent nodes so the complete key never exists in any single location.
Deployment Options
Software-Defined HSM
DefaultDistributed AES key management using MPC across multiple cloud regions or data centers. No hardware required, deploy in hours.
HSM-backed
OptionalIntegrates with Securosys HSM (Swiss vendor, FIPS 140-2 Level 3 & 4), Atos TrustWay, Fortanix, and Utimaco.
Supported Vault Backends

DuoKey MPC
Multi-Party Computation
FIPS-approved
DuoKey SD-HSM
Software-Defined HSM
MPC Cluster
Securosys CloudHSM
Swiss Cloud HSM
EU Residency
HashiCorp Vault
Secrets Engine
NativeOpenBao
Open-Source Vault
Vault-Compatible
Azure Key Vault
Microsoft Azure
Managed HSM
AWS KMS
Amazon Web Services
CloudHSM
Google Cloud KMS
Google Cloud
Multi-Region
Fortanix SDKMS
Confidential Computing
Intel SGX
Atos TrustWay HSM
Hardware HSM
ANSSI QualifiedCrypto4A QxHSM
PQC-Ready HSM
Quantum-Safe
Utimaco HSM
Hardware HSM
EAL5+Software-Defined HSM Architecture
Cryptographic keys distributed across 3 sovereign regions — never complete anywhere
No Single Point of Failure
- Keys never exist in complete form
- Operations distributed across 3+ nodes
- One compromised node ≠ compromised keys
- Multi-cloud provider distribution
Software-Based Security
- No expensive HSM hardware
- Lower total cost of ownership
- Faster deployment and scaling
- Cloud-native architecture
High Availability
- Active-active across regions
- Automatic failover (< 1s)
- Horizontal scaling on-demand
- Sub-millisecond operations
Geographic Distribution
- Deploy across AWS, Azure, GCP
- Resilient to regional outages
- Data residency compliance
- Global load balancing
Traditional HSM vs Software-Defined HSM
Traditional HSM vs Software-Defined HSM
12 criteria| Feature | Traditional HSM | DuoKey Software-Defined HSM |
|---|---|---|
| Security Model | Hardware-based | Cryptographically distributed |
| Single Point of Failure | Yes (HSM device) | No (distributed keys) |
| Geographic Distribution | Limited | Native multi-region |
| Cost | High ($$$$) | Low ($) |
| Deployment Time | Weeks | Hours |
| Scaling | Vertical (buy more HSMs) | Horizontal (add nodes) |
| Cloud Native | No | Yes |
| Disaster Recovery | Complex | Automatic |
| Performance | Limited by hardware | Software-optimized |
| Compliance | FIPS 140-2 Level 3 | Cryptographically equivalent |
| Vendor Lock-in | High | None |
| Multi-Cloud | Difficult | Native |
How the Software-Defined HSM Works
Cryptographic keys are never stored or reconstructed in a single location
Key Generation
Keys are generated in a distributed manner across multiple nodes simultaneously
Key Shares
Each node holds only a "share" of the key — never the complete key
AES Encrypt/Decrypt
Distributed AES encryption and decryption operations across nodes
Zero-Knowledge
No single node ever sees, stores, or can reconstruct the complete key
Geographic Distribution
Nodes deployed across different cloud providers and sovereign regions
Deployment Architecture
Cloud Deployment
Recommended- 3 Docker images across 3 cloud providers (AWS, Azure, GCP)
- Automatic failover and load balancing
- Geographic redundancy out of the box
- Managed infrastructure
On-Premises Deployment
- 3 Docker images across 3 separate data centers
- Administrative segregation (different admin teams per DC)
- Physical separation — no single point of compromise
- Full control over infrastructure
Hybrid Deployment
- Mix of cloud and on-premises nodes
- Example: AWS + Azure + On-Prem DC
- Maximum flexibility for compliance requirements
Security Guarantees
Distributed Security
- Keys split across multiple independent nodes
- Compromise of a single node does not expose the key
- Significantly increases attack difficulty vs single HSM
Information-Theoretic Security
- Individual key shares reveal zero information about the key
- Even with unlimited computing power, a single share is useless
- Security based on mathematical principles, not computational hardness
Use Cases Across DuoKey Products
Transparent Data Encryption
SQL Server EKM
- TDE with MPC-protected keys
- DBA/security separation of duties
- Centralized multi-DB management
Cloud Key Management
AWS XKS Proxy
- External Key Store for AWS KMS
- Double encryption: AWS + MPC
- Full key control in AWS
Salesforce BYOK
- Shield Platform Encryption
- Customer-controlled tenant secrets
- Data sovereignty & revocation
Secrets Management
HashiCorp Vault
- MPC backend storage
- Auto-unseal with distributed trust
- No single key compromise point
OpenBao
- Open-source Vault alternative
- MPC-backed secrets engine
- Community-driven development
Data Security & Compliance
Varonis DSPM
- Data classification + MPC encryption
- Privacy-preserving analytics
- GDPR, CCPA compliance
Contact Center & Digital Signatures
PDF Sign & PKI/SSL
- Qualified e-signatures (eIDAS)
- Private CA with MPC keys
- Certificate lifecycle management
Benefits: Software-Defined HSM vs Traditional HSM
Total Cost of Ownership
- Hardware purchase + maintenance contracts
- Specialized HSM administrators & consultants
- Professional services for setup, updates
- Data center space, power, cooling
- Complex multi-site redundancy (2-3x cost)
- Manual processes, no IaC support
- Limited DevOps/CI-CD integration
- No hardware purchase or maintenance
- Self-service management via API
- Full IaC support (Terraform, Ansible)
- Native DevOps/CI-CD integration
- Multi-region by default, auto failover
- Zero professional services for routine ops
- Elastic, pay-as-you-grow scaling
Deployment Speed
- Procurement: 4-8 weeks
- Hardware setup: 1-2 weeks
- Configuration: 1-2 weeks
- Testing & validation: 2-4 weeks
- Total: 2-4 months
- Cloud deployment: 1-2 hours
- Configuration: 4-8 hours
- Integration testing: 1-2 days
- Total: 2-5 days
- 20-40x faster deployment
Geographic Resilience
- Single data center deployment
- Complex replication setup
- Manual failover procedures
- Limited geographic distribution
- Multi-region by default
- Automatic failover (sub-second)
- Active-active architecture
- 99.99% vs 99.9% (10x fewer outages)
Scalability
- Fixed capacity per device
- Vertical scaling (buy more HSMs)
- Limited to physical constraints
- Complex capacity planning
- Horizontal scaling on-demand
- Auto-scaling based on load
- Unlimited capacity potential
- Linear cost growth
Enterprise Features
Centralized Management
Unified Dashboard
- Manage all keys across products
- Single pane of glass
- Role-based access control (RBAC)
- Multi-tenant architecture
API-Driven Automation
- RESTful APIs for all operations
- Infrastructure as Code (IaC)
- CI/CD integration
- GitOps compatible
Compliance & Audit
Regulatory alignment
- PCI DSS
- HIPAA/HITECH
- GDPR Article 32
- SOC 2
- ISO 27001
Monitoring
- Complete audit trail
- Tamper-evident logs
- Real-time alerting
- SIEM integration
Security Controls
Access
- Multi-factor authentication
- SSO via SAML/OIDC
- Time-based restrictions
- IP allowlisting
Key Lifecycle
- Automated key rotation
- Key versioning
- Soft delete with recovery
- Cryptographic shredding
Representative Scenarios
Major bank needed to encrypt 500+ Oracle databases while maintaining 99.99% availability
Solution
DuoKey Software-Defined HSM for Oracle TDE — deployed across 3 cloud regions (AWS, Azure, GCP) with distributed AES key operations and automated 90-day key rotation.
- ✓ High availability across multiple regions
- ✓ Lower TCO than dedicated HSM hardware
- ✓ Supports PCI DSS compliance programs
- ✓ Deploys in days, not months
Hospital network needed HIPAA-compliant encryption for patient data across Salesforce
Solution
DuoKey Software-Defined HSM for Salesforce BYOK — patient records encrypted with customer-controlled keys and key revocation for breach response.
- ✓ Supports HIPAA compliance
- ✓ Streamlined audit evidence
- ✓ Data sovereignty maintained
- ✓ MPC design: keys never reconstructed
SaaS provider needed per-tenant encryption keys for 10,000+ customers
Solution
DuoKey Software-Defined HSM multi-tenant architecture — unique key per tenant with horizontal scaling and sub-millisecond operations.
- ✓ Scales to thousands of tenants
- ✓ Low-latency key operations
- ✓ Per-tenant key isolation
- ✓ Clear competitive differentiator
Illustrative deployment scenarios based on typical customer profiles — not specific named customers or measured results.
Getting Started
Assessment
- Current KMS solution review
- Compliance requirements
- Performance & budget needs
- Timeline planning
Proof of Concept
- Free 30-day trial
- Technical support included
- Integration assistance
- Performance benchmarking
Deployment
- Phased migration plan
- Training & documentation
- Ongoing support
- Success metrics tracking
Optimization
- Performance monitoring
- Cost optimization
- Feature adoption
- Regular reviews
Technical Specifications
Performance
| Latency (p50) | < 2ms |
| Latency (p99) | < 10ms |
| Throughput | 10,000+ ops/sec/node |
| Availability | 99.99% SLA |
| Distribution | 3+ regions |
Supported Algorithms
Symmetric Encryption (AES)
Compliance Alignment
Designed to support your compliance programs (framework alignment, not DuoKey certifications):
Performance and availability figures on this page (latency, throughput, SLA) are indicative design targets, not independently benchmarked guarantees.
Frequently Asked Questions
Ready to Modernize Your Key Management?
Replace costly HSM infrastructure with DuoKey's Software-Defined HSM.
Support & Resources
Documentation
Professional Services
- Architecture design and review
- Migration from HSM or other KMS
- Performance optimization
- Compliance assistance
Support Channels
- Email: [email protected]
- Portal: support.duokey.com
- Status: status.duokey.com
- Emergency: 24/7 phone support for production issues
Training
- Self-paced online courses
- Live webinars
- On-site training
- Certification program