Independent Key Custody

Independent Key Custody for the Cloud.

Alcazarix holds the encryption keys that protect your data outside your cloud provider's reach. HSM-backed, jurisdictionally separated key custody, natively integrated with AWS KMS, Azure Key Vault, and Google Cloud KMS.

Independent of every cloud providerAWS · Azure · Google Cloud

Why Alcazarix

Your cloud shouldn't hold both your data and your keys

Alcazarix is an independent key broker. We hold and govern encryption keys — no cloud business, no appliance business, no sprawling security suite. Just custody you can verify.

Independent by Design

Your cloud provider stores encrypted data but never your keys. Alcazarix holds your keys but never your data. Neither party alone can read anything.

Native to AWS, Azure, and Google Cloud

Direct integration with AWS KMS External Key Store (XKS), Azure Key Vault Managed HSM BYOK, and Google Cloud KMS EKM. No application changes and no key handling in your code.

Jurisdictional Separation, on Paper

Key custody is operated by separate legal entities — Alcazarix, Inc. from data centers in Canada for North America, and the separately owned Alcazarix Europe B.V. from data centers in Germany for Europe. Our Trust & Custody page shows exactly who owns and controls what.

A Focused Alternative to Legacy Vendors

Teams switch to Alcazarix from Thales DPoD and Fortanix DSM for transparent, usage-based pricing and a product that does one thing well without paying very high prices for a suite of capabilities they don't need.

Built for Regulated Teams

Healthcare and clinical trial platforms, financial services teams working under DORA, and any SaaS serving EU customers. Meet regulator and enterprise-customer expectations without slowing engineering down.

Enterprise-Grade Controls

SOC 2 Type II and ISO27001 aligned security controls, HSM-backed key generation, detailed audit trails, role-based access control, and SLA-backed availability.

Use Cases

One custodian, many reasons to hold your own keys

Wherever your data lives in AWS, Azure, or Google Cloud, independent key custody turns encryption from a checkbox into real control.

Offer Key Ownership to Your Customers

Your enterprise customers demand CMEK or BYOK before they sign. Deliver it through Alcazarix instead of building a key-management practice yourself — your customers own their keys, your team keeps shipping product.

European Data Sovereignty

Make EU personal data on US clouds defensible. Keys held in Germany by a separately owned European entity give your Schrems II and GDPR story a concrete technical and legal anchor.

Cloud Exit & Concentration Risk

Regulators increasingly expect credible cloud exit plans. Externally held keys are a control you can point to in an audit — and quiet leverage at every contract renewal.

Incident Response & Crypto-Shredding

Revoke key access in minutes to render cloud data unreadable during a breach or vendor dispute. Retire data permanently with cryptographic erasure that supports GDPR deletion obligations.

AI Without Surrendering Your Data

Training corpora, vector stores, and inference logs are still your data. Keep them encrypted under keys your AI and cloud vendors never hold.

One Key Authority Across Clouds

Replace three divergent native KMS configurations with a single custodian, one policy model, and one audit trail across AWS, Azure, and Google Cloud.

Compliance

Designed for Jurisdictional Control, Not Just Encryption

Alcazarix enables true external key ownership by separating encryption key generation, storage, and governance from hyperscaler infrastructure — so no single company, and no single jurisdiction, controls both your data and the keys that unlock it. This architectural separation helps organizations address Schrems II, GDPR data sovereignty, and cross-border access concerns without abandoning cloud-native services.

Services

Managed Key Custody with Encryption Keys You Own and Control

Alcazarix provides independent key custody as a managed service, allowing customers to retain full ownership and control of encryption keys used in cloud environments.

Customer-Controlled Key Management

Alcazarix operates a highly available, HSM-backed key management service that integrates directly with cloud provider KMS platforms, keeping your keys entirely under your control.

  • HSM-generated and protected master keys
  • Secure key storage and lifecycle management
  • Key activation, rotation, suspension, and revocation
  • Customer-defined access and governance controls

Cloud KMS Integrations

Native BYOK support for leading cloud providers with jurisdictionally isolated key operations.

  • AWS KMS External Key Store (XKS) compatibility
  • Azure Key Vault Managed HSM BYOK
  • Google Cloud KMS EKM integration

Governance & Auditability

Alcazarix provides the visibility and controls required for regulated environments.

  • Detailed key usage logs
  • Administrative action auditing
  • Role-based access control
  • Exportable audit data for compliance reviews

High Availability & Resilience

Our service is designed to meet the availability expectations of cloud-native workloads.

  • Redundant HSM-backed infrastructure
  • Geographic separation options
  • Fault-tolerant key access architecture
  • SLA-backed uptime

Onboarding & Support

We work directly with customer security and platform teams to ensure smooth deployment.

  • Architecture review and integration guidance
  • BYOK configuration support
  • Migration support from Thales DPoD and Fortanix DSM
  • Direct access to technical experts

Key Custody

Key management infrastructure and dedicated key operations API owned by separate entities.

  • Key custody in North America located in Alcazarix data centers in Canada, controlled by Alcazarix, Inc.
  • Key custody in Europe located in Alcazarix data centers in Germany, controlled by the separately owned Alcazarix Europe B.V.

Trust & Custody

Who actually holds your keys?

At Alcazarix, custody is an ownership architecture, not a promise — separate legal entities, separate jurisdictions, and control boundaries you can show your counsel.

Resources

Whitepapers & Guides

In-depth technical guides for security architects, CISOs, and platform engineers navigating data sovereignty and encryption key governance.

FAQ

Questions security teams ask us

The questions that come up in every architecture review, answered plainly.

Can Alcazarix read my data?

No. Alcazarix holds encryption keys and performs key operations, but your data never passes through our infrastructure. Your cloud provider holds your encrypted data but never your keys. Neither party alone can decrypt anything.

Is Alcazarix FIPS 140 certified?

No, and this is a deliberate choice rather than an omission. Our HSM-backed platform focuses on the controls that decide real-world outcomes for external key management — key ownership, access governance, auditability, and resilience — without the cost and rigidity FIPS certification imposes. If your procurement process strictly requires FIPS-certified key custody, we may not be the right fit, and we'll tell you so early.

How does your structure relate to laws like the US CLOUD Act?

We describe our corporate and operational structure precisely and factually — which entities exist, who owns them, and what each one controls — on our Trust & Custody page, and we make our custody dossier available to your counsel under NDA. We don't make categorical legal claims on your behalf; we give your legal team the facts they need to reach their own conclusions.

What happens to my keys if Alcazarix ceases operations?

Key custody runs on redundant, HSM-backed infrastructure operated by separate entities in separate jurisdictions, and you retain the ability to rotate or revoke keys at any time. Documented continuity and exit procedures are part of our onboarding — ask us for the continuity documentation during your evaluation.

We're on Thales DPoD or Fortanix DSM today. How hard is switching?

Several of our customers made exactly that move. We provide architecture review, a migration plan for re-wrapping or rotating keys onto Alcazarix custody, and a free 30-day proof of concept so you can validate the integration before committing.

What does it cost?

Pricing is usage-based and transparent — no appliance counts, no capacity tiers, no suite bundling. Talk to sales for a quote, or start with the free 30-day proof of concept.

Get in Touch

Contact Us

Have questions? We'd love to hear from you.