Independent by Design
Your cloud provider stores encrypted data but never your keys. Alcazarix holds your keys but never your data. Neither party alone can read anything.
Independent Key Custody
Alcazarix holds the encryption keys that protect your data outside your cloud provider's reach. HSM-backed, jurisdictionally separated key custody, natively integrated with AWS KMS, Azure Key Vault, and Google Cloud KMS.
Why Alcazarix
Alcazarix is an independent key broker. We hold and govern encryption keys — no cloud business, no appliance business, no sprawling security suite. Just custody you can verify.
Your cloud provider stores encrypted data but never your keys. Alcazarix holds your keys but never your data. Neither party alone can read anything.
Direct integration with AWS KMS External Key Store (XKS), Azure Key Vault Managed HSM BYOK, and Google Cloud KMS EKM. No application changes and no key handling in your code.
Key custody is operated by separate legal entities — Alcazarix, Inc. from data centers in Canada for North America, and the separately owned Alcazarix Europe B.V. from data centers in Germany for Europe. Our Trust & Custody page shows exactly who owns and controls what.
Teams switch to Alcazarix from Thales DPoD and Fortanix DSM for transparent, usage-based pricing and a product that does one thing well without paying very high prices for a suite of capabilities they don't need.
Healthcare and clinical trial platforms, financial services teams working under DORA, and any SaaS serving EU customers. Meet regulator and enterprise-customer expectations without slowing engineering down.
SOC 2 Type II and ISO27001 aligned security controls, HSM-backed key generation, detailed audit trails, role-based access control, and SLA-backed availability.
Use Cases
Wherever your data lives in AWS, Azure, or Google Cloud, independent key custody turns encryption from a checkbox into real control.
Your enterprise customers demand CMEK or BYOK before they sign. Deliver it through Alcazarix instead of building a key-management practice yourself — your customers own their keys, your team keeps shipping product.
Make EU personal data on US clouds defensible. Keys held in Germany by a separately owned European entity give your Schrems II and GDPR story a concrete technical and legal anchor.
Regulators increasingly expect credible cloud exit plans. Externally held keys are a control you can point to in an audit — and quiet leverage at every contract renewal.
Revoke key access in minutes to render cloud data unreadable during a breach or vendor dispute. Retire data permanently with cryptographic erasure that supports GDPR deletion obligations.
Training corpora, vector stores, and inference logs are still your data. Keep them encrypted under keys your AI and cloud vendors never hold.
Replace three divergent native KMS configurations with a single custodian, one policy model, and one audit trail across AWS, Azure, and Google Cloud.
Compliance
Alcazarix enables true external key ownership by separating encryption key generation, storage, and governance from hyperscaler infrastructure — so no single company, and no single jurisdiction, controls both your data and the keys that unlock it. This architectural separation helps organizations address Schrems II, GDPR data sovereignty, and cross-border access concerns without abandoning cloud-native services.
Services
Alcazarix provides independent key custody as a managed service, allowing customers to retain full ownership and control of encryption keys used in cloud environments.
Alcazarix operates a highly available, HSM-backed key management service that integrates directly with cloud provider KMS platforms, keeping your keys entirely under your control.
Native BYOK support for leading cloud providers with jurisdictionally isolated key operations.
Alcazarix provides the visibility and controls required for regulated environments.
Our service is designed to meet the availability expectations of cloud-native workloads.
We work directly with customer security and platform teams to ensure smooth deployment.
Key management infrastructure and dedicated key operations API owned by separate entities.
Resources
In-depth technical guides for security architects, CISOs, and platform engineers navigating data sovereignty and encryption key governance.



FAQ
The questions that come up in every architecture review, answered plainly.
No. Alcazarix holds encryption keys and performs key operations, but your data never passes through our infrastructure. Your cloud provider holds your encrypted data but never your keys. Neither party alone can decrypt anything.
No, and this is a deliberate choice rather than an omission. Our HSM-backed platform focuses on the controls that decide real-world outcomes for external key management — key ownership, access governance, auditability, and resilience — without the cost and rigidity FIPS certification imposes. If your procurement process strictly requires FIPS-certified key custody, we may not be the right fit, and we'll tell you so early.
We describe our corporate and operational structure precisely and factually — which entities exist, who owns them, and what each one controls — on our Trust & Custody page, and we make our custody dossier available to your counsel under NDA. We don't make categorical legal claims on your behalf; we give your legal team the facts they need to reach their own conclusions.
Key custody runs on redundant, HSM-backed infrastructure operated by separate entities in separate jurisdictions, and you retain the ability to rotate or revoke keys at any time. Documented continuity and exit procedures are part of our onboarding — ask us for the continuity documentation during your evaluation.
Several of our customers made exactly that move. We provide architecture review, a migration plan for re-wrapping or rotating keys onto Alcazarix custody, and a free 30-day proof of concept so you can validate the integration before committing.
Pricing is usage-based and transparent — no appliance counts, no capacity tiers, no suite bundling. Talk to sales for a quote, or start with the free 30-day proof of concept.
Get in Touch
Have questions? We'd love to hear from you.