首页Home 产品Product 解决方案Solutions 关于我们About 联系我们Contact
申请演示Request Demo
基于开源项目 OpenBao 构建 Built on the open-source OpenBao project

让每一把密钥、每一张证书
可信、可控、可审计
Make every key and certificate trusted, controlled, and auditable

护词(HuKey)是新一代密钥、证书与密钥全生命周期安全管理平台,基于开源项目 OpenBao 构建,为金融、政企与云原生场景提供统一的机密与证书治理能力,从根源上消除静态密钥与过期证书带来的安全风险。 HuKey is a next-generation platform for secrets, certificate, and key lifecycle security. Built on the open-source OpenBao project, it gives finance, government, and cloud-native teams unified governance over every secret and certificate — eliminating the risk of static credentials and expired certificates at the source.

100K+
托管密钥与证书Secrets & certs under management
99.9%
平台服务可用性Platform service uptime
<30 分钟min
证书批量轮换耗时Bulk certificate rotation time
01 PKI 根证书 · 正常运行PKI Root CA · Active
02 动态凭据 · 自动轮换中Dynamic Credentials · Rotating
03 审计日志 · 已同步Audit Log · Synced
HUKEY / SECRETS-ENGINE / SCHEMATIC-01
受金融、政企与云原生行业客户信赖 Trusted across finance, government & cloud-native industries
国有银行State-Owned Bank 省级政务云Provincial Gov. Cloud 电信运营商Telecom Operator 智能制造集团Manufacturing Group 互联网医疗平台Health-Tech Platform 跨境支付平台Cross-Border Payments
核心能力Core Capabilities

六大核心模块,覆盖机密全生命周期Six core modules, covering the entire secrets lifecycle

从生成、存储、分发到轮换、吊销与审计,HuKey 提供统一、可组合的安全能力。From generation and storage to distribution, rotation, revocation, and audit — HuKey delivers unified, composable security capabilities.

01

动态密钥引擎Dynamic Secrets Engine

按需生成数据库、云平台、SSH 等临时凭据,到期自动吊销,杜绝长期静态密钥带来的泄露风险。Generate ephemeral credentials for databases, cloud platforms, and SSH on demand — automatically revoked on expiry to eliminate long-lived static secrets.

DatabaseCloud IAMSSH
02

证书全生命周期与 PKICertificate Lifecycle & PKI

内置多级 CA 体系,覆盖证书申请、签发、部署、轮换与吊销全流程,避免证书过期导致的服务中断。A built-in multi-tier CA hierarchy covers issuance, deployment, rotation, and revocation — preventing outages caused by expired certificates.

PKICA 管理ACME
03

加密即服务Encryption as a Service

无需管理密钥即可为应用提供加解密、签名与验签能力,敏感数据全程不落地明文。Give applications encryption, signing, and verification without ever handling raw key material — sensitive data never touches plaintext at rest.

SM/RSA/ECC信封加密
04

统一身份与访问控制Unified Identity & Access

融合多云、多系统身份源,基于精细化 ACL 策略统一授权,消除身份蔓延带来的权限盲区。Unify identities across clouds and systems with fine-grained ACL policies — closing the blind spots created by identity sprawl.

RBACSSO 集成
05

轮换与自动化Rotation & Automation

支持密钥、凭据与证书的定时或事件驱动轮换,结合 API 与 CLI 融入 CI/CD 流水线。Scheduled or event-driven rotation for keys, credentials, and certificates — integrated into CI/CD pipelines via API and CLI.

CI/CDAPI

审计与合规Audit & Compliance

完整记录每一次访问、签发与吊销行为,满足等级保护、审计与合规追溯要求。A complete audit trail of every access, issuance, and revocation event — supporting compliance and regulatory traceability.

日志审计合规追溯
架构优势Architecture

为什么选择 HuKeyWhy teams choose HuKey

HuKey 在开源 OpenBao 内核之上构建了面向企业的管理平面、合规能力与本地化交付方案,兼顾开放透明与生产级稳定性。HuKey layers an enterprise management plane, compliance tooling, and localized delivery on top of the open-source OpenBao core — combining transparency with production-grade stability.

  • 基于成熟开源项目 OpenBao,架构透明、社区驱动、无厂商锁定Built on the mature open-source OpenBao project — transparent, community-driven, no vendor lock-in
  • API 与主流 DevOps、云原生工具兼容,平滑对接现有体系API-compatible with mainstream DevOps and cloud-native tooling for smooth integration
  • 支持信创及国产化软硬件环境私有化部署Supports on-premises deployment on domestic ("Xinchuang")-compatible hardware and software
  • 高可用集群部署,数据不出域,满足数据主权要求High-availability clustering keeps data within your domain, meeting data-sovereignty requirements
应用 / 服务Applications / Services
↓ mTLS / Token
HuKey API Gateway统一接入unified ingress
身份认证与 ACL 策略引擎Auth & ACL policy engine
密钥引擎 · PKI 引擎 · 加密引擎Secrets · PKI · Encryption engines
加密存储encrypted at rest
高可用存储集群(私有化 / 混合云)HA storage cluster (on-prem / hybrid cloud)
LLM / Agent 运行时LLM / Agent Runtime
申请令牌requests a token
HuKey 身份令牌引擎HuKey Identity Token Engine颁发永久或一次性令牌issues permanent or one-time tokens
携带令牌调用token-scoped call
工具调用 · 其他 Agent · A2A / MCP 协议Tool calls · other agents · A2A / MCP protocols
全程审计continuously audited
统一身份审计与即时吊销Unified identity audit & instant revocation
AI 安全AI Security

让每一个 AI Agent 都拥有可信身份Give every AI agent a verifiable identity

大模型与自动化 Agent 正在成为新的"特权用户"——它们调用工具、访问数据、与其他 Agent 协作决策。HuKey 作为统一的令牌保险库,为每一个 LLM、Agent 与工具调用颁发并托管身份凭据,无论是 A2A(Agent-to-Agent)协作还是工具调用(Tool Calling)场景,都能做到可信、可控、可审计。LLMs and autonomous agents are becoming a new class of privileged user — calling tools, accessing data, and coordinating with other agents. HuKey acts as a unified token vault, issuing and custodying identity credentials for every LLM, agent, and tool call — so A2A (agent-to-agent) collaboration and tool-calling stay trusted, controlled, and auditable.

  • 支持永久身份令牌与一次性(Just-in-Time)令牌,按场景选择最小权限凭据Issues both permanent identity tokens and one-time, just-in-time tokens — matching credential scope to each scenario's minimum privilege
  • 覆盖 A2A 协作、MCP / 工具调用、RAG 数据访问等主流 Agent 集成模式Covers A2A collaboration, MCP / tool-calling, and RAG data access — the mainstream agent integration patterns
  • 令牌绑定精细化 ACL 与命名空间,防止 Agent 权限蔓延与越权调用Tokens are bound to fine-grained ACLs and namespaces, preventing agent privilege sprawl and out-of-scope calls
  • 完整记录每一次 Agent 身份签发、使用与吊销,满足 AI 治理与审计要求Logs every agent credential issuance, use, and revocation — supporting AI governance and audit requirements
A2A MCP Tool Calling LLM Runtime 一次性令牌One-Time Token
开源,可信赖的基石Open Source, the Trustworthy Foundation

HuKey 的开源内核 OpenBaoPowered by the OpenBao open-source core

6,300+
开源内核 GitHub Stars(OpenBao)Open-source core GitHub stars (OpenBao)
MPL-2.0
开源协议,可审计、无锁定Open-source license, auditable, no lock-in
Linux Foundation
社区治理,非单一厂商控制Community-governed, not single-vendor controlled
100%
API 生态兼容,平滑迁移API-compatible ecosystem, smooth migration
行业解决方案Industry Solutions

面向重点行业的机密安全方案Secrets security built for regulated industries

从金融到政企、从电信到云原生,HuKey 提供贴合场景的落地方案。From finance to government, telecom to cloud-native — HuKey adapts to how each industry actually operates.

金融行业Financial Services

满足金融行业密钥管理与交易签名的高可用、高合规要求。Meets the high-availability and compliance bar for key management and transaction signing in finance.

政企与政务云Government & Public Cloud

支持信创环境私有化部署,满足数据不出域与国产化要求。On-premises deployment for Xinchuang environments, meeting data-sovereignty and localization requirements.

云原生 / DevOpsCloud-Native / DevOps

与 Kubernetes、CI/CD 流水线深度集成,密钥即代码、机密不落盘。Deep integration with Kubernetes and CI/CD pipelines — secrets as code, never written to disk.

电信与运营商Telecom & Carriers

大规模终端与网元证书的集中签发、轮换与生命周期管理。Centralized issuance, rotation, and lifecycle management for certificates across massive device and network-element fleets.

查看完整解决方案View All Solutions
生态合作Partner Ecosystem

携手合作伙伴,共建安全生态Building a security ecosystem with our partners

HuKey 与领先的技术与咨询伙伴合作,为企业客户提供更完整的安全与数字化能力。HuKey works with leading technology and consulting partners to give enterprise customers a more complete security and digital capability.

KBQuest

KBQuest

成立于 2000 年的全球数字化转型咨询公司,在香港、洛杉矶与上海设有枢纽,专注云计算、数据分析、生成式 AI 与网络安全,服务全球企业客户。Founded in 2000, KBQuest is a global digital transformation consulting firm with hubs in Hong Kong, Los Angeles, and Shanghai — focused on cloud, analytics, generative AI, and cybersecurity for enterprise clients worldwide.

  • 联合为企业客户提供云安全与机密管理集成方案Joint cloud security and secrets-management integration for enterprise clients
  • 覆盖香港、洛杉矶与上海市场Coverage across Hong Kong, Los Angeles, and Shanghai

成为合作伙伴Become a Partner

加入 HuKey 合作伙伴生态,与我们共同拓展市场、服务更多企业客户。Join the HuKey partner ecosystem and grow the market together with us.

联系我们Contact Us

"引入 HuKey 后,我们将证书过期引发的生产事故降为零,密钥轮换从人工操作变成了全自动流程。" "After adopting HuKey, certificate-expiry incidents in production dropped to zero, and key rotation went from a manual chore to a fully automated process."

技术负责人Head of Engineering · 某金融科技公司(案例信息已做匿名化处理)A fintech company (anonymized case reference)
安全与合规Security & Compliance

安全能力与合规路径Security capabilities & compliance roadmap

以下为规划中的认证与评测事项,具体进度以官方发布为准。Certifications and evaluations below are on our roadmap — refer to official announcements for current status.

MLPS 等保三级
评测中Under evaluation
信创兼容认证Xinchuang Compatibility
适配中In adaptation
MPL-2.0
开源许可合规Open-source license compliant
<1 季度quarter

CVE 修复承诺CVE Remediation Commitment

作为一家专注软件与软件支持服务的公司,我们承诺:针对中危(Medium)及以上级别的 CVE 漏洞,为所有客户在一个季度内提供修复方案。As a company focused on software and software support, we commit to delivering a fix for every CVE rated Medium or above, for all clients, within one quarter.

准备好重新定义密钥与证书安全了吗?Ready to redefine secrets and certificate security?

预约一次演示,了解 HuKey 如何在两周内完成私有化部署与首批业务接入。Book a demo to see how HuKey can be deployed on-premises and integrated with your first workloads within two weeks.