护词(HuKey)是新一代密钥、证书与密钥全生命周期安全管理平台,基于开源项目 OpenBao 构建,为金融、政企与云原生场景提供统一的机密与证书治理能力,从根源上消除静态密钥与过期证书带来的安全风险。 HuKey is a next-generation platform for secrets, certificate, and key lifecycle security. Built on the open-source OpenBao project, it gives finance, government, and cloud-native teams unified governance over every secret and certificate — eliminating the risk of static credentials and expired certificates at the source.
从生成、存储、分发到轮换、吊销与审计,HuKey 提供统一、可组合的安全能力。From generation and storage to distribution, rotation, revocation, and audit — HuKey delivers unified, composable security capabilities.
按需生成数据库、云平台、SSH 等临时凭据,到期自动吊销,杜绝长期静态密钥带来的泄露风险。Generate ephemeral credentials for databases, cloud platforms, and SSH on demand — automatically revoked on expiry to eliminate long-lived static secrets.
内置多级 CA 体系,覆盖证书申请、签发、部署、轮换与吊销全流程,避免证书过期导致的服务中断。A built-in multi-tier CA hierarchy covers issuance, deployment, rotation, and revocation — preventing outages caused by expired certificates.
无需管理密钥即可为应用提供加解密、签名与验签能力,敏感数据全程不落地明文。Give applications encryption, signing, and verification without ever handling raw key material — sensitive data never touches plaintext at rest.
融合多云、多系统身份源,基于精细化 ACL 策略统一授权,消除身份蔓延带来的权限盲区。Unify identities across clouds and systems with fine-grained ACL policies — closing the blind spots created by identity sprawl.
支持密钥、凭据与证书的定时或事件驱动轮换,结合 API 与 CLI 融入 CI/CD 流水线。Scheduled or event-driven rotation for keys, credentials, and certificates — integrated into CI/CD pipelines via API and CLI.
完整记录每一次访问、签发与吊销行为,满足等级保护、审计与合规追溯要求。A complete audit trail of every access, issuance, and revocation event — supporting compliance and regulatory traceability.
HuKey 在开源 OpenBao 内核之上构建了面向企业的管理平面、合规能力与本地化交付方案,兼顾开放透明与生产级稳定性。HuKey layers an enterprise management plane, compliance tooling, and localized delivery on top of the open-source OpenBao core — combining transparency with production-grade stability.
大模型与自动化 Agent 正在成为新的"特权用户"——它们调用工具、访问数据、与其他 Agent 协作决策。HuKey 作为统一的令牌保险库,为每一个 LLM、Agent 与工具调用颁发并托管身份凭据,无论是 A2A(Agent-to-Agent)协作还是工具调用(Tool Calling)场景,都能做到可信、可控、可审计。LLMs and autonomous agents are becoming a new class of privileged user — calling tools, accessing data, and coordinating with other agents. HuKey acts as a unified token vault, issuing and custodying identity credentials for every LLM, agent, and tool call — so A2A (agent-to-agent) collaboration and tool-calling stay trusted, controlled, and auditable.
从金融到政企、从电信到云原生,HuKey 提供贴合场景的落地方案。From finance to government, telecom to cloud-native — HuKey adapts to how each industry actually operates.
满足金融行业密钥管理与交易签名的高可用、高合规要求。Meets the high-availability and compliance bar for key management and transaction signing in finance.
支持信创环境私有化部署,满足数据不出域与国产化要求。On-premises deployment for Xinchuang environments, meeting data-sovereignty and localization requirements.
与 Kubernetes、CI/CD 流水线深度集成,密钥即代码、机密不落盘。Deep integration with Kubernetes and CI/CD pipelines — secrets as code, never written to disk.
大规模终端与网元证书的集中签发、轮换与生命周期管理。Centralized issuance, rotation, and lifecycle management for certificates across massive device and network-element fleets.
HuKey 与领先的技术与咨询伙伴合作,为企业客户提供更完整的安全与数字化能力。HuKey works with leading technology and consulting partners to give enterprise customers a more complete security and digital capability.

成立于 2000 年的全球数字化转型咨询公司,在香港、洛杉矶与上海设有枢纽,专注云计算、数据分析、生成式 AI 与网络安全,服务全球企业客户。Founded in 2000, KBQuest is a global digital transformation consulting firm with hubs in Hong Kong, Los Angeles, and Shanghai — focused on cloud, analytics, generative AI, and cybersecurity for enterprise clients worldwide.
加入 HuKey 合作伙伴生态,与我们共同拓展市场、服务更多企业客户。Join the HuKey partner ecosystem and grow the market together with us.
"引入 HuKey 后,我们将证书过期引发的生产事故降为零,密钥轮换从人工操作变成了全自动流程。" "After adopting HuKey, certificate-expiry incidents in production dropped to zero, and key rotation went from a manual chore to a fully automated process."
以下为规划中的认证与评测事项,具体进度以官方发布为准。Certifications and evaluations below are on our roadmap — refer to official announcements for current status.
作为一家专注软件与软件支持服务的公司,我们承诺:针对中危(Medium)及以上级别的 CVE 漏洞,为所有客户在一个季度内提供修复方案。As a company focused on software and software support, we commit to delivering a fix for every CVE rated Medium or above, for all clients, within one quarter.
预约一次演示,了解 HuKey 如何在两周内完成私有化部署与首批业务接入。Book a demo to see how HuKey can be deployed on-premises and integrated with your first workloads within two weeks.