Turnkey holds your keys in hosted SaaS. ZeroCopy keeps your keys in your own VPC. The difference is 1,215x in latency and full self-custody.
Modeled improvement. Full benchmark methodology at zerocopy.systems/benchmarks.
| Feature | Turnkey | ZeroCopy Sentinel |
|---|---|---|
| P50 Latency | 75ms | 41µs (target) |
| Key Location | Turnkey infrastructure | Your VPC enclave |
| Signing Traffic | Leaves your network | Stays in your VPC |
| TEE Type | Hosted enclave | AWS Nitro Enclave (your account) |
| SOC 2 Type II | Available | Scheduled Q3 2026 |
| Pricing Model | Per-operation | Fixed annual license |
| Open Source CLI | No | Yes (zcp) |
| Kill Switch | Account-level | Cryptographic fleet revocation |
| Policy Engine | Limited | Declarative Rust rules, hot-reload |
| EC2 Dependency | None (hosted) | c6i/m6i/r6i family with Nitro |
If you need a signing API that requires zero AWS infrastructure management and your strategy can tolerate 75ms signing latency, Turnkey is a reasonable hosted option. It is appropriate for wallets, consumer applications, and low-frequency institutional workflows where speed is not the primary constraint.
If you need sub-millisecond signing, full self-custody, or keys that never leave your VPC, ZeroCopy Sentinel is the right choice.
Migration from Turnkey takes one to two weeks. Parallel deployment, attestation verification, then cutover.