Sovereign Data Capability
Data sovereignty is a first-order priority globally. As nations diversify their economies, adopt artificial intelligence at scale, and treat critical infrastructure as a matter of national security, keeping data access and control local has become essential — it ensures compliance with national law, reduces exposure to external interference, and supports the growth of an indigenous technology sector, all while continuing to leverage global hyperscale infrastructure rather than replacing it.
Not a compliance exercise — control. Two separate exposures exist today: technically, a provider using standard architecture retains the capability to access data it stores; Legally, a provider may be compelled by its home country to provide access to customer data, regardless of where that data is stored. Data residency alone does not eliminate this exposure. Clients require data control: no third party should have technical or legal access to it’s data without explicit authorization.
XQ Sovereign Data Governance is the cryptographic layer that binds sovereignty to the data object itself — not the infrastructure perimeter. This means that exclusive key control and policy enforcement persists for data on cloud services, compute, and storage.
Two deployment options depending on requirements: 1. XQ Zero Trust Data Platform is deployed directly into cloud infrastructure in region; 2. XQ Zero Trust Data Platform is deployed on-prem in region and links to cloud data to remotely enforce data sovereignty.
The selection between them is determined by scale, investment appetite, sovereignty requirements and existing facility infrastructure.
1. THE FUNDAMENTAL DISTINCTION
Conventional approaches to sovereign workloads anchor sovereignty to a physical perimeter or regional deployment: lock the compute into a certified environment, air-gap the network, and trust that physical isolation is sufficient. When the perimeter changes — when workloads migrate to the cloud, when data leaves the network, or when a vendor changes — the sovereignty question must be re-litigated.
XQ Sovereign Data Governance inverts this model. Cryptographic sovereignty is bound to the data and the model artifacts themselves. Exclusive key control means that no infrastructure provider, including cloud, has access to plaintext under any operating condition. The protected payload is the data— not the rack in which it executes.
2. XQ SOVEREIGN DATA GOVERNANCE: CORE CAPABILITY
XQ Sovereign Data Governance provides a Zero Trust Data Overlay (ZTDO) architecture that wraps cryptographic protection around data payloads at the object level.
Encryption keys and access policy are bound to the data itself — nothing leaves the environment until it is already secured, and control remains with the customer in region.
Access can be restricted to authorized users within the region regardless of where the underlying hardware is hosted, and every access — authorized or attempted — is independently logged in real time.
No party outside that key trust boundary — including cloud and any infrastructure operator — can access plaintext.
3. XQ SOVEREIGN DATA GOVERNANCE ACROSS DEPLOYMENT OPTIONS
Regardless of which delivery path the customer selects, XQ Sovereign Data Governance provides the same sovereignty guarantees. The following capabilities are constant across Option A and Option B.
4. ARCHITECTURE: SOVEREIGN CONTROL PLANE
The diagrams below illustrates the sovereign control plane architecture operating inside the cloud and the customer facility. The XQ cryptographic trust boundary is co-located with the accreditation boundary. Data sovereignty is maintained at the object level independent of the physical infrastructure layer. This architecture applies to both Option A and Option B — the difference between the options is the customer’s regulatory need—not the underlying sovereignty model.
Option A – Cloud Only Deployment

Figure 1: XQ Sovereign Control Plane – Cloud Deployment
Architecture Element Legend
Option B – Hybrid Deployment

Figure 2: XQ Sovereign Control Plane – On-Prem + Cloud Deployment
Architecture Element Legend
5. STRATEGIC IMPERATIVE
The strategic imperative is to decouple data sovereignty from cloud infrastructure location. XQ enables cloud customers to keep using cloud’s global cloud services while enforcing where data can be accessed, where keys are held, and who can access it—within or outside a jurisdictional boundary.
- Maintain cloud agility: Avoid creating separate sovereign cloud environments solely to satisfy data residency or sovereignty requirements.
- Control data independently of cloud: Apply persistent encryption, policy, RBAC/ABAC, and geofencing at the data layer.
- Enforce jurisdictional boundaries: Ensure data remains inaccessible when users, workloads, keys, or services operate outside approved jurisdictions.
- Reduce regulatory and geopolitical risk: Support requirements for data residency, localization, national control, and lawful access.
- Enable cross-border operations: Share and process data globally while maintaining jurisdiction-specific access policies.
- Protect data across the lifecycle: Maintain controls as data moves between cloud services, edge environments, SaaS applications, AI systems, and other clouds.
- Avoid cloud lock-in: Make sovereignty controls portable across regions, clouds, edge infrastructure, and hybrid environments.
Frequently asked questions
What is sovereign data governance?
Sovereign data governance means keeping exclusive control over who can access data, and under which jurisdiction, rather than relying on where the data physically sits. XQ Sovereign Data Governance does this with a cryptographic layer bound to the data object itself, so exclusive key control and policy enforcement persist across cloud services, compute and storage, and no third party gains technical or legal access without explicit authorization.
Why isn't data residency alone enough to guarantee data sovereignty?
Data residency alone does not remove two exposures: a provider using standard architecture can technically access the data it stores, and a provider may be legally compelled by its home country to hand over customer data wherever it is stored. XQ addresses both by binding encryption keys and access policy to the data, so no infrastructure operator, including the cloud provider, can reach plaintext.
How does XQ enforce data sovereignty while still using hyperscale cloud?
XQ enforces sovereignty through a Zero Trust Data Overlay (ZTDO) architecture that wraps cryptographic protection around each data payload, with keys and policy held by the customer in region. Access can be limited to authorized users inside the region regardless of where hardware is hosted, and every authorized or attempted access is logged in real time. Organizations keep using global cloud services without building separate sovereign cloud environments.
What deployment options does XQ offer for sovereign data control?
XQ offers two deployment options: the XQ Zero Trust Data Platform deployed directly into cloud infrastructure in region, or deployed on-premises in region and linked to cloud data to enforce sovereignty remotely. The choice depends on scale, investment appetite, sovereignty requirements and existing facilities. Both options provide the same sovereignty guarantees, because the cryptographic trust boundary is tied to the data rather than the infrastructure.
How is data-centric sovereignty different from perimeter-based sovereign cloud?
Perimeter-based sovereignty anchors control to a certified environment or air-gapped network, so it must be re-examined whenever workloads migrate, data leaves the network or a vendor changes. XQ inverts this model by binding cryptographic sovereignty to the data and model artifacts themselves. Controls such as persistent encryption, RBAC/ABAC and geofencing travel with the data across clouds, edge, SaaS and AI systems, which also reduces cloud lock-in.