Zero-gate · self-serve · no sales call
Developer Platform
Encryption API and SDKs
Encrypt your first record in 5 minutes.
REST APIs and SDKs for Node, Python, Java, JavaScript and C. Wrap object-level encryption and ZTDF-compliant policy directly into your own application — the same engine that runs the managed platform.
import { XQ } from '@xq/sdk'
const xq = new XQ({ apiKey: process.env.XQ_API_KEY })
const record = await xq.encrypt({
data: file,
policy: { classification: 'CUI', geofence: 'US' },
})
// record.ciphertext travels anywhere — the
// policy travels with it, not your network.
console.log(record.auditId)from xq import Client
xq = Client(api_key=os.environ["XQ_API_KEY"])
record = xq.encrypt(
data=file,
policy={"classification": "CUI", "geofence": "US"},
)
# record.ciphertext travels anywhere — the
# policy travels with it, not your network.
print(record.audit_id)XQClient xq = new XQClient(System.getenv("XQ_API_KEY"));
EncryptedRecord record = xq.encrypt(
file,
Policy.builder().classification("CUI").geofence("US").build()
);
// record.ciphertext() travels anywhere — the
// policy travels with it, not your network.
System.out.println(record.auditId());import { XQ } from '@xq/sdk/browser'
// Short-lived token from your server — never ship an API key to the browser.
const xq = new XQ({ token: await getXQToken() })
const record = await xq.encrypt({
data: fileInput.files[0],
policy: { classification: 'CUI', geofence: 'US' },
})
// Encrypted in the browser, before upload — the
// policy travels with it, not your network.
console.log(record.auditId)#include <xq/xq.h>
xq_client *xq = xq_client_new(getenv("XQ_API_KEY"));
xq_policy policy = { .classification = "CUI", .geofence = "US" };
xq_record *record = xq_encrypt(xq, data, data_len, &policy);
/* record->ciphertext travels anywhere — the
policy travels with it, not your network. */
printf("%s\n", record->audit_id);
xq_record_free(record);
xq_client_free(xq);Quickstart
From zero to encrypted in four steps.
Sign up
Verify your email — no sales call, no procurement form.
Get a key
Instant self-serve API key, scoped to a sandbox environment.
Encrypt
One call wraps your first record in a ZTDF policy envelope.
Verify
Inspect the immutable, HMAC-signed audit object inline.
Reference
Everything you need to build.
FAQ
Build with XQ — the short answers.
Is there a free XQ developer sandbox?
Yes. Signing up gives you an instant self-serve API key scoped to a sandbox environment — no sales call or procurement form required.
Which languages does the XQ SDK support?
Node/TypeScript, Python, Java, JavaScript and C all have first-class SDKs, alongside a REST API for any other language.
Do I need a sales call to get an XQ API key?
No. Create an account at manage.xqmsg.com, verify your email and you get a self-serve sandbox key immediately — the same zero-gate flow described in the Quickstart above.
Does my data pass through XQ when I use the SDK?
No. The SDK encrypts and decrypts locally, in the application or device where the data originates. The XQ API manages keys, policy and identity validation; the backend never touches the data itself.
Can I use the XQ SDK in the browser?
Yes. The JavaScript SDK encrypts data in the browser before upload. Have your server issue a short-lived token for the browser session rather than shipping an API key to the client.
Get your API key.
No sales form, no call required — create your account and start building.