Resources / Glossary
Zero Trust Data glossary.
Plain-language definitions of the security, compliance and cryptography terms used in zero trust data protection — from ABAC and ACP 240 to ZTDF and ZTNA — with links to how XQ applies each one.
Jump to a letter
A B C D F G H I K M N O P R S T Z
A
ABAC (attribute-based access control)
An authorization model that grants or denies access by evaluating attributes of the subject (the user or service, such as department or clearance), the object (the data’s sensitivity, labels and tags), the action (read, edit, share) and the environment (location, device, time) against policy rules. Unlike role-based access control, which relies on static roles and tends toward role explosion, ABAC is fine-grained and context-aware, and a policy written for a tag applies automatically to every object that carries it. XQ evaluates ABAC policy each time protected data is opened. Platform capabilities →
ACP 240
Allied Communications Publication 240, the Five Eyes (CCEB) standard for data-centric security when sharing information among allies — how data is labeled, bound to its metadata and protected, including the Zero Trust Data Format (ZTDF). ACP 240 →
AES-256-GCM
The Advanced Encryption Standard with a 256-bit key in Galois/Counter Mode — authenticated encryption that provides both confidentiality and integrity. XQ encrypts every object with it.
B
BYOK / HYOK
Bring Your Own Key and Hold Your Own Key. With BYOK the customer supplies keys that a provider then uses; with HYOK the customer keeps keys outside the provider entirely. XQ supports customer-controlled key stores on-premises, in the cloud or in an HSM. Platform capabilities →
C
C3PAO
A Certified Third-Party Assessor Organization, authorized to conduct CMMC Level 2 certification assessments of defense contractors. CMMC 2.0 →
CEF (Common Event Format)
A standard log format that SIEM systems ingest. XQ audit events are SIEM-ready in CEF.
Chain of custody
A complete, tamper-evident record of who accessed, moved or changed a piece of data, when and from where. XQ records it for every protected object with HMAC-signed logs.
CMMC
The Cybersecurity Maturity Model Certification — the Department of Defense program (32 CFR Part 170) that verifies how defense contractors protect FCI and CUI, across three levels. CMMC 2.0 compliance →
Crypto-shredding
Making data permanently unreadable by revoking or destroying its encryption keys instead of deleting every copy — useful for erasure requests and data in backups. GDPR right to erasure →
CUI (Controlled Unclassified Information)
Information the U.S. government creates or possesses that requires safeguarding under law, regulation or policy but is not classified. Contractors handling it must protect it to NIST SP 800-171. NIST SP 800-171 →
D
Data residency
A requirement that data be stored or processed in a specific country or region. GDPR and data residency →
Data sovereignty
The principle that data is subject to the laws of the place it is collected or stored — and, in practice, keeping control over who (including foreign authorities and providers) can access it. Defense & Sovereignty →
Data-centric security
An approach that protects the data itself — with encryption, labels and policy — rather than relying only on the networks, devices and applications around it. Zero Trust Data →
DDIL
Denied, disrupted, intermittent and limited-bandwidth environments — conditions at the tactical edge where connectivity can’t be assumed. XQ keeps policy enforcement running offline. Defense & Sovereignty →
DFARS 252.204-7012
The Defense Federal Acquisition Regulation Supplement clause that requires contractors to safeguard covered defense information using NIST SP 800-171 and to report cyber incidents to the DoD within 72 hours. CMMC 2.0 →
DLP (data loss prevention)
Tools and policies that detect and stop sensitive data from leaving authorized hands. Zero Trust Data DLP keeps protecting data after it leaves the network. XQ DLP →
DSPM (data security posture management)
Discovering where sensitive data lives across clouds and SaaS, who can access it and how exposed it is. XQ DLP & DSPM →
F
FCI (Federal Contract Information)
Information provided by or generated for the U.S. government under a contract that is not intended for public release. Protecting it is the focus of CMMC Level 1. CMMC 2.0 →
FIPS 140
The NIST standard for validating cryptographic modules; FIPS 140-3 supersedes FIPS 140-2. Many U.S. government and CJIS requirements call for FIPS-validated cryptography.
G
Geofencing
Restricting access to data based on where the request comes from. XQ geolocates each access request and can block decryption outside approved jurisdictions. ITAR →
H
HMAC
A hash-based message authentication code — a keyed hash that proves a message or log entry has not been altered. XQ signs its audit logs with HMAC.
I
IL4 / IL5
Department of Defense cloud Impact Levels: IL4 covers CUI, and IL5 covers higher-sensitivity CUI and unclassified National Security Systems.
ITAR
The International Traffic in Arms Regulations (22 CFR Parts 120–130), which control defense articles and technical data on the U.S. Munitions List. ITAR compliance →
K
KAS (key access service)
The service that holds encryption keys and releases them only when an object’s access policy is satisfied — the core of TDF and ZTDF architectures.
M
Multi-KAS
An architecture in which several independent key access services — one per nation, agency or partner — each control access to their own data, so sharing never means handing over keys. Defense & Sovereignty →
N
NIST SP 800-171
The NIST publication that sets the security requirements for protecting CUI in nonfederal systems; CMMC Level 2 assesses against its 110 requirements. NIST SP 800-171 compliance →
O
Object-level encryption
Encrypting each file, email, record or packet individually, with its own key, so protection travels with the object instead of the storage it sits in. Zero Trust Data →
P
PDP (policy decision point)
In NIST SP 800-207 zero trust architecture, the component that decides whether a request for access is allowed. In XQ, the policy engine acts as the PDP, evaluating attribute-based rules before it releases a key for a data object. Zero Trust AI →
PEP (policy enforcement point)
The component that carries out an access decision. XQ binds a micro-PEP to each payload — an encrypted envelope that enforces policy wherever the data travels, rather than only at a network gateway. Zero Trust AI →
PHI (protected health information)
Individually identifiable health information held by HIPAA covered entities and business associates. HIPAA compliance →
PII (personally identifiable information)
Information that can identify a specific person, such as a name combined with a date of birth, a Social Security number or an email address. Free Governance Scanner →
Post-quantum cryptography
Encryption and signature algorithms designed to resist attacks by future quantum computers. NIST has standardized post-quantum algorithms, including one derived from CRYSTALS-Dilithium, which XQ uses to protect long-lived data against “harvest now, decrypt later” attacks.
Purview sensitivity labels (MIP)
Microsoft Purview Information Protection labels that classify and protect content in Microsoft 365. XQ applies them automatically and enforces them beyond Microsoft. XQ + Microsoft Purview →
R
RAG (retrieval-augmented generation)
An AI pattern that retrieves documents or passages from your own data and passes them to a language model as context. Without data-level access control, RAG can surface restricted content to users who are not authorized to see it. Zero Trust AI →
RBAC (role-based access control)
Granting access based on a user’s role in the organization. Simple to start with, but static: each new combination of access needs another role. XQ uses roles as one input alongside attribute-based policy (see ABAC).
S
Shadow AI
Use of AI tools and models without IT approval, which risks sensitive data reaching unauthorized systems. AI Governance →
SIEM
Security information and event management — systems such as Splunk and QRadar that collect and analyze security events. XQ exports access logs to them.
STANAG
A NATO Standardization Agreement. STANAG 4774 (confidentiality metadata labels) and STANAG 4778 (binding metadata to data) underpin labeling in data-centric security. Defense & Sovereignty →
T
TDF (Trusted Data Format)
An open data format that wraps a data object with its encryption and access policy so the protection travels with it.
Z
Zero trust
A security model — “never trust, always verify” — in which no user, device or network is trusted by default and every access is verified, as described in NIST SP 800-207. Zero Trust Data →
Zero Trust AI
Zero Trust Data powered by AI: AI discovers and classifies sensitive data, adapts access to real-time context and keeps enterprise AI from retrieving data a user is not authorized to see, while per-object encryption and policy enforce each decision. What is Zero Trust AI? →
Zero Trust Data
A security model that makes each piece of data its own security boundary: classified, encrypted with its own key and bound to an access policy checked every time it is opened. What is Zero Trust Data? →
ZTDF (Zero Trust Data Format)
The data format specified in ACP 240 that packages data with its labels, access policy and encryption so it can be shared securely across nations and systems. Defense & Sovereignty →
ZTNA (zero trust network access)
Technology that grants users access to specific applications after verifying identity and device, commonly replacing VPNs. It protects access to systems, not data once it is shared. Zero Trust Data vs. ZTNA →
Related resources and articles
Put the terms into practice.
Talk to our team about protecting your data to the standards above.