Platform / Database Governance

Database governance

Encrypt every sensitive record, no code changes.

XQ Database Governance encrypts sensitive database columns, rows and cells with unique keys and policies — without changing application code. Middleware between your application server and database adds classification, role-based access, geofencing, data loss prevention and a forensic chain of custody, with encryption keys held outside your cloud provider.

Built for Application and data owners in regulated industries · Teams storing PII, PHI or CUI in cloud databases · SaaS builders who need tenant-grade data isolation

At a glance

EncryptsColumns, rows and cells, each with its own key

Code changesNone — middleware between app and database

CompatibleMySQL

KeysSplit-knowledge external key management

Works with MySQL · AWS · Azure · On-premises · Snowflake

Protect records without rewrites

Encrypt sensitive fields without touching application code.

Keep keys away from the cloud

External key management means your cloud provider never holds the keys.

Prove who touched each record

A forensic chain of custody records every access and change.

Why databases need record-level protection

Database permissions are all-or-nothing at the table or schema, and a stolen credential or backup exposes everything. Cloud providers that manage your encryption also hold your keys. XQ gives every sensitive record its own protection and moves key custody outside the cloud.

How it works

  • Middleware sits between the application server and the database and manages the interaction with the XQ backend.
  • Sensitive data in columns, rows and cells is encrypted with unique keys and policies, without application code changes.
  • Records inherit the XQ platform: strong encryption, automated key management, access control, sovereignty and logging.
  • External Key Management stores keys in in-country data centers, operated outside AWS, Azure or your on-premises platform, so providers cannot access them.

Want to see record-level encryption on your own schema?

Features

FeatureWhat it does
Split-knowledge key controlsKey knowledge is distributed across multiple entities, so there is no single point of compromise.
Data labeling and classificationTags data by sensitivity, compliance requirement and policy for granular control.
Role-based access controlOnly authorized roles can view, modify or interact with specific data.
Forensic chain of custodyAn immutable record of access and changes for audits and investigations.
Data loss preventionPolicies that prevent exfiltration, leakage and misuse.
Data access geofencingRestricts access by geography to meet data sovereignty rules.

Compliance

Record-level encryption, access control and audit help align database workloads with GDPR, CCPA, CMMC, FINRA, PCI and HIPAA requirements.

Related resources and articles

Database governance, answered directly.

Do we need to change application code?

No. XQ’s middleware sits between your application server and database and encrypts and decrypts records transparently.

Which databases are supported?

XQ Database Governance is MySQL compatible; contact us about other databases and data warehouses such as Snowflake.

Who holds the encryption keys?

Keys are managed outside your cloud or on-premises platform with split-knowledge controls, in in-country data centers, so the database host and cloud provider never have them.

Can we restrict access by geography?

Yes. Data access geofencing enforces where records can be decrypted, supporting data sovereignty requirements.

Can we prove who accessed or changed a record?

Yes. A forensic chain of custody keeps an immutable record of every access and change, for audits and investigations.

Protect every sensitive record.

Talk to a specialist about record-level encryption and external key custody for your databases.