Platform / Database Governance
Database governance
Encrypt every sensitive record, no code changes.
XQ Database Governance encrypts sensitive database columns, rows and cells with unique keys and policies — without changing application code. Middleware between your application server and database adds classification, role-based access, geofencing, data loss prevention and a forensic chain of custody, with encryption keys held outside your cloud provider.
Built for Application and data owners in regulated industries · Teams storing PII, PHI or CUI in cloud databases · SaaS builders who need tenant-grade data isolation
At a glance
EncryptsColumns, rows and cells, each with its own key
Code changesNone — middleware between app and database
CompatibleMySQL
KeysSplit-knowledge external key management
Works with MySQL · AWS · Azure · On-premises · Snowflake
Protect records without rewrites
Encrypt sensitive fields without touching application code.
Keep keys away from the cloud
External key management means your cloud provider never holds the keys.
Prove who touched each record
A forensic chain of custody records every access and change.
Why databases need record-level protection
Database permissions are all-or-nothing at the table or schema, and a stolen credential or backup exposes everything. Cloud providers that manage your encryption also hold your keys. XQ gives every sensitive record its own protection and moves key custody outside the cloud.
How it works
- Middleware sits between the application server and the database and manages the interaction with the XQ backend.
- Sensitive data in columns, rows and cells is encrypted with unique keys and policies, without application code changes.
- Records inherit the XQ platform: strong encryption, automated key management, access control, sovereignty and logging.
- External Key Management stores keys in in-country data centers, operated outside AWS, Azure or your on-premises platform, so providers cannot access them.
Want to see record-level encryption on your own schema?
Features
| Feature | What it does |
|---|---|
| Split-knowledge key controls | Key knowledge is distributed across multiple entities, so there is no single point of compromise. |
| Data labeling and classification | Tags data by sensitivity, compliance requirement and policy for granular control. |
| Role-based access control | Only authorized roles can view, modify or interact with specific data. |
| Forensic chain of custody | An immutable record of access and changes for audits and investigations. |
| Data loss prevention | Policies that prevent exfiltration, leakage and misuse. |
| Data access geofencing | Restricts access by geography to meet data sovereignty rules. |
Compliance
Record-level encryption, access control and audit help align database workloads with GDPR, CCPA, CMMC, FINRA, PCI and HIPAA requirements.
Related resources and articles
FAQ
Database governance, answered directly.
Do we need to change application code?
No. XQ’s middleware sits between your application server and database and encrypts and decrypts records transparently.
Which databases are supported?
XQ Database Governance is MySQL compatible; contact us about other databases and data warehouses such as Snowflake.
Who holds the encryption keys?
Keys are managed outside your cloud or on-premises platform with split-knowledge controls, in in-country data centers, so the database host and cloud provider never have them.
Can we restrict access by geography?
Yes. Data access geofencing enforces where records can be decrypted, supporting data sovereignty requirements.
Can we prove who accessed or changed a record?
Yes. A forensic chain of custody keeps an immutable record of every access and change, for audits and investigations.
Protect every sensitive record.
Talk to a specialist about record-level encryption and external key custody for your databases.