Platform / DLP & DSPM

DLP & DSPM

Data loss prevention that goes where Purview can’t.

XQ’s independent data loss prevention and data security posture management engine mirrors and extends Microsoft Purview beyond the Microsoft perimeter. It enforces block download, block external sharing, geofencing, MFA gating, session expiry and screenshot prevention — wherever your data goes.

Built for Microsoft 365 customers with data outside Microsoft · Security teams replacing network-bound DLP · Organizations sharing sensitive data with third parties

At a glance

ControlsBlock download and sharing, MFA gating, session expiry

PostureContinuous data posture across clouds

ReachBeyond the Microsoft perimeter

LabelsMirrors Microsoft Purview

Works with Microsoft Purview · Microsoft 365 · Google Workspace · Box · AWS · Azure · Google Cloud

One policy across clouds

The same DLP rules apply in Microsoft 365, other SaaS and every major cloud.

Controls that survive sharing

Restrictions stay on the data after it leaves your tenant.

See your data posture

Know where sensitive data lives and whether it’s protected.

The Purview gap

Microsoft Purview labels and policies work well inside Microsoft 365. But data moves to Google Workspace, Box, AWS, partner tenants and personal devices, and there Purview’s controls stop. XQ mirrors Purview’s policies in its own engine and enforces them on the data itself, so protection doesn’t depend on where the file ends up.

What XQ enforces

ControlWhat it does
Block downloadLets users view protected data without saving a local copy.
Block external sharingStops protected data from being opened by recipients outside approved groups.
GeofencingAllows access only from approved countries or regions.
MFA gatingRequires multi-factor authentication before sensitive data opens.
Session expiryEnds access automatically after a set time.
Screenshot preventionBlocks screen capture of protected content.

See DLP that follows your data beyond Microsoft.

Posture you can see

Data security posture management means knowing where sensitive data lives, how it’s classified and whether it’s protected. XQ validates data posture continuously across your environments, using the same AI-powered classification that drives protection — and the free Governance Scanner shows you a sample in minutes.

Go deeper

See how XQ DLP is packaged on the DLP product page, and how it complements Microsoft on XQ + Microsoft Purview.

Related resources and articles

DLP and DSPM, answered directly.

Does XQ replace Microsoft Purview?

No. XQ mirrors and extends Purview: your Purview labels and policies keep working in Microsoft 365, and XQ enforces them on the data beyond the Microsoft perimeter.

What is DSPM?

Data security posture management: continuously knowing where sensitive data lives, how it’s classified and whether it’s protected. XQ combines it with enforcement, so findings become protection.

Which controls can XQ enforce on shared data?

Block download, block external sharing, geofencing, MFA gating, session expiry and screenshot prevention — on the data itself, wherever it goes.

How is XQ different from network DLP?

Network DLP inspects traffic at your perimeter and loses control once data leaves. XQ’s controls are bound to the encrypted data, so they apply in any cloud, tenant or device.

Can XQ detect attempts to exfiltrate protected data?

Yes. Opening protected data requires a key from XQ, so an attempt to decrypt a copy taken out of the authorized environment shows up as a key request from an unexpected identity or location, which is denied and flagged.

Stop data loss beyond the perimeter.

See how XQ extends your DLP policy everywhere data goes.