Platform / Gateway
XQ Secure Gateway
Zero Trust protection for data in motion.
XQ Secure Gateway encrypts data streams before they leave the device and carries them over any network — public, contested or satellite. It layers onto existing infrastructure as a software alternative to site-to-site VPNs, MACsec and IPsec, gives every packet a key you control, and runs on hardware as small as a Raspberry Pi.
Built for OT and network engineers in critical infrastructure · Teams moving data from on-premises to AWS, Azure or Google Cloud · Defense and edge programs on contested networks
At a glance
ReplacesSite-to-site VPN, MACsec and IPsec links
TrafficTCP/UDP streams, VLAN tagging and IP routing
Runs onLinux on ARM or x86-64 — Ubuntu, CentOS, Red Hat, Pi OS
ManagedWeb portal: status, traffic, logs, remote start/stop
Works with Ubuntu · CentOS · Red Hat · Raspberry Pi OS · Ubiquiti UniFi · AWS · Azure · Google Cloud · MQTT
Protect data before it moves
Streams are encrypted at the source and stay encrypted across every hop.
Retire brittle VPN tunnels
Layer on software instead of hardware appliances and site-to-site VPN configuration.
Keep a leash on every packet
Per-packet keys in an external key store let you cut off access at any time.
Why network tunnels aren’t enough
VPNs and link encryption protect the pipe, not the data: traffic is decrypted at each end and exposed wherever it lands. OT networks add another problem — secure remote access and cloud transfer for ICS systems usually mean costly physical segmentation at every layer. XQ Secure Gateway protects the data itself.
How XQ Secure Gateway works
- Trusted devices send traffic through the gateway, which encrypts it before it leaves and decrypts it only at an authorized destination.
- Dynamic packet micro-segmentation: keys live in an external key store you control, with configurable key recycling.
- Handles multiple TCP/UDP connections, devices and team settings from a single unit, with VLAN tagging and IP-based routing.
- Each gateway synchronizes with an XQ backend — hosted, or your own deployment.
- Managed from the gateway portal: status, ingested traffic and logs per gateway, trusted IP ranges for automatic onboarding, and remote start, stop and restart.
Planning an OT-to-cloud or site-to-site replacement?
Where it’s used
| Use case | What XQ Secure Gateway does |
|---|---|
| Site-to-site links | Replaces site-to-site VPNs with a Zero Trust secure connection. |
| OT to cloud | Two-way MQTT security across Purdue levels, PLC/RTU certificate replacement, and ICS data transfer to the cloud over contested networks. |
| Hybrid and multi-cloud | Connects on-premises systems with AWS, Azure and Google Cloud with a complete audit trail. |
| Migrations and APIs | Dynamic credential rotation keeps migrations and API traffic governed and stops credential reuse. |
| Streams and services | Secure file transfer, media streaming, URL hosting and intranet bridging across networks. |
Deploy it on what you have
XQ Secure Gateway has been tested on Ubuntu, CentOS, Red Hat and Pi OS, on ARM and x86-64 chipsets, and can run in a container on a Ubiquiti UniFi UDM Pro. The deployment guides below walk through setup end to end.
Related resources and articles
- IT/OT & Critical Infrastructure solutions
- IT/OT Operational Intelligence guide
- Deployment of XQ’s Zero Trust Secure Gateway on Ubiquiti UniFi UDM Pro
- Transfer: XQ Zero Trust Data Protection Gateway – Part 2
- Transfer: XQ Zero Trust Data Protection Gateway – Part 1
- Alternative methods for Cybersecurity: Zero-Trust Gateway
FAQ
XQ Secure Gateway, answered directly.
Is XQ Secure Gateway a VPN?
No. A VPN protects a tunnel; XQ Secure Gateway encrypts the data itself before it leaves the device, with keys you control, so it stays protected across every network it crosses. It is often used to replace site-to-site VPNs.
What hardware does XQ Secure Gateway need?
It is software that runs on most modern Linux distributions — tested on Ubuntu, CentOS, Red Hat and Pi OS — on ARM or x86-64, from a Raspberry Pi up, including in a container on a Ubiquiti UniFi UDM Pro.
Can XQ Secure Gateway protect OT and ICS traffic?
Yes. It secures two-way MQTT across Purdue levels, replaces PLC/RTU x509 certificates, and moves ICS data to the cloud over contested networks without physical segmentation at each layer.
How are gateways managed?
From the XQ gateway portal: create gateways and routes, set trusted IP ranges, view status, traffic and logs, and remotely start, stop or restart each gateway.
Who controls the keys for Gateway traffic?
You control the keys. They live in an external key store with configurable key recycling, and each gateway synchronizes with an XQ backend that XQ hosts or that you deploy yourself, so you can cut off access at any time.
Protect data in motion, on any network.
Talk to an engineer about replacing VPN tunnels and securing OT-to-cloud traffic.