Platform / Governance Scanner

XQ Governance Scanner

From “what do we have?” to enforced policy.

The XQ Governance Scanner finds sensitive data — PII, PHI and CUI — across Google Drive, SharePoint, Outlook and uploaded files, scores the risk, and uses AI to generate the classification labels, access tags and governance policies to protect it. Approved policies go straight to the XQ platform for encryption and enforcement. Start with a free instant scan, no account required.

Built for Compliance and security leads who need to know what data they have · Agencies and enterprises preparing CJIS, CMMC, HIPAA or GDPR programs · Microsoft Purview teams with unlabeled or overexposed data

At a glance

ScansGoogle Drive, SharePoint, Outlook, files and folders — including text in images

FindsPII, PHI and CUI, scored 0–100 for risk

GeneratesSensitivity labels, ABAC tags, governance and DLP policies

Maps toCMMC, HIPAA, GDPR, NIST, ITAR, ISO 27001, ACP 240

Works with Google Drive · SharePoint · Outlook · Microsoft Entra ID · Microsoft Purview · XQ platform

See what you actually have

An inventory of sensitive data, where it lives and how exposed it is — including data nobody knew about.

Get policies, not just findings

AI drafts labels, access tags and governance rules from what it finds, for your data stewards to approve.

Protect it in one step

Quarantine high-risk files or send them to XQ for encryption and enforcement.

Two ways to start

Free instant scanGovernance Scanner for your repositories
SourcesFiles and folders you drop inGoogle Drive, SharePoint and Outlook, plus uploads
AccountNone requiredConnected to your identity and XQ account
OutputSensitive files found, data distribution, compliance postureRisk scores, labels, ABAC tags, generated policies, audit trail
ProtectionGuidance on next stepsQuarantine, XQ encryption and policy enforcement
LimitsPublic demo: 5 files a day, 5 MB each; analyzed by a third-party AI modelSized to your environment

Want to see what’s in your own files first?

What the Governance Scanner does

  • Multi-source scanning: connect Google Drive, SharePoint and Outlook, or scan files and whole folder trees; OCR extracts text from images (PNG, JPEG) so screenshots and scans are checked too.
  • AI classification: every file gets a sensitivity label — Public, Internal, Confidential or Restricted — and a 0–100 risk score based on how much sensitive data it holds and how sensitive it is.
  • ABAC tagging: access tags are generated automatically for region (data residency), minimum role, data type and required access level.
  • Compliance mapping: findings map to GDPR, HIPAA, NIST, MITRE, ITAR, ISO 27001 and more.
  • Policy generation: governance policies are drafted from the risks found and pushed to the XQ platform for enforcement.
  • Data steward review: approve or override any AI classification before it takes effect.
  • Protection: one-click quarantine for high-risk files, and XQ encryption for sensitive assets.
  • Dashboard, audit and DSAR: executive metrics on risk and protection coverage, an immutable log of every governance action, and a portal for finding a data subject’s records.

How a deployment runs

A state department of corrections used this approach to cut the time from data discovery to policy to enforcement, starting with Microsoft SharePoint:

PhaseWhat happens
1. DiscoverScan one or two high-value SharePoint sites and file shares for CUI, PII, PHI, CJIS-related data, legal records and inmate records; flag policy gaps and overexposure.
2. Generate policyDraft classification schemas, labeling policies, RBAC/ABAC access controls and DLP rules aligned to CJIS, NIST, state requirements and the department’s own operations.
3. Label and protectApply persistent metadata tags and encryption by sensitivity and usage context, so protection holds wherever files are stored or shared.
4. EnforceEnforce access restrictions, sharing controls, geofencing and conditional access through the existing identity system — optionally pushing labels and policies into Microsoft Purview.
5. ExpandRoll out repository by repository, with continuous AI-driven policy tuning and automated response to new data risks.

Success is measured the way governance teams measure it: the share of data assets classified, previously unknown sensitive data found, manual classification and policy effort removed, over-permissioned data reduced, and alignment with CJIS and NIST controls.

Related resources and articles

Governance Scanner, answered directly.

Is there a free version?

Yes. The public Governance Scanner is free with no account required: drop up to 5 files a day, 5 MB each, and see what sensitive data they hold. The public demo analyzes content with a third-party AI model, so use non-production files.

Which repositories can it scan?

Google Drive, Microsoft SharePoint and Outlook, plus files and folders you upload — including text inside images through OCR.

What does it do with what it finds?

It labels each file, scores its risk, generates access tags and governance policies, and lets you quarantine files or send them to the XQ platform for encryption and enforcement — after a data steward approves.

Does it work with Microsoft Purview?

Yes. Generated labels, classifications and policies can be pushed into Purview so enforcement aligns with your Microsoft controls; see XQ + Microsoft Purview.

Can it help with data subject access requests?

Yes. The DSAR portal searches the governance index for a specific person’s data, so you can locate records across connected sources.

Which compliance frameworks do findings map to?

Findings map to frameworks including CMMC, HIPAA, GDPR, NIST, ITAR, ISO 27001, ACP 240 and MITRE, so you can see your compliance posture as well as the sensitive data itself.

Find it, classify it, protect it.

Start with a free scan, or talk to us about scanning your SharePoint, Drive and Outlook.