Platform / Externalized Key Management

Externalized Key Management

Your keys, never your provider’s.

Whoever holds the keys controls the data. XQ generates keys at the edge and keeps them out of your storage and cloud providers’ hands — in XQ-managed or customer-controlled key stores, on premises, in your own cloud or in an HSM — so access to plaintext stays under your jurisdiction.

Built for Organizations that must keep key custody in their own jurisdiction · Defense and coalition programs sharing data across nations · Regulated teams whose cloud provider must never hold the keys

At a glance

ModelsBYOK and HYOK

Key storesOn-premises, your cloud or HSM

ReleaseOne-time keys, only after a policy check

SharingMulti-KAS across sovereign key stores

Works with On-premises key stores · Hardware security modules · AWS · Microsoft Azure · Google Cloud

Provider compromise exposes nothing

Your storage and cloud providers never hold the keys to your data.

Sovereignty you can prove

Key material stays in the regions and infrastructure you choose.

Share without surrendering control

Partners with their own key stores can exchange data while each keeps its own keys.

Why key custody decides who controls the data

Most cloud encryption leaves the provider holding both the data and the keys, so a single administrative compromise — or a foreign government access request — reaches everything. Organizations relying on hyperscale platforms inherit that jurisdictional exposure. XQ removes it by keeping keys apart from the data and away from the provider.

How XQ handles keys

  • Generated at the edge. Keys are created locally on the endpoint, from high-entropy, quantum-seeded material, before data is encrypted.
  • Held outside storage. Key references live in the XQ platform or in your own external key store, never with the storage provider.
  • Released once, after policy. When someone opens protected data, XQ checks policy and then delivers a one-time decryption key to the requesting agent.
  • Gone after use. Data is decrypted in memory and the key expires when the session ends, leaving nothing on the storage medium.
  • Revocable at any time. Withdraw access and every copy, wherever it is, becomes unreadable — without moving or deleting it.

See where your keys would live with XQ.

Sovereign key stores that can work together

XQ key stores can be private or interoperable. Two organizations, each with its own sovereign XQ key store, can exchange data and request each other’s keys while each keeps control over access. That multi-KAS model supports coalition data sharing and cryptographic separation of tenants and partners on shared infrastructure.

Residency, localization and sovereignty

Because keys are generated and managed at the edge or in customer-controlled stores, keys are never transmitted to or stored in another jurisdiction without policy allowing it. Combined with geofenced key release, that keeps data readable only where regulations allow, supporting GDPR, ITAR and national sovereignty mandates.

Related resources and articles

Externalized key management, answered directly.

Does XQ hold my encryption keys?

You choose. Key references can be held by the XQ platform or in your own external key store, on premises or in your cloud. Either way your storage provider never holds them, and XQ never sees your data.

What is the difference between BYOK and HYOK?

With bring your own key (BYOK), you supply the keys a service uses. With hold your own key (HYOK), keys stay in infrastructure you control and are released only when policy allows. XQ supports both.

Can two organizations share data while keeping separate keys?

Yes. XQ key stores can be interoperable, so partners with their own sovereign key stores can exchange data and request each other’s keys while each keeps control over access.

What happens to a key after data is opened?

XQ releases a one-time key to the requesting agent, the data is decrypted in memory, and the key expires when the session ends.

Can XQ key management run on premises or air-gapped?

Yes. The XQ backend is containerized and deploys in the cloud, on premises — including air-gapped environments with a local database and local entropy — or in a hybrid model that keeps sensitive keys on premises.

What happens if the XQ key database is compromised?

It does not directly expose usable keys. XQ stores only the components needed to reconstruct each key, plus a locator token, and releases key material only after identity and policy checks pass.

Keep your keys under your control.

See how XQ separates key custody from your cloud and storage providers.