Platform / Secure Email

XQ Secure Email

Encryption that stays in control after you hit send.

XQ Secure Email encrypts messages and attachments on your device, inside Outlook and Gmail, and keeps them governed after delivery. You can revoke or expire any message, track where attachments are opened, and require recipients to authenticate — without changing email addresses, clients or providers, and without XQ ever holding your content.

Built for Defense contractors emailing CUI from Microsoft 365 · Healthcare, legal and financial teams sending sensitive data · IT leaders fighting business email compromise

At a glance

Works inOutlook (Microsoft 365 E3/E5, Business Premium, GCC, GCC High) and Gmail

After sendingRevoke, expire (six hours to six months), track

ContentEncrypted on the device; XQ never reads it

ComplianceCMMC Level 2, HIPAA, ITAR, GDPR, CCPA, FINRA

Works with Microsoft Outlook · Microsoft 365 · GCC · GCC High · Gmail · Google Workspace · Active Directory

Unsend a mistake

Revoke access to any sent message or attachment — it becomes unreadable instantly.

Shut down email compromise

DLP, role-based access and data sovereignty stop BEC attacks as they happen.

Keep your email as it is

Same addresses, same clients; encrypted content stays in your mail service.

Why email needs data-level protection

Email is where most sensitive data leaves the organization — and where business email compromise, phishing and credential theft start. Transport encryption protects messages only in transit; once delivered, they sit readable in every inbox forever. XQ keeps control of each message and attachment for its whole life.

What XQ Secure Email does

CapabilityWhat it does
Edge encryptionMessages and files are encrypted on your device before they reach the cloud; the encrypted content stays in your existing mail service.
Revoke and expireRevoke any message with one click, or set it to expire from six hours to six months.
Attachment protectionAttachments stay protected in inboxes, desktops, shared folders and Google Drive — and you can track how, when and where they are opened.
Record-level DLPLabels and tracks access to every encrypted message and transfer, for compliance at the finest level.
Role-based accessActive Directory integration applies role-based access control to email data.
Verified channelEncrypted messages establish provenance, helping stop phishing and vendor spoofing.

Want to see revocation and tracking on your own mailbox?

Compliance without changing email

XQ Secure Email governs data access in Microsoft Outlook for Business Premium, E3, E5, GCC and GCC High, and in Gmail — helping organizations meet CMMC Level 2, HIPAA, ITAR, GDPR, CCPA and FINRA requirements while teams keep working as they do today.

Related resources and articles

XQ Secure Email, answered directly.

Does XQ Secure Email work with Outlook and Gmail?

Yes. It works in Microsoft Outlook — including Microsoft 365 Business Premium, E3, E5, GCC and GCC High — and in Gmail, and recipients can read protected messages in any email app.

Can I unsend an email with XQ?

Yes. Revoke access to a sent message or attachment and it is no longer readable by the recipient; you can also set messages to expire automatically.

Does XQ read or store our email?

No. Content is encrypted on your device and stays in your existing mail service. XQ provides the keys and policy logic to encrypt and decrypt, not the content.

How does XQ help stop business email compromise?

Data loss prevention, role-based access control and data sovereignty policies block phishing, credential compromise and vendor spoofing as they happen, and encrypted messages give recipients a verified channel.

Can I track who opens an attachment?

Yes. Attachments stay protected in inboxes, desktops, shared folders and Google Drive, and you can track how, when and where they are opened.

Does XQ Secure Email help meet CMMC and HIPAA requirements?

Yes. It governs data access in Outlook and Gmail with edge encryption, record-level DLP and role-based access, helping organizations meet CMMC Level 2, HIPAA, ITAR, GDPR, CCPA and FINRA requirements without changing how teams use email.

Send sensitive email without losing control.

See revocation, expiry and tracking in your own Outlook or Gmail.