Platform / Vault
XQ Vault
File storage where the policy travels with every file.
XQ Vault is secure file storage with persistent, data-bound access policy. Every file is classified, encrypted with its own key and tracked, so you always know who accessed what, where and when — across OneDrive, SharePoint, Google Drive, AWS S3, Azure and on-premises storage — and stolen files stay unreadable.
Built for IT and security leaders storing regulated files in the cloud · Defense contractors keeping CUI in Microsoft 365 · Finance, healthcare and legal teams with sensitive documents
At a glance
GovernsOneDrive, SharePoint, Google Drive, Box, Dropbox, S3, Azure Blob
ControlsRBAC, ABAC, geofencing and revocation per file
IdentityMicrosoft Entra and Okta security groups
RansomwareDetection, forensics and extortion protection
Works with Microsoft 365 · SharePoint · OneDrive · Google Drive · Box · Dropbox · AWS S3 · Azure Blob · Okta · Splunk
Know who touched every file
Data access governance with full classification and traceability — who, what, where and when.
Make stolen files worthless
Each file is encrypted separately; revoke its key and exfiltrated copies turn to digital dust.
Stay in your own tenant
Govern files where they already live, including CUI in commercial Microsoft 365.
Why files need their own protection
Cloud storage permissions stop at the folder. Once a file is downloaded, synced or shared, those controls no longer apply — and a breached account or ransomware crew gets everything the account could see. XQ Vault moves the control into each file.
What XQ Vault does
| Capability | What it does |
|---|---|
| Data access governance | Classifies files and records who accessed each one, from where and when, in a single-pane-of-glass console. |
| Per-file encryption | Every file gets its own key, held outside the storage provider; access is decided by policy when the file is opened. |
| Granular permissions | Role-based administration and policy control for labeling, data localization and contextual access, tied to Microsoft and Okta security groups. |
| Data sovereignty | Geofencing and data localization keep files readable only in approved regions. |
| Record-level DLP | Tracks sensitive data down to the record, aligned with NIST standards. |
| Ransomware defense | Behavioral and signature-based monitoring catches suspicious activity; audit trails speed forensics; encryption blocks extortion. |
| No storage limits | No file-size or storage caps beyond your own infrastructure; syncs with S3, Azure Blob, OneDrive, Google Drive and more. |
See how Vault would govern the files you already store.
Built for regulated data
XQ Vault helps organizations meet CMMC Level 2, ITAR, GDPR, HIPAA, CCPA, FINRA and FISMA requirements in Microsoft 365, Azure and AWS. It works alongside the Zero Trust tools you already run, such as Zscaler, Okta, CrowdStrike and Splunk.
Proven with classified data
In Data Squared’s reView platform for government and defense, XQ Vault encrypts classified intelligence data stored in Amazon S3, restricts access by classification label and user clearance, and lets administrators revoke access retroactively when a threat is detected.
Related resources and articles
- How XQ Protects Your Files from Ransomware Extortion | Zero Trust Data Security
- Data²s reView: AI Analytics for Government & Defense Powered by XQ Vault
- Healthcare CISOs’ Ransomware Extortion Crisis
- Titan Cloud Storage Partners with XQ Message to Deliver Industry’s First Zero Trust by Default Cloud Storage Solution
FAQ
XQ Vault, answered directly.
Where can XQ Vault govern files?
In Microsoft OneDrive and SharePoint, Google Drive, Box, Dropbox, AWS S3, Azure Blob, Google Cloud and Linux or on-premises storage — without moving files to a new repository.
How does XQ Vault protect against ransomware extortion?
Every file is encrypted with its own key held outside your storage. Attackers who copy files get ciphertext, and revoking the keys makes exfiltrated copies unreadable; monitoring and audit trails speed detection and forensics.
Can we keep CUI in commercial Microsoft 365 with XQ Vault?
Yes. XQ governs CUI inside your existing tenant with per-file encryption, access policy and audit, as an alternative to moving to GCC High. XQ never has your CUI.
Does XQ Vault integrate with our identity provider?
Yes. XQ works with any OIDC or SAML 2.0 identity provider, including Microsoft Entra ID, Okta and Ping / PingFederate. Vault access policies can use Entra ID and Okta security groups, with role-based administration for billing, access control and more.
Is there a desktop app for XQ Vault?
Yes. The Vault desktop app installs on Windows (vault-setup.exe) and macOS (vault-setup.pkg) from the Download Vault page, xqmsg.co/vault-download. A Vault license is required; see pricing at manage.xqmsg.com/pricing.
Govern every file, everywhere it’s stored.
See how XQ Vault protects the files you already have — without migrating them.