Platform / Zero Trust Data Encryption

Zero Trust Data Encryption

Every object is its own perimeter.

XQ encrypts data at the object level, on the device or server where it is created, before it ever reaches the cloud. Every file, email, database record and stream segment gets its own AES-256 key, generated at the edge and never exposed to your storage provider.

Built for Security architects replacing provider-managed encryption · Teams keeping regulated data in commercial cloud · Defense and critical-infrastructure programs sharing data with partners

At a glance

ScopeFiles, email, database records and stream segments

CipherAES-256-GCM, crypto-agile

WhereAt the originating endpoint, before upload

KeysOne per object, held outside your storage

Works with AWS S3 · Azure Blob · Microsoft 365 · OneDrive · SharePoint · Google Drive · SQL databases · Kafka

Breaches return ciphertext

A compromised storage account or provider administrator exposes only encrypted objects.

Protection survives sharing

Each object carries its policy with it, so control persists after it is downloaded or forwarded.

No rip and replace

Data stays in the storage you already use; XQ manages keys and policy separately.

Why disk and cloud encryption fall short

In most cloud services the provider manages the encrypted data, the keys and the network access together. One administrative compromise exposes everything, and once data is shared or exfiltrated its owner loses visibility and control. XQ separates storage from access: the data stays where it is, and XQ decides who can read it at the moment they try.

How XQ encrypts data

  • Edge-based encapsulation. Encryption happens on the originating device or local server, before the data touches the cloud.
  • Object-level keys. Unlike disk-level encryption, XQ generates a unique, high-entropy key for every individual object.
  • A policy wrapper. Each object is wrapped in XQ metadata that carries its identity requirements, geofencing and access policy.
  • Decoupled storage. The ciphertext lives in your existing storage, such as S3 or OneDrive; keys and policy are managed outside it.

See object-level encryption on your own data.

Encrypted at rest and in motion

Data is encrypted before it leaves its originating environment, so nothing crosses public infrastructure in plaintext. Data flows are split into discrete channels protected by keys that rotate on a defined schedule, and tunnels terminate only inside XQ Gateway or managed API services.

Part of a complete Zero Trust Data layer

Encryption is the foundation. Externalized key management keeps the keys out of your provider’s hands, dynamic policy enforcement decides who may decrypt, and post-quantum cryptography protects data that must stay secret for years.

Related resources and articles

Zero Trust Data Encryption, answered directly.

How is XQ different from my cloud provider’s encryption?

Provider encryption protects disks, but the provider also holds the keys and controls access, so an administrative or account compromise exposes your data. XQ encrypts each object at the edge with its own key held outside the provider, and releases keys only after a policy check.

Do we have to move our data to use XQ?

No. Encrypted objects stay in your existing storage, such as AWS S3, Azure Blob, OneDrive or SharePoint. XQ manages the keys and access policy separately.

What kinds of data can XQ encrypt?

Files, email, database records and streaming data, through XQ’s Vault, Email, Database Proxy and Streaming Gateway agents, or in your own applications through the XQ API and SDKs.

Is data protected in transit as well as at rest?

Yes. Data is encrypted before it leaves the device or local environment, travels in segmented channels with rotating keys, and stays encrypted wherever it is stored.

Has XQ’s data encryption been validated for federal zero trust architectures?

Yes. AWS validated XQ for the Data pillar of AWS ZTAG-I (Zero Trust Accelerator for Government – Integrated), its reference zero trust architecture for the U.S. federal government. AWS encrypts stored data, while XQ adds encryption for sensitive information and communications, monitors data access, enforces encryption policy and assesses access risk.

Make every object its own perimeter.

See how XQ encrypts your data at the edge — without moving it.