Zero Trust Data solutions for defense, critical infrastructure and AI.

From defense coalitions to the plant floor, AI governance to your own codebase — XQ enforces data-layer security across every audience, environment, and regulatory requirement.

Defense & Sovereignty

Share across classification levels without surrendering sovereignty.

Coalition data sharing requires that each party maintains control of their data even when sharing with allies — and CUI must be protected wherever it lives and flows. XQ Multi-KAS architecture lets each nation, agency, or partner hold their own key authority, enforces CMMC and DFARS requirements at the data object level, and keeps policy enforcement running even in disconnected, tactical-edge environments.

Key use cases

  • Bi-directional sharing with sovereign key control
  • Cross-domain data distribution at different classification levels
  • Real-time access revocation for any partner
  • DDIL-ready operation at the tactical edge — sub-10ms decrypt latency offline
  • Auto-label CUI categories via AI classification, mapped to NIST 800-171 controls
  • Full audit trail across organizational and coalition boundaries

Industries

  • NATO & Coalition Partners
  • FVEY
  • Defense & Intelligence
  • Defense Industrial Base
  • DoD Contractors

Standards & Compliance

ACP 240

NATO STANAG

ZTDF / TDF Standard

CMMC 2.0 L2 / L3

DFARS 252.204-7012

NIST 800-171

ITAR / EAR

DoD IL4 / IL5

Already know what you’re looking for? Jump straight there.

Sovereignty

Keep regulated data under your control, cryptographically, regardless of where it is hosted.

Learn more →

Vault

Secure storage with persistent, data-bound access policy.

Learn more →

Gateway

Zero Trust enforcement for OT/edge and satellite connectivity.

Learn more →

Secure Email

Encrypted, policy-governed email that stays governed after delivery.

Learn more →

Governance Scanner

Free, instant scan for PII, PHI, and CUI exposure — no account required.

Learn more →

Zero Trust Data API

Build Zero Trust data protection directly into your own applications.

Learn more →

Database Governance

Classification, access control, and audit for data at the database layer.

Learn more →

DLP (beyond Purview)

Data-layer loss prevention that does not stop at the tenant boundary.

Learn more →

Compliance and coverage, answered directly.

Does XQ help defense contractors meet CMMC 2.0 Level 2 and Level 3?

Yes. XQ enforces the data-level safeguards CMMC 2.0 and DFARS 252.204-7012 depend on — object-level encryption of CUI, access control evaluated at decryption and a complete audit trail — so CUI stays protected wherever it lives and flows, including in disconnected, tactical-edge environments.

How does XQ support ACP 240 coalition data sharing?

XQ's Multi-KAS architecture lets each nation, agency, or coalition partner hold their own key authority, enabling bi-directional sharing with sovereign key control and real-time access revocation for any partner.

Does XQ help meet NERC CIP for critical infrastructure?

Yes. XQ encrypts telemetry at the point of ingestion, enforces policy across the IT/OT boundary, and records the access and revocation logs auditors ask for, supporting NERC CIP, IEC 62443 and CISA guidance. It is a complementary data-layer control and does not replace required CIP network, system and procedural controls.

Does XQ integrate with Microsoft Purview?

Yes. XQ syncs bi-directionally with Microsoft Purview, extending sensitivity labels and DLP enforcement beyond the Microsoft perimeter — to unmanaged devices, third-party tools, and AI systems Purview alone can't reach.

Can we use AWS, Azure or Google Cloud and still meet data sovereignty requirements?

Yes. XQ binds keys and policy to each data object and keeps the keys in your jurisdiction under your exclusive control, with geofenced key release by country or region, so the cloud provider stores encrypted data it cannot read. This applies to commercial organizations under laws such as GDPR, DORA and NIS2 as well as to government and defense.

One platform, every mandate.

DFARS

NIST 800-171

HIPAA

PCI-DSS

NIS2

IEC 62443