Four pillars
Zero Trust Data solutions for defense, critical infrastructure and AI.
From defense coalitions to the plant floor, AI governance to your own codebase — XQ enforces data-layer security across every audience, environment, and regulatory requirement.
Defense & Sovereignty
Share across classification levels without surrendering sovereignty.
Coalition data sharing requires that each party maintains control of their data even when sharing with allies — and CUI must be protected wherever it lives and flows. XQ Multi-KAS architecture lets each nation, agency, or partner hold their own key authority, enforces CMMC and DFARS requirements at the data object level, and keeps policy enforcement running even in disconnected, tactical-edge environments.
Key use cases
- Bi-directional sharing with sovereign key control
- Cross-domain data distribution at different classification levels
- Real-time access revocation for any partner
- DDIL-ready operation at the tactical edge — sub-10ms decrypt latency offline
- Auto-label CUI categories via AI classification, mapped to NIST 800-171 controls
- Full audit trail across organizational and coalition boundaries
Industries
- NATO & Coalition Partners
- FVEY
- Defense & Intelligence
- Defense Industrial Base
- DoD Contractors
Standards & Compliance
ACP 240
NATO STANAG
ZTDF / TDF Standard
CMMC 2.0 L2 / L3
DFARS 252.204-7012
NIST 800-171
ITAR / EAR
DoD IL4 / IL5
IT/OT Industrial Security
Protect the data your plant floor can't afford to lose.
Operational technology environments — power grids, manufacturing lines, industrial control systems — generate sensitive telemetry that traditional IT security was never built to govern. XQ encrypts data at the point of ingestion, enforces policy across the IT/OT boundary, and lets you remotely revoke access to a compromised edge device without ever touching it physically.
Key use cases
- Edge telemetry encryption at the sensor, before it crosses the IT/OT boundary
- ICS/SCADA policy-gated access — historian and control-system data stays governed
- Remote cryptographic revocation of a compromised edge device or gateway
- Trusted AI agent workflows for predictive maintenance and plant-floor automation
- Low-latency enforcement that does not disrupt real-time operational control loops
- Joint IT/OT operational intelligence programs (Phoenix Contact, GDIT)
Industries
- Energy & Utilities
- Manufacturing
- Critical Infrastructure
- Oil & Gas
- Water Systems
Standards & Compliance
NERC CIP
IEC 62443
CISA Guidance
DoD IL4 / IL5
Enterprise AI Governance
Adopt AI without losing control of your data.
As AI adoption accelerates, so does the risk of sensitive data flowing into unauthorized models — and every cloud provider promises security while still holding your keys. XQ sits between your data and your AI systems, enforcing policy at every interaction, extending Microsoft Purview labels beyond the Microsoft perimeter, and moving key authority back to you in every cloud you use.
Key use cases
- Block sensitive data from reaching unauthorized LLMs
- Govern AI-generated documents and outputs; agentic DLP for autonomous AI workflows
- Bi-directional Purview label sync — enforce AIP/MIP labels in non-Microsoft apps and AI systems
- Encrypt before upload to any cloud; customer-managed keys, never cloud KMS
- Enforce data residency for AI workloads and by geography
- Audit every AI access event with signed, immutable logs
- Automated least-privilege remediation — map the exact blast radius of sensitive data across nested groups and sharing links, and revoke stale or excessive access without breaking workflows
- Automated DSAR (Data Subject Access Request) fulfillment — locate, export, or flag records tied to a data subject across every connected source
Industries
- Financial Services
- Healthcare
- Federal Government
- Legal & Professional Services
Standards & Compliance
GDPR
DORA
NIS2
HIPAA
Microsoft Purview / MIP
NIST AI RMF
Developer Platform
Encrypt your first record in under 5 minutes.
XQ ships as embeddable primitives, not just a managed service. REST APIs and SDKs for Node, Python, Java, JavaScript and C let you wrap object-level encryption, policy enforcement, and ZTDF-compliant data envelopes directly into your own application — no infrastructure to stand up, no sales call required to start.
Key use cases
- Drop-in ZTDF wrappers for existing file, email, and database workflows
- Self-serve API key provisioning — start building immediately
- Live sandbox with real request/response cycles across 5 languages
- Embed the same policy engine (RBAC/ABAC/geofencing) used by the managed platform
- Immutable, HMAC-signed audit objects returned inline with every call
Industries
- System Integrators
- ISVs & Platform Builders
- Internal Engineering Teams
Standards & Compliance
ZTDF / TDF
Named Solutions
Already know what you’re looking for? Jump straight there.
Sovereignty
Keep regulated data under your control, cryptographically, regardless of where it is hosted.
Governance Scanner
Free, instant scan for PII, PHI, and CUI exposure — no account required.
Zero Trust Data API
Build Zero Trust data protection directly into your own applications.
Database Governance
Classification, access control, and audit for data at the database layer.
DLP (beyond Purview)
Data-layer loss prevention that does not stop at the tenant boundary.
FAQ
Compliance and coverage, answered directly.
Does XQ help defense contractors meet CMMC 2.0 Level 2 and Level 3?
Yes. XQ enforces the data-level safeguards CMMC 2.0 and DFARS 252.204-7012 depend on — object-level encryption of CUI, access control evaluated at decryption and a complete audit trail — so CUI stays protected wherever it lives and flows, including in disconnected, tactical-edge environments.
How does XQ support ACP 240 coalition data sharing?
XQ's Multi-KAS architecture lets each nation, agency, or coalition partner hold their own key authority, enabling bi-directional sharing with sovereign key control and real-time access revocation for any partner.
Does XQ help meet NERC CIP for critical infrastructure?
Yes. XQ encrypts telemetry at the point of ingestion, enforces policy across the IT/OT boundary, and records the access and revocation logs auditors ask for, supporting NERC CIP, IEC 62443 and CISA guidance. It is a complementary data-layer control and does not replace required CIP network, system and procedural controls.
Does XQ integrate with Microsoft Purview?
Yes. XQ syncs bi-directionally with Microsoft Purview, extending sensitivity labels and DLP enforcement beyond the Microsoft perimeter — to unmanaged devices, third-party tools, and AI systems Purview alone can't reach.
Can we use AWS, Azure or Google Cloud and still meet data sovereignty requirements?
Yes. XQ binds keys and policy to each data object and keeps the keys in your jurisdiction under your exclusive control, with geofenced key release by country or region, so the cloud provider stores encrypted data it cannot read. This applies to commercial organizations under laws such as GDPR, DORA and NIS2 as well as to government and defense.
Regulatory coverage
One platform, every mandate.
CMMC 2.0
ITAR / EAR
ACP 240
DoD IL4 / IL5
NERC CIP
GDPR
DORA
CJIS
DFARS
NIST 800-171
HIPAA
PCI-DSS
NIS2
IEC 62443