Solutions / AI Governance
Adopt AI without losing control of your data.
XQ keeps sensitive data under your control as AI adoption accelerates. It sits between your data and your AI systems, blocks regulated data from reaching unauthorized models, extends Microsoft Purview labels beyond the Microsoft perimeter, keeps encryption keys out of cloud providers’ hands, and logs every AI access with signed, immutable records.
Built for CISOs and CDOs in financial services, healthcare and government · Microsoft 365 and Purview customers rolling out AI · Teams deploying agentic AI workflows
At a glance
Built forRegulated enterprises adopting AI
ControlsWhat data reaches which model, agent or cloud
IntegratesMicrosoft Purview labels, beyond Microsoft
KeysCustomer-managed — never the cloud provider’s KMS
Works with Microsoft Purview · Microsoft 365 · AWS · Azure · Google Cloud · Snowflake · Scale AI
Stop sensitive data reaching unauthorized AI
Policy is enforced at every AI interaction, before data ever reaches a model.
Extend Purview beyond Microsoft
Sensitivity labels and DLP follow data into non-Microsoft apps, devices and AI systems.
Take your keys back
Encrypt before upload with customer-managed keys that cloud providers never hold.
The AI data risk
As AI adoption accelerates, so does the risk of sensitive data flowing into unauthorized models, AI-generated documents and autonomous agents — and every cloud provider promises security while still holding your keys. Governing AI means governing the data it can reach.
How XQ governs data used by AI
| Capability | What it does |
|---|---|
| LLM exposure prevention | Blocks sensitive data from reaching unauthorized large language models. |
| Agentic DLP | Governs AI-generated documents and outputs, and enforces data-loss prevention for autonomous AI workflows. |
| Purview label sync | Bi-directional sync enforces AIP/MIP sensitivity labels in non-Microsoft apps and AI systems. |
| Customer-managed keys | Encrypts before upload to any cloud, with keys you control — never the provider’s KMS. |
| Residency for AI workloads | Enforces where data can be processed, by geography. |
| Signed audit | Records every AI access event in immutable, signed logs. |
| Least-privilege remediation | Maps the blast radius of sensitive data across nested groups and sharing links, and revokes stale or excessive access without breaking workflows. |
| DSAR automation | Locates, exports or flags records tied to a data subject across every connected source. |
Want to see where sensitive data meets your AI tools today?
Safe Copilot and RAG adoption
Employees using Copilots and internal RAG applications can bypass access controls and expose restricted data through prompt outputs. XQ enforces data-level policies inside the retrieval pipeline, checking document- and chunk-level permissions before any context reaches the model — so each user only gets answers built from data they are authorized to see. It works alongside Microsoft Purview and existing DLP, automating the labels they rely on. This is the AI governance pillar of Zero Trust AI.
Frameworks this supports
Related resources and articles
- Zero Trust Data Governance for AI Agents
- Why Data Sovereignty Matters More Than the AI Model — and What It Means for the Enterprise
- Why XQ and Xage Are Better Together: Extending Zero Trust from Identity to Data and AI
- Infrastructure No Longer Defines Risk: Why AI-Driven Data Exposure Is the New Battleground
- It’s easier than we thought to poison an AI model
FAQ
AI governance, answered directly.
Does XQ integrate with Microsoft Purview?
Yes. XQ syncs bi-directionally with Microsoft Purview, extending sensitivity labels and DLP enforcement beyond the Microsoft perimeter — to unmanaged devices, third-party tools and AI systems Purview alone can’t reach.
How does XQ stop sensitive data from reaching an LLM?
XQ enforces policy at every interaction between your data and AI systems, so regulated or labeled data is blocked from unauthorized models before it is sent.
Do cloud or AI providers ever hold our keys?
No. Data is encrypted before upload with customer-managed keys; providers store and process only what your policy allows them to decrypt.
Can we prove what data an AI system accessed?
Yes. Every AI access event is recorded in signed, immutable logs, so you can show exactly what each model or agent touched.
Does XQ govern autonomous AI agents?
Yes. Agentic DLP applies data-loss prevention to autonomous AI workflows and governs the documents and outputs they generate.
Can Copilot and RAG applications respect our access controls?
Yes. XQ enforces data-level policy inside the retrieval pipeline, checking document- and chunk-level permissions before any context reaches the model, so each user only gets answers built from data they are authorized to see. It works alongside Microsoft Purview and existing DLP.
Govern AI at the data layer.
Book a strategy demo to see where sensitive data meets your AI tools — and how to control it.