Solutions / Defense & Sovereignty
Share mission data with allies without surrendering sovereignty.
XQ lets defense organizations, coalition partners and the Defense Industrial Base share sensitive data without giving up control: each nation, agency or partner holds its own key authority, CUI is protected at the data-object level, and policy keeps being enforced even in disconnected environments at the tactical edge.
Built for NATO, FVEY and coalition partners · Defense and intelligence agencies · Defense Industrial Base contractors
At a glance
Built forCoalitions, agencies and the Defense Industrial Base
Key authorityMulti-KAS — each party holds its own keys
EdgeDDIL-ready, sub-10ms decrypt latency offline
StandardsACP 240, ZTDF, CMMC 2.0, ITAR, DoD IL4/IL5
Works with GDIT · CGI · AWS · Microsoft
Share with allies, keep sovereignty
Each nation or agency holds its own key authority and can revoke any partner’s access in real time.
Protect CUI across the supply chain
Enforce CMMC and DFARS requirements at the data-object level, wherever CUI flows.
Operate at the tactical edge
Policy enforcement keeps running in disconnected, intermittent and limited-bandwidth environments.
The problem: sharing means losing control
Coalition operations depend on sharing data across nations, agencies and classification levels — yet each party must keep control of its own information, even after it has been shared with allies. At the same time, CUI moves through primes, subcontractors and commercial clouds where perimeter controls no longer reach.
How XQ works for defense and coalition missions
| Capability | What it does |
|---|---|
| Multi-KAS architecture | Each nation, agency or partner runs its own key access service, so sharing never means handing over your keys. |
| Standards-based data envelopes | Data is wrapped in ZTDF / TDF-compliant objects that carry their own policy, aligned with ACP 240 data-centric security. |
| Real-time revocation | Withdraw any partner’s access to any object instantly, wherever the data has travelled. |
| DDIL operation | Policy enforcement continues offline at the tactical edge, with sub-10ms decrypt latency. |
| AI classification | CUI categories are labeled automatically at ingestion and mapped to NIST SP 800-171 controls. |
| Cross-boundary audit | A full audit trail spans organizational and coalition boundaries. |
Designing a coalition or cross-domain sharing architecture?
Mission use cases
- Bi-directional coalition sharing with sovereign key control.
- Cross-domain data distribution at different classification levels.
- CUI protection across the Defense Industrial Base supply chain — see CMMC 2.0.
- Sensor and platform data at the disconnected tactical edge.
- Export-controlled technical data — see ITAR.
Standards and compliance
- CMMC 2.0 Level 2 / Level 3
- NIST SP 800-171
- ITAR / EAR
- DFARS 252.204-7012
- ACP 240 and NATO STANAG
- ZTDF / TDF standard
- DoD IL4 / IL5
- Validated for the Data pillar of AWS ZTAG-I, the AWS Zero Trust Accelerator for Government – Integrated reference architecture
Related resources and articles
- How XQ Delivers on ACP 240
- ITAR and CMMC Level 2 on GCC Moderate: Implementation Plan
- From Sovereign Trust to Sovereign Data: How XQ Enables Resilient Defense Ecosystems
- Why Data Sovereignty Matters More Than the AI Model — and What It Means for the Enterprise
- XQ Sovereign Data Governance
- From Policy to Practice: Operationalizing Data Sovereignty Through Zero Trust
FAQ
Defense & Sovereignty, answered directly.
What is XQ’s Multi-KAS architecture?
Multi-KAS (multiple key access services) lets each nation, agency or partner operate its own key authority. Shared data stays encrypted, and each party controls access to its own information — including revoking it in real time.
How does XQ support ACP 240 coalition data sharing?
XQ wraps data in ZTDF / TDF-compliant objects that carry their own classification, policy and metadata, as ACP 240 data-centric security requires. Its Multi-KAS architecture lets each nation, agency or coalition partner hold its own key authority, enabling bi-directional sharing with sovereign key control and real-time access revocation for any partner.
Does XQ help defense contractors meet CMMC 2.0 Level 2 and Level 3?
Yes. XQ enforces the data-level safeguards CMMC 2.0 and DFARS 252.204-7012 depend on — object-level encryption of CUI, access control evaluated at decryption and a complete audit trail — so CUI stays protected wherever it lives and flows, including in disconnected, tactical-edge environments.
Does XQ work in disconnected (DDIL) environments?
Yes. Policy enforcement keeps running offline at the tactical edge, with sub-10ms decrypt latency, and synchronizes when connectivity returns.
Has AWS validated XQ for zero trust in government?
Yes. AWS validated XQ for the Data pillar of AWS ZTAG-I (Zero Trust Accelerator for Government – Integrated), AWS’s reference zero trust architecture for the US federal government. In the combined solution, AWS encrypts stored data while XQ adds encryption for sensitive information and communications, monitors data access, enforces encryption policies and assesses access risk.
Share with allies. Keep control.
Request a briefing on sovereign, coalition-ready data protection for your mission.