The XQ Zero Trust Data Governance Platform.

The Zero Trust Data layer behind XQ’s Zero Trust AI: a managed service that enforces security at the data layer — using edge-based encryption, distributed policy enforcement, and externalized key control. Data stays encrypted and under your exclusive control, even in commercial cloud and AI systems.

Encrypt

At the edge, before cloud

Label

AI classification at ingestion

Enforce

Policy at decryption time

Audit

Immutable chain of custody

Eight pillars of data sovereignty.

Zero Trust Data Encryption

Object-level, edge-based, pre-cloud encryption. Every file, record, and stream receives a unique AES-256 cryptographic key generated at the edge — never exposed to storage providers.

AES-256-GCM

Post-Quantum

Edge-side keygen

Learn more

Externalized Key Management

Keys are never held by your storage provider. Customer-controlled key stores (BYOK/HYOK) — on-prem, cloud, or HSM — give you exclusive key sovereignty.

BYOK / HYOK

HSM support

Multi-KAS

Learn more

AI-Powered Data Classification

Semantic AI classification goes beyond regex to understand context. Automatically labels CUI, PHI, PII, ITAR-controlled, and custom categories across structured and unstructured data.

Semantic AI

Purview sync

Custom labels

Learn more

Dynamic Policy Enforcement

RBAC + ABAC with geofencing, device posture, and time-based conditions. Policies are evaluated at decryption time against live conditions — anywhere data travels.

RBAC / ABAC

Geofencing

Time-bound

Learn more

AI Governance & Shadow AI Control

Restrict sensitive data from unauthorized AI tools. Govern what LLMs can ingest and automatically protect AI-generated outputs. Agentic DLP for modern AI workflows.

Shadow AI block

Agentic DLP

LLM-agnostic

Learn more

Provenance & Audit Trail

Immutable, HMAC-signed audit logs for every access and decryption event. SIEM-ready in CEF format. Full chain of custody from origin to disposition.

HMAC-signed

CEF / SIEM

Immutable log

Learn more

Post-Quantum Cryptography

NIST-standardized post-quantum algorithms, including Dilithium, protect against harvest-now-decrypt-later attacks. Future-proof your most sensitive long-lived data today.

Dilithium

NIST PQC

Learn more

Data Loss Prevention (DLP) & DSPM

Independent DLP/DSPM engine that mirrors and extends Microsoft Purview beyond the Microsoft perimeter. Enforces block download, block external sharing, geofencing, MFA gating, session expiry, and screenshot prevention — wherever your data goes.

DSPM

Purview gap

Cross-cloud

Learn more

Agents that act on your data. Integrations that don't undo your controls.

XQ agents apply policy automatically — classification, key management, and access decisions run without manual intervention. Every integration plugs into the same policy layer, so adding a tool never means opening a gap.

XQ Agents

Governance Scanner →

AI discovery agent: finds PII, PHI and CUI across Google Drive, SharePoint, Outlook and uploaded files, scores the risk, and generates the policies to protect it.

Vault Agent

Transparent encryption for file systems, NAS, and shared drives. Works with any application without code changes.

Email Agent

End-to-end email encryption with automatic classification. Works with Exchange, M365, and Google Workspace.

Database Proxy

Column-level and row-level encryption for SQL and NoSQL databases. Applications see plaintext, storage sees ciphertext.

Streaming Gateway

Real-time encryption for Kafka, Kinesis, and event streams. Zero latency impact on high-throughput pipelines.

API / SDK →

Full-featured REST API and SDKs for Node, Python, Java, JavaScript and C. Integrate XQ into any custom application.

Integrations

Cloud

  • AWS
  • AWS GovCloud
  • Azure Gov
  • Google Cloud

Productivity

  • Microsoft 365
  • SharePoint
  • Google Workspace
  • Box

Identity

  • Azure AD / Entra
  • Okta
  • Ping / PingFederate
  • SAML 2.0 / OIDC

Security

  • Microsoft Purview
  • Microsoft Sentinel
  • Splunk / SIEM
  • CrowdStrike

Zero Trust Network Access secures the door. XQ secures what's inside — permanently.

Traditional Zero Trust Network Access (ZTNA) verifies identity at the network edge, once, per session. The moment a file leaves that boundary — shared with a partner, synced to another cloud, copied to a laptop — the network’s controls stop applying.

XQ moves the enforcement point from the network to the data itself. Every file, record, or message is cryptographically bound to its own identity, access policy, and encryption key at the moment it’s created. The policy travels with the data, and access is evaluated fresh, every time, against the current policy — not a policy that was true when the session started.

A valid credential alone is no longer enough. An attacker — or an over-permissioned employee, or an AI agent — with legitimate network access still can’t open a file whose policy doesn’t grant them access. If a key is revoked, access is cut off instantly, even on a copy that already left the building.

01

Bind

Identity, policy, and encryption attach to the data object at creation.

02

Travel

Policy moves with the object across networks, clouds, and borders — no re-encryption step.

03

Evaluate

Every access request is checked against current policy, in real time, at the point of use.

04

Revoke

The key holder can cut access instantly, cryptographically, even after the data has left the network.

ZTNATraditional DLP / PurviewXQ
Enforcement pointNetwork edgeTenant boundaryThe data object itself
Survives leaving the networkNoNoYes, cryptographically
Post-exfil visibilityNoneNoneFull, revocable chain-of-custody

You control the keys. We never see your data.

Deploy where you need it.

XQ operates identically across commercial cloud and the harshest edge environments.

Zero infrastructure overhead

SaaS / Managed

XQ manages the platform; you own the keys. Up and running in hours, not months.

  • No infrastructure to manage
  • XQ-operated key authority
  • Continuous updates and patching

Air-gapped capable

On-Premises

Full deployment within your environment. No external network dependencies. DoD IL5 and classified deployment ready.

  • Air-gapped operation
  • HSM-backed key stores
  • DoD IL5 and classified systems

DDIL-ready

Hybrid & Edge

Disconnected operations, forward edge deployments, and DDIL environments. Same policy engine across every mode.

  • DDIL policy caching
  • Forward edge deployment
  • Automatic sync on reconnection

Zero Trust Data, answered directly.

What is the difference between ZTNA and Zero Trust Data?

Zero Trust Network Access (ZTNA) verifies identity once at the network edge; once a file leaves that edge, ZTNA's controls stop applying. XQ's Zero Trust Data instead binds identity, policy, and encryption to the data object itself, so access is re-evaluated every time it's requested — even after the object has left the network.

Can XQ revoke access to a file that already left the network?

Yes. Because the encryption key and access policy are bound to the object rather than the network, the key holder can revoke or update policy at any time — cryptographically, not by a takedown request — even on a copy that already left the building.

Does XQ hold my encryption keys?

You choose, and you control the keys. In the managed service, the XQ-operated key authority stores the material needed to reconstruct each key, never alongside the data; alternatively, keys live in customer-controlled key stores (BYOK/HYOK) — on premises, in your cloud or in an HSM. Either way your storage provider never holds them, and the XQ backend manages only keys and policy, never your data.

Which identity providers and access attributes does XQ support?

XQ works with any OIDC or SAML 2.0 identity provider, including Microsoft Entra ID, Okta and Ping / PingFederate. Policies combine roles (RBAC) with attributes (ABAC) of the user, such as clearance, department or citizenship from your identity provider, of the data, such as its labels, of the action, such as view, download or share, and of the environment, such as location, device posture and time.

Can XQ run on premises or in air-gapped environments?

Yes. XQ runs as a managed SaaS service, fully on premises — including air-gapped operation with HSM-backed key stores — or in hybrid and edge deployments for disconnected (DDIL) operations, with the same policy engine in every mode.

See the architecture in action on your own data.