Platform overview
The XQ Zero Trust Data Governance Platform.
The Zero Trust Data layer behind XQ’s Zero Trust AI: a managed service that enforces security at the data layer — using edge-based encryption, distributed policy enforcement, and externalized key control. Data stays encrypted and under your exclusive control, even in commercial cloud and AI systems.
Encrypt
At the edge, before cloud
Label
AI classification at ingestion
Enforce
Policy at decryption time
Audit
Immutable chain of custody
Core platform
Eight pillars of data sovereignty.
Zero Trust Data Encryption
Object-level, edge-based, pre-cloud encryption. Every file, record, and stream receives a unique AES-256 cryptographic key generated at the edge — never exposed to storage providers.
Learn more
Externalized Key Management
Keys are never held by your storage provider. Customer-controlled key stores (BYOK/HYOK) — on-prem, cloud, or HSM — give you exclusive key sovereignty.
Learn more
AI-Powered Data Classification
Semantic AI classification goes beyond regex to understand context. Automatically labels CUI, PHI, PII, ITAR-controlled, and custom categories across structured and unstructured data.
Learn more
Dynamic Policy Enforcement
RBAC + ABAC with geofencing, device posture, and time-based conditions. Policies are evaluated at decryption time against live conditions — anywhere data travels.
Learn more
AI Governance & Shadow AI Control
Restrict sensitive data from unauthorized AI tools. Govern what LLMs can ingest and automatically protect AI-generated outputs. Agentic DLP for modern AI workflows.
Learn more
Provenance & Audit Trail
Immutable, HMAC-signed audit logs for every access and decryption event. SIEM-ready in CEF format. Full chain of custody from origin to disposition.
Learn more
Post-Quantum Cryptography
NIST-standardized post-quantum algorithms, including Dilithium, protect against harvest-now-decrypt-later attacks. Future-proof your most sensitive long-lived data today.
Learn more
Data Loss Prevention (DLP) & DSPM
Independent DLP/DSPM engine that mirrors and extends Microsoft Purview beyond the Microsoft perimeter. Enforces block download, block external sharing, geofencing, MFA gating, session expiry, and screenshot prevention — wherever your data goes.
Learn more
Platform
Agents that act on your data. Integrations that don't undo your controls.
XQ agents apply policy automatically — classification, key management, and access decisions run without manual intervention. Every integration plugs into the same policy layer, so adding a tool never means opening a gap.
XQ Agents
AI discovery agent: finds PII, PHI and CUI across Google Drive, SharePoint, Outlook and uploaded files, scores the risk, and generates the policies to protect it.
Vault Agent
Transparent encryption for file systems, NAS, and shared drives. Works with any application without code changes.
Email Agent
End-to-end email encryption with automatic classification. Works with Exchange, M365, and Google Workspace.
Database Proxy
Column-level and row-level encryption for SQL and NoSQL databases. Applications see plaintext, storage sees ciphertext.
Streaming Gateway
Real-time encryption for Kafka, Kinesis, and event streams. Zero latency impact on high-throughput pipelines.
Full-featured REST API and SDKs for Node, Python, Java, JavaScript and C. Integrate XQ into any custom application.
Integrations
Cloud
- AWS
- AWS GovCloud
- Azure Gov
- Google Cloud
Productivity
- Microsoft 365
- SharePoint
- Google Workspace
- Box
Identity
- Azure AD / Entra
- Okta
- Ping / PingFederate
- SAML 2.0 / OIDC
Security
- Microsoft Purview
- Microsoft Sentinel
- Splunk / SIEM
- CrowdStrike
Architecture
Zero Trust Network Access secures the door. XQ secures what's inside — permanently.
Traditional Zero Trust Network Access (ZTNA) verifies identity at the network edge, once, per session. The moment a file leaves that boundary — shared with a partner, synced to another cloud, copied to a laptop — the network’s controls stop applying.
XQ moves the enforcement point from the network to the data itself. Every file, record, or message is cryptographically bound to its own identity, access policy, and encryption key at the moment it’s created. The policy travels with the data, and access is evaluated fresh, every time, against the current policy — not a policy that was true when the session started.
A valid credential alone is no longer enough. An attacker — or an over-permissioned employee, or an AI agent — with legitimate network access still can’t open a file whose policy doesn’t grant them access. If a key is revoked, access is cut off instantly, even on a copy that already left the building.
01
Bind
Identity, policy, and encryption attach to the data object at creation.
02
Travel
Policy moves with the object across networks, clouds, and borders — no re-encryption step.
03
Evaluate
Every access request is checked against current policy, in real time, at the point of use.
04
Revoke
The key holder can cut access instantly, cryptographically, even after the data has left the network.
| ZTNA | Traditional DLP / Purview | XQ | |
|---|---|---|---|
| Enforcement point | Network edge | Tenant boundary | The data object itself |
| Survives leaving the network | No | No | Yes, cryptographically |
| Post-exfil visibility | None | None | Full, revocable chain-of-custody |
You control the keys. We never see your data.
Deployment
Deploy where you need it.
XQ operates identically across commercial cloud and the harshest edge environments.
Zero infrastructure overhead
SaaS / Managed
XQ manages the platform; you own the keys. Up and running in hours, not months.
- No infrastructure to manage
- XQ-operated key authority
- Continuous updates and patching
Air-gapped capable
On-Premises
Full deployment within your environment. No external network dependencies. DoD IL5 and classified deployment ready.
- Air-gapped operation
- HSM-backed key stores
- DoD IL5 and classified systems
DDIL-ready
Hybrid & Edge
Disconnected operations, forward edge deployments, and DDIL environments. Same policy engine across every mode.
- DDIL policy caching
- Forward edge deployment
- Automatic sync on reconnection
FAQ
Zero Trust Data, answered directly.
What is the difference between ZTNA and Zero Trust Data?
Zero Trust Network Access (ZTNA) verifies identity once at the network edge; once a file leaves that edge, ZTNA's controls stop applying. XQ's Zero Trust Data instead binds identity, policy, and encryption to the data object itself, so access is re-evaluated every time it's requested — even after the object has left the network.
Can XQ revoke access to a file that already left the network?
Yes. Because the encryption key and access policy are bound to the object rather than the network, the key holder can revoke or update policy at any time — cryptographically, not by a takedown request — even on a copy that already left the building.
Does XQ hold my encryption keys?
You choose, and you control the keys. In the managed service, the XQ-operated key authority stores the material needed to reconstruct each key, never alongside the data; alternatively, keys live in customer-controlled key stores (BYOK/HYOK) — on premises, in your cloud or in an HSM. Either way your storage provider never holds them, and the XQ backend manages only keys and policy, never your data.
Which identity providers and access attributes does XQ support?
XQ works with any OIDC or SAML 2.0 identity provider, including Microsoft Entra ID, Okta and Ping / PingFederate. Policies combine roles (RBAC) with attributes (ABAC) of the user, such as clearance, department or citizenship from your identity provider, of the data, such as its labels, of the action, such as view, download or share, and of the environment, such as location, device posture and time.
Can XQ run on premises or in air-gapped environments?
Yes. XQ runs as a managed SaaS service, fully on premises — including air-gapped operation with HSM-backed key stores — or in hybrid and edge deployments for disconnected (DDIL) operations, with the same policy engine in every mode.