From Sovereign Trust to Sovereign Data: How XQ Enables Resilient Defense Ecosystems
The next frontier of defense cybersecurity is proving control over data
In a recent article, CGI Defense & Intelligence Global Industry Lead Torsten Bernström argues that resilience is no longer simply an operational requirement—it is becoming a sovereign capability.
The argument is particularly relevant as defense organizations move toward highly distributed digital ecosystems spanning enterprise IT, cloud, mission edge, operational technology, coalition partners and multiple national jurisdictions.
CGI calls this emerging requirement “sovereign trust.”
The concept goes beyond traditional cybersecurity and beyond simply knowing where infrastructure is hosted. Sovereign trust requires organizations to continuously demonstrate that systems, data and operations remain within the required boundaries, with the visibility, governance and evidence necessary to prove that control.
That distinction is critical.
A sovereign cloud does not necessarily make the data inside it sovereign.
A zero-trust network does not necessarily provide sovereignty over the data moving across it.
And knowing where data is stored does not necessarily mean knowing who can access it, where it can travel, what it can be used for, or whether access can be revoked when circumstances change.
Sovereignty ultimately has to exist at the data layer.
This is where XQ Message aligns directly with CGI's vision of secure, resilient digital ecosystems.
CGI's five imperatives for sovereign trust
CGI identifies five imperatives for defense organizations:
Continuously verify identities and interactions.
Design data sovereignty into the ecosystem.
Treat cloud and edge as sovereign environments.
Strengthen trust in the software supply chain.
Engineer resilience from the start.
Together, these represent an important evolution from traditional cybersecurity.
The objective is no longer simply to protect the perimeter.
It is to continuously prove control across an interconnected ecosystem.
XQ provides a data-centric security layer that operationalizes this principle.
1. Continuous verification must extend to the data
CGI emphasizes continuously validating users, systems and workloads.
XQ extends that concept to the data itself.
Instead of granting access based solely on network location, application access or static permissions, XQ can apply policy based on attributes such as:
Who is requesting access
What organization they belong to
What role they have
What device or workload is making the request
What classification the data carries
Where the user and data are located
What mission or business context applies
What jurisdiction governs the information
Whether the request remains authorized at that moment
This creates a critical distinction:
Zero Trust asks whether an entity should be trusted.
XQ asks whether that entity should have access to this specific data, under these specific conditions, right now.
The result is a data-level enforcement model using ABAC/RBAC policies that can follow information across applications, clouds, organizations and geographic boundaries.
2. Data sovereignty has to be built into the data
CGI's second imperative is perhaps the most directly aligned with XQ: data sovereignty must be designed into the ecosystem.
CGI states that data needs to remain visible, traceable and governed across organizational boundaries.
That becomes difficult when data crosses:
Government agencies
Defense contractors
Coalition partners
Cloud providers
SaaS platforms
Mission environments
Geographic jurisdictions
IT and OT systems
Traditional security models frequently protect the system surrounding the data.
XQ takes a different approach.
XQ protects the data itself.
Data can be classified, tagged, encrypted and governed according to policy before it moves through the ecosystem. The protection remains associated with the information rather than depending entirely on the security controls of every environment through which the data travels.
This creates what can be thought of as a cryptographic trust boundary around the data.
The organization does not have to assume that every infrastructure provider, application or network along the path is equally trusted.
The data carries its protection with it.
3. Cloud and edge become sovereign environments through data control
Defense architectures are increasingly distributed between centralized cloud environments and mission-edge systems.
CGI argues that cloud and edge need to be treated as sovereign environments, with control, residency and governance designed into the architecture from the beginning.
XQ complements this approach by separating data control from infrastructure control.
This is important because a defense organization may have limited control over the infrastructure where data is processed.
For example, data may move from:
Mission Edge → Tactical Network → Cloud → AI Workload → Coalition Partner → Mission Edge
The infrastructure may change at every step.
The XQ policy governing the data does not have to.
XQ can enforce controls around:
Data classification
Encryption
Identity
Geographic boundaries
Data access
Data sharing
Key ownership
Policy enforcement
Auditability
Revocation
This allows organizations to establish a consistent security and sovereignty model across heterogeneous infrastructure.
In practical terms:
The infrastructure can be distributed.
The policy can remain centralized.
The protection can remain with the data.
4. Sovereignty becomes particularly important for coalition operations
CGI highlights a fundamental challenge in defense environments: the most difficult problem is often not collecting information, but exchanging the right information with the right controls at operational speed.
This is especially important for coalition operations.
A U.S. organization may need to share information with a NATO ally, Five Eyes partner, defense contractor or another government agency without simply handing over unrestricted access to the underlying data.
Traditional approaches often force organizations into a binary choice:
Share the data or don't share the data.
A data-centric architecture creates another option:
Share the data under policy.
For example, a mission could permit a coalition partner to access information classified for a particular mission while restricting:
Which records they can see
Which attributes are visible
Where the data can be accessed
How long access remains valid
Whether the data can be exported
Whether it can be shared further
This is where dynamic policy enforcement becomes particularly powerful.
The objective is not to prevent collaboration.
It is to make controlled collaboration possible.
5. Sovereign trust requires cryptographic control
There is another important distinction between infrastructure sovereignty and data sovereignty.
If an organization relies entirely on the infrastructure provider to enforce access controls, sovereignty ultimately depends on that provider's security architecture and administrative controls.
XQ introduces a different model through customer-controlled cryptographic protection.
Encryption keys can remain under the control of the organization or its designated jurisdictional key infrastructure, while XQ provides the policy and enforcement mechanisms necessary to determine when those keys can be released.
This creates a stronger separation between:
Where the data resides
and
Who controls access to the data.
That distinction becomes increasingly important as governments adopt sovereign-cloud and sovereign-AI architectures.
The cloud can provide the infrastructure.
The customer retains control of the data.
6. AI makes sovereign data control even more important
The emergence of AI and autonomous systems makes CGI's sovereign-trust model even more relevant.
AI systems require access to enormous amounts of data.
But an AI agent should not automatically receive access to everything available to the user, organization or network on which it operates.
An AI workload might legitimately need:
Intelligence reports
Sensor data
Logistics information
Maintenance records
Geospatial information
Mission data
Classified documents
But access needs to be governed according to the mission and the specific data.
XQ can act as a data policy control plane for AI agents, establishing identity and authorization before data is released to an AI workload.
The fundamental principle is:
The AI agent does not inherit unrestricted access to the data simply because the user or application has access to it.
Instead, data access can be evaluated dynamically based on identity, attributes, classification, location, policy and mission context.
This becomes especially important as defense organizations move from AI assistants toward autonomous and agentic systems.
7. From protecting systems to proving control
Perhaps the most important point in CGI's article is the transition from protection to assurance.
CGI argues that resilience is no longer simply about preventing disruption. Organizations must be able to demonstrate continuously that systems and operations remain secure, governed and reliable.
That requires evidence.
XQ's architecture is designed around this same principle.
Every policy decision can become part of an auditable chain of control:
Classify → Protect → Request → Evaluate → Enforce → Audit
This provides organizations with evidence of:
What data was protected
What policy applied
Who requested access
What attributes were evaluated
Whether access was granted or denied
Which key was released
Where access occurred
When access occurred
Whether access was subsequently revoked
This transforms data security from a collection of preventative controls into a continuously verifiable governance system.
XQ + CGI: A complementary architecture for sovereign trust
CGI brings the broader systems-integration, defense, intelligence and digital-transformation capabilities required to build resilient mission ecosystems.
XQ provides a complementary data security and sovereignty layer that can operate across those ecosystems.
CGI Sovereign Trust ImperativeXQ Data-Centric ApproachContinuously verify identities and interactionsIdentity-aware ABAC/RBAC policy enforcementDesign data sovereignty into the ecosystemEncryption, classification, tagging and persistent data controlsTreat cloud and edge as sovereignData protection independent of infrastructure locationStrengthen supply-chain trustData-level controls that reduce reliance on infrastructure trustEngineer resilience from the startDistributed enforcement, customer-controlled keys and policy-driven accessProve control continuouslyAuditable policy decisions, access and cryptographic events
This creates a natural division of responsibility.
CGI can architect and integrate the sovereign digital ecosystem.
XQ can provide the data control layer that protects the information flowing through it.
Sovereignty at the data layer
CGI's article makes an important observation: sovereignty cannot be reduced to where infrastructure is located or who owns it.
Sovereignty must be continuously demonstrated across a distributed ecosystem.
XQ takes that principle one step further.
If infrastructure is distributed, data protection must be distributed.
If users and workloads are dynamic, authorization must be dynamic.
If missions cross organizational and national boundaries, policy must cross those boundaries with the data.
And if AI increasingly determines how information is consumed and acted upon, AI access to data must become policy-controlled rather than implicitly trusted.
This is the foundation of a true sovereign data architecture.
The future of Zero Trust is data-centric
The next generation of defense cybersecurity will not be defined solely by better firewalls, stronger identity systems or more secure clouds.
It will be defined by the ability to answer, continuously and with evidence:
Who can access this data?
Why can they access it?
Where can they access it?
What are they allowed to do with it?
Who controls the cryptographic keys?
Can that access be revoked immediately?
Can we prove that the policy was enforced?
That is the transition from Zero Trust infrastructure to Zero Trust data.
And it is the foundation for the sovereign, resilient digital ecosystems that CGI describes.
XQ's role is simple: give organizations control of the data itself—across cloud, edge, enterprise, coalition and AI environments—so sovereignty can be enforced rather than merely asserted.

