Platform / Zero Trust Data

What is Zero Trust Data?

Zero Trust Data is a security model that makes each piece of data — a file, email, database record or data stream — its own security boundary. Data is classified, encrypted with its own key, and bound to an access policy that is checked every time it is opened, so protection, control and audit travel with the data wherever it goes, independent of networks, clouds or applications.

Built for Security architects and CISOs evaluating data-centric security · Compliance teams protecting CUI, PHI and personal data · Anyone comparing zero trust approaches

At a glance

BoundaryThe data object itself

EnforcedAt the moment of access — every time

KeysHeld outside the storage or cloud provider

Aligns withDoD Zero Trust Data pillar, ACP 240 / ZTDF

Protection that travels

Encryption and policy move with the data through clouds, partners and AI systems.

Control after sharing

Access can be changed or revoked at any time — even after data has left your hands.

Proof of every access

Every open, denial and revocation is recorded in a tamper-evident audit trail.

Zero Trust, applied to the data itself

Zero Trust Data is also the foundation of Zero Trust AI: AI discovers and classifies data and adapts access to context, and the Zero Trust Data layer enforces those decisions on every object.

Zero trust means “never trust, always verify”: no user, device or network is trusted by default (NIST SP 800-207). Most zero trust programs apply that principle to networks and applications — verifying who connects. Zero Trust Data applies it to the data: verifying who can open each object, every time, wherever it is.

How Zero Trust Data works

  • Classify: sensitive data — CUI, PHI, PII, export-controlled — is identified and labeled as it is created or ingested.
  • Encrypt at the edge: each object is encrypted with its own key before it reaches storage or the cloud.
  • Externalize the keys: keys are held by a key access service, outside the storage provider — optionally in your own environment.
  • Bind the policy: role, attribute, location and time rules (RBAC, ABAC, geofencing) travel with the object.
  • Verify every access: the policy is evaluated at decryption time against live conditions; keys are released only when it passes.
  • Audit and revoke: every access attempt is logged, and access can be withdrawn instantly, making every copy unreadable.

See Zero Trust Data on your own data.

Zero Trust Data vs. network zero trust (ZTNA)

Network zero trust / ZTNAZero Trust Data
What it protectsAccess to networks and applicationsThe data object itself
When it enforcesWhen a user connectsEvery time the data is opened
After data is shared or downloadedNo further controlPolicy still applies and can be revoked
Who holds the keysNot applicableYou — outside the storage or cloud provider
If data is stolenReadableCiphertext that can’t be opened

The two are complementary: ZTNA secures the door, Zero Trust Data secures what’s inside — including after it leaves. Zero Trust Data also goes further than traditional data loss prevention, which guards the perimeter; see XQ DLP.

Standards and mandates

  • The U.S. DoD Zero Trust Strategy makes Data one of its pillars.
  • AWS validated XQ for the Data pillar of AWS ZTAG-I (Zero Trust Accelerator for Government – Integrated), its reference zero trust architecture for the U.S. federal government.
  • The allied ACP 240 standard defines data-centric security for coalition sharing, including the Zero Trust Data Format (ZTDF).
  • CMMC 2.0 and NIST SP 800-171 require access control, audit and protection for CUI wherever it is.
  • GDPR Article 32 names encryption as an appropriate measure for personal data.

How XQ delivers Zero Trust Data

XQ acts as an external key store and policy service, with agents in your environment that classify, encrypt and enforce — XQ never stores or handles your data. The same engine powers Vault, Secure Email, Gateway, Database Governance, DLP and the developer API, and extends Microsoft Purview beyond Microsoft 365.

Related resources and articles

Zero Trust Data, answered directly.

What is Zero Trust Data?

Zero Trust Data treats the data object itself as the security boundary — binding identity, policy and encryption directly to a file, record or message so protection is enforced wherever that data goes, independent of the network it crosses.

Is Zero Trust Data just encryption?

No. Encryption is one part. Zero Trust Data combines per-object encryption with externally held keys, access policy evaluated at every open, classification, audit and revocation.

How is Zero Trust Data different from ZTNA?

ZTNA decides who can connect to an application or network. Zero Trust Data decides who can open each piece of data — and keeps deciding after the data has been shared, downloaded or stolen.

Does Zero Trust Data replace firewalls or ZTNA?

No. It complements them: network controls reduce who can reach your systems, and Zero Trust Data protects the data when those controls are bypassed or the data leaves.

What is ZTDF?

The Zero Trust Data Format is the allied standard for packaging data with its labels, access policy and encryption, defined as part of ACP 240 so allies can share data securely.

Has XQ’s Zero Trust Data approach been validated?

Yes. AWS validated XQ for the Data pillar of AWS ZTAG-I (Zero Trust Accelerator for Government – Integrated), AWS’s reference zero trust architecture for the U.S. federal government, where XQ adds encryption for sensitive information and communications alongside AWS encryption for stored data.

Make every piece of data its own boundary.

Talk to our team about applying Zero Trust Data to your email, files, databases and clouds.