Platform / Zero Trust Data
What is Zero Trust Data?
Zero Trust Data is a security model that makes each piece of data — a file, email, database record or data stream — its own security boundary. Data is classified, encrypted with its own key, and bound to an access policy that is checked every time it is opened, so protection, control and audit travel with the data wherever it goes, independent of networks, clouds or applications.
Built for Security architects and CISOs evaluating data-centric security · Compliance teams protecting CUI, PHI and personal data · Anyone comparing zero trust approaches
At a glance
BoundaryThe data object itself
EnforcedAt the moment of access — every time
KeysHeld outside the storage or cloud provider
Aligns withDoD Zero Trust Data pillar, ACP 240 / ZTDF
Protection that travels
Encryption and policy move with the data through clouds, partners and AI systems.
Control after sharing
Access can be changed or revoked at any time — even after data has left your hands.
Proof of every access
Every open, denial and revocation is recorded in a tamper-evident audit trail.
Zero Trust, applied to the data itself
Zero Trust Data is also the foundation of Zero Trust AI: AI discovers and classifies data and adapts access to context, and the Zero Trust Data layer enforces those decisions on every object.
Zero trust means “never trust, always verify”: no user, device or network is trusted by default (NIST SP 800-207). Most zero trust programs apply that principle to networks and applications — verifying who connects. Zero Trust Data applies it to the data: verifying who can open each object, every time, wherever it is.
How Zero Trust Data works
- Classify: sensitive data — CUI, PHI, PII, export-controlled — is identified and labeled as it is created or ingested.
- Encrypt at the edge: each object is encrypted with its own key before it reaches storage or the cloud.
- Externalize the keys: keys are held by a key access service, outside the storage provider — optionally in your own environment.
- Bind the policy: role, attribute, location and time rules (RBAC, ABAC, geofencing) travel with the object.
- Verify every access: the policy is evaluated at decryption time against live conditions; keys are released only when it passes.
- Audit and revoke: every access attempt is logged, and access can be withdrawn instantly, making every copy unreadable.
See Zero Trust Data on your own data.
Zero Trust Data vs. network zero trust (ZTNA)
| Network zero trust / ZTNA | Zero Trust Data | |
|---|---|---|
| What it protects | Access to networks and applications | The data object itself |
| When it enforces | When a user connects | Every time the data is opened |
| After data is shared or downloaded | No further control | Policy still applies and can be revoked |
| Who holds the keys | Not applicable | You — outside the storage or cloud provider |
| If data is stolen | Readable | Ciphertext that can’t be opened |
The two are complementary: ZTNA secures the door, Zero Trust Data secures what’s inside — including after it leaves. Zero Trust Data also goes further than traditional data loss prevention, which guards the perimeter; see XQ DLP.
Standards and mandates
- The U.S. DoD Zero Trust Strategy makes Data one of its pillars.
- AWS validated XQ for the Data pillar of AWS ZTAG-I (Zero Trust Accelerator for Government – Integrated), its reference zero trust architecture for the U.S. federal government.
- The allied ACP 240 standard defines data-centric security for coalition sharing, including the Zero Trust Data Format (ZTDF).
- CMMC 2.0 and NIST SP 800-171 require access control, audit and protection for CUI wherever it is.
- GDPR Article 32 names encryption as an appropriate measure for personal data.
How XQ delivers Zero Trust Data
XQ acts as an external key store and policy service, with agents in your environment that classify, encrypt and enforce — XQ never stores or handles your data. The same engine powers Vault, Secure Email, Gateway, Database Governance, DLP and the developer API, and extends Microsoft Purview beyond Microsoft 365.
Related resources and articles
- XQ Technical Overview (white paper)
- Glossary of zero trust terms
- The XQ platform
- ATCO Ventures Invests in XQ: Accelerating the Future of Zero Trust Data Security
- Federal Cybersecurity Compliance Is Evolving — And Zero Trust Data Is the Catalyst
- Why Encryption Keys Must Live Outside Third Parties — and How Zero Trust Data Solves the Problem
- How Zero Trust Data Aligns with the NSA’s Zero Trust Implementation Guidelines and Industry Best Practices
FAQ
Zero Trust Data, answered directly.
What is Zero Trust Data?
Zero Trust Data treats the data object itself as the security boundary — binding identity, policy and encryption directly to a file, record or message so protection is enforced wherever that data goes, independent of the network it crosses.
Is Zero Trust Data just encryption?
No. Encryption is one part. Zero Trust Data combines per-object encryption with externally held keys, access policy evaluated at every open, classification, audit and revocation.
How is Zero Trust Data different from ZTNA?
ZTNA decides who can connect to an application or network. Zero Trust Data decides who can open each piece of data — and keeps deciding after the data has been shared, downloaded or stolen.
Does Zero Trust Data replace firewalls or ZTNA?
No. It complements them: network controls reduce who can reach your systems, and Zero Trust Data protects the data when those controls are bypassed or the data leaves.
What is ZTDF?
The Zero Trust Data Format is the allied standard for packaging data with its labels, access policy and encryption, defined as part of ACP 240 so allies can share data securely.
Has XQ’s Zero Trust Data approach been validated?
Yes. AWS validated XQ for the Data pillar of AWS ZTAG-I (Zero Trust Accelerator for Government – Integrated), AWS’s reference zero trust architecture for the U.S. federal government, where XQ adds encryption for sensitive information and communications alongside AWS encryption for stored data.
Make every piece of data its own boundary.
Talk to our team about applying Zero Trust Data to your email, files, databases and clouds.