Data Sovereignty Requirements in XR Start With Where the Data Lives
Defense and aerospace organizations operate under strict rules about where sensitive data is processed and stored. Pixel streaming is the only XR architecture that keeps all data inside your own infrastructure, by design, not by configuration.
AI generated image
EVENTS
Meet us at I/ITSEC 2026
EVENTS
Meet us at I/ITSEC 2026
EVENTS
Meet us at I/ITSEC 2026
EVENTS
Meet us at I/ITSEC 2026
Trusted by Leading Defense and Industrial Organizations
INDUSTRY CHALLENGE
The Compliance Problem Every Defense XR Program Eventually Hits
XR is moving into defense and aerospace maintenance, training, and engineering review at a meaningful pace. But most programs hit the same structural problem: AR and VR headsets are mobile, often shared across teams, and not designed to hold sensitive or classified data within a controlled perimeter.
For organizations operating under CMMC 2.0, the DoD's cybersecurity certification framework now being incorporated into active defense contracts, this creates a concrete compliance question. Where is the Controlled Unclassified Information being processed? Where does it reside? Who can access it, and from what device? Organizations subject to ITAR face the same set of questions with equally serious consequences for non-compliance.
Standard XR deployments push the application and its data to the headset, or route it through the device manufacturer's cloud infrastructure. Either way, the raw data leaves the organization's own environment. That is not a configuration problem that access controls can fully resolve; it is an architectural problem.
Addressing data sovereignty requirements in a cybersecurity-governed environment means the processing boundary has to be established before deployment, not patched afterward. The organizations that have solved this for XR did not do it through policy. They did it by choosing a different architecture from the start.
THE MECHANISM
Pixel Streaming Is the Architecture That Resolves This at the Source
Standard XR
XR device receives the underlying data.
Data persists on the device after the session.
Maintaining security depends on device policy.
Models simplified to run on the headset.
XR pixel streaming
XR device acts as a screen, only pixels reach the headset.
Nothing remains on the device after the session.
Maintaining security is architectural default.
Full model complexity, no data preparation.
Hololight does not stream content. It streams pixels. The distinction matters more than it might first appear. The application runs entirely on a server or workstation inside the organization's own infrastructure. What reaches the headset is an encrypted stream of image frames. Nothing else crosses the boundary. The headset acts as a display, and all processing stays inside the perimeter.
Because the application never runs on the headset, the raw data never reaches it. The 3D model, the classified assembly file, the digital twin: none of it crosses the network boundary. If a device is lost, shared without authorization, or connected outside the perimeter, the exposure is zero because there is nothing on it to expose. This is data sovereignty by architecture: the security posture is preserved because nothing ever has to leave the perimeter.
This is fundamentally different from approaches that push applications to the device and rely on encryption at rest or access controls to manage the resulting exposure. Controls can be misconfigured. Access policies can be bypassed. An architecture that keeps data off the device cannot be compromised at the device level, because there is nothing at the device level to compromise.
Hololight deploys fully on-premise, including in air-gapped environments with no public internet connection required. For organizations operating classified programs or working under strict network segmentation policies, on-premise deployment without any external cloud dependency is a hard requirement. Hololight is the only enterprise XR streaming platform that meets it while running on a fully proprietary streaming stack.
USE CASES
Where Data Sovereignty Requirements Drive XR Decisions
in Defense and Aerospace
Reviewing Classified Engineering Data in XR Without Moving It Off-Site
Defense programs routinely work with export-controlled 3D models and classified assembly files that cannot be transferred to a mobile device or processed outside a controlled environment. With Hololight, engineers review those assets at full fidelity in XR, at 1:1 scale and full geometric complexity, without the model file ever leaving the organization's secure server. What reaches the headset is the rendered image. The source data stays exactly where it is required to stay.
Deploying XR Across Distributed Teams Without Distributing the Data
Large defense programs involve engineering and operations teams spread across multiple facilities, often operating under different classification levels or network restrictions. Hololight Hub, the platform's centralized orchestration layer, controls user access, device permissions, and application delivery from one management interface. The data stays in one location; every access event is logged, auditable, and governed by the same policies regardless of where the end user is located.
Supporting Field Technicians With XR When the Data Cannot Leave the Perimeter
Sustainment operations require field technicians to access complex technical information: maintenance procedures, component specifications, system diagnostics. With pixel streaming, that information streams from a secure on-premise server to the technician's headset as a real-time rendered image. The technician sees exactly what they need. The underlying data never crosses the perimeter. Hololight's XR pixel streaming technology is part of Lockheed Martin Skunk Works' 5G Pixel Streaming Kit, a system that streams high-fidelity, real-time 3D visualization to edge devices for defense sustainment work.
REQUIREMENTS AND COMPLIANCE
How Pixel Streaming Supports Your Data Sovereignty Requirements in Practice
Demonstrating data sovereignty in a cybersecurity-governed environment means showing, not just asserting, that sensitive data is processed and stored within controlled boundaries. Hololight's architecture addresses each of the structural requirements that defense and aerospace procurement and compliance teams evaluate during XR platform selection.
| Requirement | How Hololight Addresses It |
|---|---|
| Data must not be processed on a shared or mobile device | The application runs on the organization's own server; the headset receives only rendered pixels |
| Data must not leave the organization's infrastructure | No raw data is transmitted; only encrypted image frames reach the headset |
| Deployment must be fully on-premise | Hololight deploys on-premise on the organization's own hardware, with no external cloud dependency. Cloud and hybrid deployment are supported where permitted. |
| Air-gapped environments must be supported | Hololight operates in fully air-gapped networks with no public internet requirement, as a built-in capability of the architecture |
| User access must be centrally managed and auditable | Hololight Hub provides centralized user management, access control, and session monitoring |
| Device fleet must be manageable at scale | Hololight Hub supports multi-device deployment and oversight from a single management interface |
PROOF
Proven Across Industries Where Data Cannot Leave the Building
– Jörn Stiegelmeier, Head of Technology and Development, ENGIE Refrigeration
This is only possible with the streaming technology by Hololight. The streaming technology is the key. If this wouldn't work perfectly, nobody would use it.
– Armin Brucic, Head of Software Development and Application Engineering, Felder Group
Hololight works with defense and aerospace organizations across Europe and the United States. In the United States, Hololight's XR pixel streaming technology is part of Lockheed Martin Skunk Works' 5G Pixel Streaming Kit, a system that streams high-fidelity, real-time 3D visualization to edge devices for defense sustainment work.
COMPARISON
Why Architecture Matters More Than Access Controls
Not all XR deployments handle sensitive data the same way. The differences below are architectural.
They cannot be resolved through configuration or policy, because they reflect where the data goes and who controls that boundary.
| Factor | Hololight Pixel Streaming | Standard On-Device XR | Consumer XR Tools |
|---|---|---|---|
| Where is the data processed? | On-premise server inside the organization's own infrastructure | On the headset, or through the manufacturer's cloud | On the user's PC or a third-party cloud service |
| Does raw data reach the headset? | No. Only encrypted pixel frames are transmitted | Yes | Yes |
| On-premise deployment supported? | Yes, including fully air-gapped environments | Rarely; cloud dependency is typical | No |
| Air-gapped operation? | Yes | No | No |
| Centralized user and access management? | Yes, via Hololight Hub | Limited; per-device setup is standard | No |
| Device agnosticism? | Yes, all major AR and VR headsets are supported: Apple Vision Pro, Meta Quest, PICO 4 Ultra Enterprise, HTC VIVE Family, Snap Spectacles, Lenovo ThinkReality VRX, Microsoft HoloLens 2 (Maintenance Mode), plus iOS, Windows desktop and web browser clients | Device-specific or limited | PC VR only |
| Dependency on a third-party streaming engine? | None. Hololight's stack is fully proprietary | Varies by vendor | Consumer platforms only |
| Enterprise support and integration services? | Full commercial relationship, integration support, white-label option available | Varies; typically self-service | No enterprise support |
| OpenXR support? | Yes, including fully air-gapped environments | Rarely; cloud dependency is typical | No |
| Air-gapped operation? | Native. Designed to be conformant with OpenXR and expected to pass the Khronos Conformance Process. | Varies | Limited |
WHY HOLOLIGHT
The Only XR Streaming Infrastructure Built for Organizations
Where Security Is Not Optional
A Proprietary Stack With No External Dependencies
Hololight's pixel streaming technology is built and owned entirely in-house. There is no dependency on any third-party streaming engine. That matters for one specific reason: a platform that relies on someone else's infrastructure cannot unconditionally guarantee full on-premise or air-gapped deployment, because part of the decision is outside its control. Hololight's is not.
Streaming Technology and the Platform to Manage It
Hololight Stream handles the pixel streaming layer. Hololight Hub handles deployment, user access, device management, and operational oversight from a single interface. No other enterprise XR streaming provider offers the complete stack. That completeness means organizations are building on infrastructure, not assembling one from parts.
Every Major Headset. No Vendor Lock-In.
The same application streams to Apple Vision Pro, Meta Quest, PICO 4 Ultra Enterprise, HTC VIVE Family, Snap Spectacles, and Microsoft HoloLens 2, without modification, with iOS, Windows desktop and browser clients alongside them. Organizations are not bound to a single hardware vendor. When the device landscape changes, and it will, the platform continues to work without rearchitecting the deployment.
Proven in Production, Not in Pilots
Hololight's named customers include BMW, ENGIE Refrigeration, Genesis Design Studios, Bilfinger, and Felder Group. These organizations are not running experimental XR programs. They have integrated Hololight into the workflows they depend on every day. In defense, Hololight's streaming technology is part of Lockheed Martin Skunk Works' 5G Pixel Streaming Kit.
Strategic Partnerships, Full Infrastructure Independence
Hololight maintains strategic partnerships with NVIDIA, Snap, HTC, Qualcomm, Autodesk, Microsoft, Meta and PICO. Those partnerships inform product development and ensure device compatibility. They do not create dependency. Hololight's infrastructure decisions remain its own, which is the point.
Built on the OpenXR Standard
Hololight natively supports OpenXR across all major applications and headsets. OpenXR is the royalty-free, multi-vendor runtime standard governed by the Khronos Group. It is the right foundation for any XR infrastructure intended to outlast the current device generation. Hololight's streaming technology is designed to be conformant with OpenXR. The technology is based on a published Khronos Specification and is expected to pass the Khronos Conformance Process.
FAQ
Common Questions About Data Sovereignty in XR Deployments
-
Does Hololight store any data on the headset?
No. With Hololight's pixel streaming architecture, the application runs on a server or workstation inside the organization's own infrastructure. The headset receives only the rendered pixel output: an encrypted stream of image frames. No application data, model files, or sensitive content is stored on or transmitted to the headset in raw form.
-
Can Hololight be deployed in a fully air-gapped environment?
Yes. Hololight deploys fully on-premise and operates in air-gapped networks with no public internet connection required. This is a built-in architectural capability, not a custom configuration, and it sits alongside cloud and hybrid deployment options. Defense programs operating classified workloads or under strict network segmentation requirements can deploy Hololight within their existing secure infrastructure without any external cloud dependency.
-
How does pixel streaming relate to data sovereignty requirements?
Data sovereignty requires that data be processed and stored within boundaries you control. Standard XR architectures run the application on the headset itself, which means sensitive data travels to a mobile device that may be shared across teams, moved between facilities, or connected to networks outside your perimeter. Pixel streaming works the other way: the application and its data remain inside your own infrastructure. What reaches the device is a rendered image, not a file. That architectural inversion is what makes it possible to maintain data sovereignty in a cybersecurity-governed environment without redesigning your security posture around the headset.
-
Does Hololight use NVIDIA CloudXR?
No. Hololight's pixel streaming technology is developed and maintained entirely by Hololight. It does not use NVIDIA CloudXR or any third-party streaming engine. Hololight is fully optimized for NVIDIA RTX GPUs, and it renders demanding, ray-traced scenes server-side before streaming only pixels to the headset. Owning the full stack is what allows on-premise, cloud and fully air-gapped deployment from the same architecture.
-
What headsets does Hololight support?
Hololight supports all major AR and VR headsets, including Apple Vision Pro, Meta Quest 2, 3, 3S and Pro, PICO 4 Ultra Enterprise, the HTC VIVE family, Snap Spectacles, and Microsoft HoloLens 2. Clients are also available for iOS, Windows desktop, and the web browser. The same application streams to all supported devices without modification. Organizations do not need to maintain separate codebases or deployment configurations for different headset types.
-
How complex is the integration, and what infrastructure is required?
The integration process depends on the organization's existing IT infrastructure and the applications involved. Hololight provides integration support throughout implementation, including custom integration services. Organizations need a Windows server or workstation with an NVIDIA RTX GPU to handle rendering; Hololight's team works with customers to define specific infrastructure requirements based on their workload and deployment environment. The best starting point is a direct conversation about your specific use case.
CONTACT US
Your Data Stays in Your Infrastructure. Let Us Show You How.
Defense and aerospace organizations cannot discover a data sovereignty gap after an XR program is already in production. The architectural decision, where data lives, where it is processed, and who controls those boundaries, has to be made before the first headset is deployed.
Hololight is built for organizations where security is a baseline requirement, not a feature. Every engagement starts with a genuine understanding of the customer's infrastructure, compliance environment, and operational constraints. That is not a positioning statement; it is how the product is implemented.