What is Zero Trust?
Zero trust does not assume that every user or device is malicious. It grants no implicit trust based only on network location, asset ownership, or a previous session. A zero trust architecture protects resources through explicit authentication and authorization, least privilege, device and other context, and continued policy enforcement. Network controls remain useful, but being inside a network does not grant broad access.
Why it matters
Users, devices, services, and data now cross cloud and network boundaries. Zero trust keeps access decisions tied to the protected resource and current context instead of a broad trusted network zone.
How it works
- Identify the resources, subjects, and data flows that need protection.
- Authenticate the subject and evaluate least-privilege policy with available device, request, and resource context.
- Enforce the decision at the resource path, monitor activity, and evaluate later requests again when context changes.
Example
An employee in the office must still authenticate to reach payroll, and policy allows only the payroll actions needed for that employee's role.
Pomerium boundary
Pomerium is an identity-aware proxy built around zero trust principles. It applies identity and context policy to protected routes and proxies only approved requests to the named upstream services.
Limits and non-claims
- Zero trust is an architecture and operating model, not one product or certification.
- Zero trust does not remove the need for network, endpoint, application, and data security controls.
- Poor identity data, missing context, unsafe policy, or incomplete enforcement can still permit harmful access.
Evaluation checklist
- Which named resources, actions, human identities, and workload identities need protection?
- Which location, ownership, session, or inherited role still creates implicit trust?
- Where do policy administration, information, decision, and enforcement occur?
- Can any direct, internal, service, administrative, or recovery path bypass mediation?
- Which network, endpoint, workload, application, data, evidence, and recovery controls remain necessary?
