Skip to main content

Zero Trust

Zero trust does not assume that every user or device is malicious.

What is Zero Trust?

Zero trust does not assume that every user or device is malicious. It grants no implicit trust based only on network location, asset ownership, or a previous session. A zero trust architecture protects resources through explicit authentication and authorization, least privilege, device and other context, and continued policy enforcement. Network controls remain useful, but being inside a network does not grant broad access.

Why it matters

Users, devices, services, and data now cross cloud and network boundaries. Zero trust keeps access decisions tied to the protected resource and current context instead of a broad trusted network zone.

How it works

  1. Identify the resources, subjects, and data flows that need protection.
  2. Authenticate the subject and evaluate least-privilege policy with available device, request, and resource context.
  3. Enforce the decision at the resource path, monitor activity, and evaluate later requests again when context changes.

Example

An employee in the office must still authenticate to reach payroll, and policy allows only the payroll actions needed for that employee's role.

Pomerium boundary

Pomerium is an identity-aware proxy built around zero trust principles. It applies identity and context policy to protected routes and proxies only approved requests to the named upstream services.

Limits and non-claims

  • Zero trust is an architecture and operating model, not one product or certification.
  • Zero trust does not remove the need for network, endpoint, application, and data security controls.
  • Poor identity data, missing context, unsafe policy, or incomplete enforcement can still permit harmful access.

Evaluation checklist

  • Which named resources, actions, human identities, and workload identities need protection?
  • Which location, ownership, session, or inherited role still creates implicit trust?
  • Where do policy administration, information, decision, and enforcement occur?
  • Can any direct, internal, service, administrative, or recovery path bypass mediation?
  • Which network, endpoint, workload, application, data, evidence, and recovery controls remain necessary?

Sources and further reading

Keep learning

Zero TrustAuthorization and Policy

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo