Zero Trust
A security model where trust is never assumed based on network location and is continuously re-evaluated. Each access decision considers identity, device posture, and context. Codified in NIST SP 800-207. Distinct from ZTNA, which is the access control product category.
Zero trust is a set of design principles, not a product, and the identity parts are the ones that actually get implemented: strong authentication, device posture, per-application authorization, and continuous re-evaluation instead of a one-time gate at the perimeter. NIST SP 800-207 is the reference worth reading, mostly because it is vendor-neutral enough to argue with.
See also: what is zero trust, conditional access, ZTNA, zero trust vendors
Related on Start with Identity
- GlossaryAdaptive Authentication
Authentication flows that change based on risk signals. Low-risk sign-ins may complete with one factor; high-risk sign-ins escalate to step-up MFA or are blocke
- GlossaryDevice Posture
The state of a device at the time of access: OS patch level, disk encryption status, EDR presence, jailbreak detection, certificate enrollment. Posture is an in
- GlossaryTrust over IP (ToIP)
A Linux Foundation framework that organizes decentralized trust into a dual stack: technology layers (identifiers, credentials, protocols) and governance layers
- RankingBest Zero Trust Tools: Top 5 ZTNA and SSE Platforms
The top 5 Zero Trust tools (Cloudflare, Zscaler, Tailscale, Palo Alto Prisma Access, Netskope), scored on a 10-dimension rubric.
- VendorCloudflare Zero Trust
top_tier
- ArticleTop 7 Open-Source Zero Trust and ZTNA Tools
The best open-source zero trust tools in 2026, from OpenZiti and Pomerium to Teleport, Headscale, NetBird, HashiCorp Boundary, and Authelia, compared on archite