Zero Trust
A security model where trust is never assumed based on network location and is continuously re-evaluated. Each access decision considers identity, device posture, and context. Codified in NIST SP 800-207. Distinct from ZTNA, which is the access control product category.
Zero trust is a set of design principles, not a product, and the identity parts are the ones that actually get implemented: strong authentication, device posture, per-application authorization, and continuous re-evaluation instead of a one-time gate at the perimeter. NIST SP 800-207 is the reference worth reading, mostly because it is vendor-neutral enough to argue with.
See also: what is zero trust, conditional access, ZTNA, zero trust vendors
Related on Start with Identity
- GlossaryAdaptive Authentication
Authentication flows that change based on risk signals. Low-risk sign-ins may complete with one factor; high-risk sign-ins escalate to step-up MFA or are blocke
- GlossaryDevice Posture
The state of a device at the time of access: OS patch level, disk encryption status, EDR presence, jailbreak detection, certificate enrollment. Posture is an in
- GlossaryRADIUS
RADIUS (Remote Authentication Dial-In User Service) is a protocol, defined in [RFC 2865](https://www.rfc-editor.org/rfc/rfc2865), that network devices such as s
- VendorCloudflare Zero Trust
top_tier
- ExpertSPIFFE and SPIRE maintainer, co-author of Zero Trust Networks
Evan Gilman is a maintainer of SPIRE, the reference implementation of SPIFFE, and co-wrote O'Reilly's Zero Trust Networks. He was an engineer at Scytale, where
- ArticleTop 7 Open-Source Zero Trust and ZTNA Tools
The best open-source zero trust tools in 2026, from OpenZiti and Pomerium to Teleport, Headscale, NetBird, HashiCorp Boundary, and Authelia, compared on archite