Skip to content
Zero-Trust Architecture

Never trust. Always verify.
Identity, everywhere.

Start with explicit identity, access and network boundaries. Use the architecture below to discuss the controls your workload needs; implementation and compliance evidence require engagement-specific review.

Technology operators working beside a glass-walled server room.
Architecture

Six layers to review for explicit access decisions.

Conceptual areas to examine during an assessment. The diagram does not establish that these controls are deployed or verified for a particular workload.

Conceptual access review
01 / 06
Layer 1 · IdentityPolicy decision point
Who is requesting access?

Confirm the authoritative identity and supported policy signals for this access path.

Review: identity assertion, device posture and policy inputs

Select a layer to review its assessment questions. This illustration does not display live access decisions.

  1. 01Identity

    Identify authoritative user and workload identity providers, immutable identifiers, sign-in policies and authorization boundaries.

  2. 02Access broker

    Assess remote-access workflows, target permissions, credential lifetime and session records. Confirm what the chosen broker supports.

  3. 03Network

    Map tenant and workload boundaries, permitted flows, segmentation controls and service authentication requirements.

  4. 04Workload

    Review compute isolation, patching, boot integrity and encryption options against the selected platform and workload requirements.

  5. 05Data

    Define encryption, key custody, data access and recovery requirements. Verify supported controls and responsibilities for each data class.

  6. 06Observability

    Identify required events, collection paths, retention periods and review responsibilities. Validate representative evidence before acceptance.

Each layer enforces the same identity-based policy decision. A compromise at one layer does not grant access at the next.

The five tenets

What “zero-trust” actually means here.

Use these principles to define assessment questions and implementation evidence for your environment.

Verify explicitly, every request

Use explicit identity and authorization checks at defined access boundaries. Do not grant trust solely because a request originates inside the network.

Assume breach, contain blast radius

Identify likely compromise paths and design segmentation to limit lateral movement. Test the boundaries and document remaining exposure.

Least privilege, by default

Define the minimum access each role and service needs. Review standing privileges and assess time-bound elevation where supported.

Continuous verification

Define which device, identity and session signals can trigger re-evaluation. Agree response actions and operational ownership.

Identity-everywhere, not perimeter-first

Map users, services and access paths to policy enforcement points. Verify each integration instead of assuming uniform coverage.

Audit at the workload, not just the edge

Specify the actors, actions and outcomes that must be logged. Test collection, retention, access and evidence retrieval for the agreed scope.

Perimeter vs. zero-trust

What changes when identity becomes the perimeter.

Side-by-side: the assumptions you grew up with, vs. the assumptions Ultiblob ships with.

Legacy perimeterUltiblob zero-trust
Login once to the corporate VPN; you're trusted on the networkExplicitly authorize access to each protected resource using the signals and policies supported by the design.
Engineers SSH to bastions, then jump to VMs with shared keysAssess identity-bound access, limited credential lifetime and session logging for each administrative path.
Internal services trust each other by IPDefine and test service authentication and segmentation at the intended enforcement boundaries.
Compliance evidence is a quarterly screenshot exerciseSpecify audit events and verify their collection and retrieval for the selected workloads.
Vendor accesses your data with their key custodyAgree the key-custody model and test who can encrypt, decrypt, administer and recover data.
FAQ

Zero-trust, asked + answered.

It is an architecture approach that avoids granting trust solely from network location. A scoped assessment identifies identity, access, segmentation and logging controls to implement and test; it is not a guarantee against breaches.

Plan your security architecture

Move your perimeter from the network to the identity.

Discuss your current architecture, priority risks and assessment needs. Confirm deliverables, commercial terms and timing in the proposed scope.