Skip to content

Security

Zero Trust

A security model that trusts nothing by default and verifies every request, rather than trusting anything inside the network.

Zero trust replaces the old "castle and moat" model (where anything inside the corporate network was trusted), with a simple principle: never trust, always verify. Every request to access a resource is authenticated and authorised on its own merits, regardless of where it comes from, because "inside the network" is no longer a meaningful boundary once people work remotely and systems live in the cloud.

In practice it means strong identity, least-privilege access (each user and service gets only what it needs), and continuous verification rather than a single login at the perimeter. It is a direction of travel and a set of principles more than a product you buy, and applying it well is about design, not a single switch.

Related terms

Working out whether you need Zero Trust?

Definitions are the easy part. If you are trying to decide whether Zero Trust belongs in your system, describe what you are building and a senior engineer will give you a straight answer, including when the answer is that you do not need it.

  1. 01A senior engineer reads it. Not a form queue, and not an account manager.
  2. 02We reply either with questions or with a straight answer that we are not the right fit.
  3. 03If it looks like a fit, a technical call with the person who would actually run the delivery.
  4. 04Then scope, effort and risk in writing, before anyone signs anything.

Two fields required. We reply to real enquiries. No list, no sequence.