Zero Trust
Zero Trust is the umbrella cybersecurity strategy that eliminates implicit trust based on network location and requires continuous verification of every user, device, workload, and access request. This index aggregates the core specifications (NIST, CISA, DoD, NSA, NCSC), the leading vendor platforms that implement Zero Trust (Cloudflare, Zscaler, Netskope, Palo Alto Networks, Tailscale, Twingate, Microsoft, Google), and the CNCF-graduated open standards that the ecosystem depends on (SPIFFE, SPIRE, OPA). Three sister API Evangelist topics cover Zero Trust Architecture, Zero Trust Network Access (ZTNA), and the Zero Trust Security Model in greater depth.
Resources
-
NIST SP 800-207 Zero Trust Architecture
The foundational US specification of Zero Trust, defining the seven tenets, PDP/PEP/PA components, and three deployment variants (enhanced identity governance, microsegmentation, network infrastructure / SDP).
-
CISA Zero Trust Maturity Model v2
The federal-civilian Zero Trust roadmap from CISA, with four maturity levels across the Identity, Devices, Networks, Applications & Workloads, and Data pillars plus cross-cutting capabilities for Visibility & Analytics, Automation & Orches…
-
DoD Zero Trust Reference Architecture
The Department of Defense seven-pillar Zero Trust reference architecture and 152-capability target/advanced execution roadmap.
-
Cloudflare Zero Trust API
Cloudflare's Zero Trust platform combining ZTNA, SWG, CASB, RBI, DLP and an REST API for managing all of it.
-
Zscaler Zero Trust Exchange API
Zscaler's combined ZIA (internet access) and ZPA (private access) Zero Trust platform with REST APIs for both.
-
Microsoft Entra Zero Trust APIs
Microsoft Entra (formerly Azure AD), Conditional Access, Defender for Cloud Apps, and Microsoft Intune together implement Zero Trust on the Microsoft platform; Microsoft Graph exposes a unified REST surface.
-
Google BeyondCorp Enterprise
Google's productized Zero Trust platform building on the original BeyondCorp research; provides context-aware access through Identity-Aware Proxy and Chrome Enterprise.
-
SPIFFE / SPIRE
CNCF-graduated workload identity standard (SPIFFE) and reference runtime (SPIRE) used as the workload-identity foundation in Zero Trust deployments.
-
Open Policy Agent (OPA)
CNCF-graduated general-purpose policy engine commonly deployed as the PDP in Zero Trust implementations.
Links
Providers working in Zero Trust
Providers whose own tags share at least two of this topic's tags, most shared first — the top 30 of 392.
| Provider | About | Rating | APIs |
|---|---|---|---|
| Zero Trust Network Access | Zero Trust Network Access (ZTNA) is a security framework and product category that grants access to private applications and resources based on identity, device posture, and context, rather than network location. ZTNA replaces the implicit… | thin | 1 |
| Zero-Trust Security Model | The Zero Trust security model is a strategic cybersecurity approach that eliminates implicit trust and requires continuous verification of every user, device, workload, and request attempting to access resources, regardless of network loca… | thin | 5 |
| iboss | iboss, Inc. is a Boston-headquartered cybersecurity company founded in 2003 that operates an AI-powered, cloud-native Zero Trust SASE (Secure Access Service Edge) platform used by more than 4,000 enterprise, US federal, state and local gov… | emerging | 1 |
| Zero Trust Architecture | Zero Trust Architecture (ZTA) is a security framework defined by NIST SP 800-207 that requires all users and devices to be authenticated, authorized, and continuously validated before being granted access to applications and data, regardle… | emerging | 5 |
| Zero Networks | Zero Networks is an Israeli-American network security company whose Segment platform delivers automated, agentless microsegmentation and identity segmentation for enterprise networks. It builds a host-based firewall "bubble" around every a… | developing | 1 |
| P0 Security | P0 Security is a cloud-native Privileged Access Management (PAM) platform that governs runtime authorization for human users, machine/service accounts, and AI agents across hybrid and multi-cloud environments. Its AuthZ Control Plane enfor… | developing | 1 |
| SpiderOak | SpiderOak (SpiderOak, Inc. / SpiderOak Mission Systems) builds zero-trust access governance and secure data exchange software for defense, aerospace and commercial operators working in contested, disconnected, degraded, intermittent and lo… | developing | 1 |
| CoroNet | Coro (CoroNet) is a cybersecurity company delivering a unified, AI-native security platform for lean IT teams, growing organizations, and managed service providers (MSPs). A single platform and dashboard consolidate endpoint protection, em… | developing | 1 |
| Pulse | Ivanti's secure-access product family, formerly Pulse Secure, acquired by Ivanti in 2020. Three administrator-facing REST APIs configure and observe it: Ivanti Connect Secure for SSL VPN remote access, Ivanti Policy Secure for 802.1X and R… | thin | 3 |
| Check Point | Check Point Software Technologies is a global cybersecurity vendor providing network, cloud, endpoint, mobile, and email security through its Quantum, CloudGuard, and Harmony product families. Check Point exposes a wide range of REST APIs… | thin | 5 |
| Perimeter 81 | Perimeter 81 is a cloud-native Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) platform, now part of Check Point as Check Point Harmony SASE following its 2023 acquisition. It lets organizations build and manage secu… | thin | 1 |
| Illumio | Illumio is a Zero Trust Segmentation (microsegmentation) cybersecurity company whose platform stops the lateral spread of ransomware and breaches across data centers, cloud, and endpoints. Its Policy Compute Engine (PCE) exposes a REST API… | thin | 1 |
| Unisys | Unisys is a global information technology company that provides specialized solutions integrated with leading-edge security. Unisys delivers digital workplace services, cloud and infrastructure services, and enterprise computing solutions… | emerging | 4 |
| Aceiss | Aceiss is a security monitoring and access-visibility platform that gives CISOs and risk managers continuous insight into who has access to their GitHub organizations and repositories. It monitors user access across repositories, detects u… | emerging | 0 |
| FireMon | FireMon is a cybersecurity company providing firewall and security policy management across hybrid, on-premises, and cloud environments. Its platform normalizes and governs security policies spanning firewalls, cloud security groups, and m… | emerging | 0 |
| Xage | Xage Security is a Palo Alto, California zero trust access and protection company whose Xage Fabric Platform enforces identity-based access control across operational technology (OT), IT, cloud and edge environments — covering privileged a… | emerging | 0 |
| 6Cloud Technology | 6Cloud Technology (Chinese name 六方云; legal entity Beijing 6Cloud Information Technology Co., Ltd. / 北京六方云信息技术有限公司) is a Beijing-based industrial and critical-infrastructure cybersecurity product vendor founded in 2018 and backed by China's… | minimal | 0 |
| Axis Security | Axis Security was a Security Service Edge (SSE) and Zero Trust Network Access (ZTNA) vendor founded in 2018 and headquartered in San Mateo, California, with research and development in Israel. Its cloud-delivered Atmos platform combined ZT… | minimal | 0 |
| Guardicore | Guardicore is a micro-segmentation and Zero Trust network security company, founded in 2013 and backed by Battery Ventures and Partech, best known for its Centra platform for software-defined segmentation, application dependency mapping, a… | minimal | 0 |
| Cyemptive | Cyemptive Technologies is a cybersecurity vendor founded in 2014 by Rob Pike, headquartered in Washington State with additional offices in North Carolina, the United Kingdom, France and India. It sells preemptive, detection-independent sec… | minimal | 0 |
| Aembit | Aembit is a Workload Identity and Access Management (Workload IAM) platform for non-human identities — AI agents, applications, microservices, CI/CD pipelines, scripts and service accounts. Instead of long-lived, hard-coded secrets, Aembit… | exemplar | 2 |
| Palo Alto Networks | Palo Alto Networks is a global cybersecurity leader providing advanced security platforms and services across network security, cloud security, and security operations. Its developer platform at pan.dev offers REST and XML APIs for PAN-OS… | exemplar | 468 |
| Tenable | Tenable is a cybersecurity and exposure-management company, maker of Nessus and the Tenable One platform, providing vulnerability management, web application scanning, cloud security, identity exposure, attack surface management and OT sec… | strong | 8 |
| Cisco Umbrella | Cisco Umbrella, built on the OpenDNS platform Cisco acquired in 2015 and now sold within Cisco Secure Access, is Cisco's cloud-delivered security service: DNS-layer security, secure web gateway, cloud-delivered firewall, CASB (Cisco Cloudl… | strong | 52 |
| Cisco Secure Firewall | Cisco Secure Firewall is the product line built on the Sourcefire technology Cisco acquired in 2013 — the Firepower/Secure Firewall appliances and Threat Defense (FTD) software, the Secure Firewall Management Center (FMC), the on-box devic… | strong | 14 |
| Amazon IAM Access Analyzer | AWS IAM Access Analyzer helps you set, verify, and refine your IAM policies by providing a suite of capabilities including findings for external, internal, and unused access, basic and custom policy checks for validating policies, and poli… | strong | 1 |
| Microsoft Entra | Microsoft Entra (formerly Azure Active Directory) provides identity and access management services including authentication, authorization, and directory services. | strong | 1 |
| Nord Security | Nord Security is a Lithuania-founded digital security and privacy company whose consumer and business portfolio spans NordVPN, NordPass, NordLocker, NordLayer (network access security for business), NordProtect/Coveron, Saily (eSIM) and No… | strong | 7 |
| C1 | C1 (ConductorOne) is an identity and access management platform engineered for the AI era. It provides unified access governance across human identities, AI agents, and services — agentic identity management, policy-driven access controls,… | developing | 1 |
| Britive | Britive is a runtime privileged access management (PAM) platform that issues just-in-time, ephemeral privileges to human users, non-human identities and AI agents across AWS, Azure, GCP, Oracle Cloud, Kubernetes, Snowflake, Okta, Salesforc… | developing | 3 |