Glossary term · Z
Zero Trust (zero-trust security)
Definition
The Zero Trust model (zero trust) is a security architecture based on the principle "Never trust, always verify" — unlike the classic perimeter model which trusts everything inside the corporate network. Its pillars are: continuous identity verification (MFA at each access), least privilege (access strictly limited to operational need), micro-segmentation (service isolation), traffic inspection (including internal), and real-time monitoring. In the context of electronic signature, Zero Trust applies at multiple levels: access to the HSM (no private key accessible without strong operator authentication), access to envelopes (identity-based control, not just link-based), and admin access (ephemeral sessions with automatic revocation). The NIST SP 800-207 framework and the ANSSI guide "Recommendations on Zero Trust" (2021) formalize the requirements in France.
Associated guides
Related terms
Ready to put these concepts into practice?
Certyneo allows you to create eIDAS-compliant signature envelopes in a few clicks, without installation.