Skip to main content
Certyneo
Glossary term · Z

Zero Trust (zero-trust security)

Definition

The Zero Trust model (zero trust) is a security architecture based on the principle "Never trust, always verify" — unlike the classic perimeter model which trusts everything inside the corporate network. Its pillars are: continuous identity verification (MFA at each access), least privilege (access strictly limited to operational need), micro-segmentation (service isolation), traffic inspection (including internal), and real-time monitoring. In the context of electronic signature, Zero Trust applies at multiple levels: access to the HSM (no private key accessible without strong operator authentication), access to envelopes (identity-based control, not just link-based), and admin access (ephemeral sessions with automatic revocation). The NIST SP 800-207 framework and the ANSSI guide "Recommendations on Zero Trust" (2021) formalize the requirements in France.

Ready to Put These Concepts Into Practice?

Certyneo allows you to create eIDAS-compliant signature envelopes in just a few clicks, without installation.