What is zero-trust network access (ZTNA)?
Zero-trust network access grants each person or device access to specific applications based on verified identity and policy, instead of trusting anything that sits inside a network perimeter. Nothing is reachable until a policy allows it.
Written by Paul Madelénat. Last updated
From perimeter to identity
The traditional model trusts the network. Once a laptop is inside the office network or connected to the VPN, it can usually reach far more than its user needs. An attacker who gets in, through a stolen password or a compromised device, inherits that reach.
Zero trust removes the assumption. The approach, described by the US National Institute of Standards and Technology in its publication SP 800-207, treats every request as untrusted until the identity behind it is verified and a policy allows it. Zero-trust network access applies that idea to connectivity: a person reaches the specific applications their role requires, and nothing else is visible to them.
In practice ZTNA combines three things: an identity provider that says who someone is, policies that map groups to applications, and a network layer that enforces those policies on every connection.
How it differs from a VPN
A classic VPN joins a device to a network. ZTNA joins a person to applications. With a VPN, access control happens after the connection, if at all. With ZTNA, the policy decides whether a connection can exist. Disabling an account in the directory removes access everywhere at once, and every connection can be recorded against a named person.
ZTNA also removes the need to publish internal applications on the internet. If an app has no public address, automated scanners cannot find it.
Commercial ZTNA services such as Zscaler Private Access run the policy layer as a subscription. Open-source tools such as NetBird do the same job on machines you control, for your own staff and the internal systems they need to reach.
Zero-trust access at Pilae
Every app Pilae operates answers only on a private network, a mesh of encrypted tunnels operated by Pilae. Staff join with their Keycloak or Entra ID account, and the groups in your directory decide which apps each person reaches. The only public entry point is one hardened gate on port 443, and only for the apps you choose to publish.
Machines on your premises and in Pilae Cloud sit on the same mesh, so a hybrid estate keeps one network and one policy. Peers, policies and policy changes are recorded in the audit trail. For sites with no outbound connection, the coordination service runs inside your perimeter; see air-gapped deployments.