Security

Security Model

Identity, assignment, resource readiness, credential custody, session policy, revocation, and records.

Page type: SecuritySecurity modelStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

This page is the map for CerberusD security documentation. Each control is defined once on its canonical page.

Control map

Question Canonical page
How is the person authenticated and where is the second factor applied? Identity and SSO
Which inputs open a resource session? Identity, scope, and assignment
How is the resource port separated from the user surface? Zero Trust / Zero Port
How is connected-machine readiness established? Resource readiness and Agent trust
How are target credentials protected? Credential custody
How are Windows local accounts prepared? Managed local accounts
Which controls apply during a session? Session policies
How are future access and active sessions closed? Revocation and evidence
How is ownership split between product and operating environment? Deployment responsibilities

Starting a security review

Start with the first two rows for identity, Zero Port and readiness for network posture, or session policy and revocation for operations. Architecture overview connects the end-to-end technical responsibilities.