Security

Zero Trust / Zero Port Model

How CerberusD combines identity, assignment, readiness, and session decisions without making resource ports the normal user-facing access surface.

Page type: SecurityZero Trust / Zero PortStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

Zero Port removes the resource port from the person’s everyday sign-in path. The person opens an assigned work surface through CerberusD while resource-side reachability is prepared according to the connection model.

Connection models

Model Resource-side path Person experience
Windows Agent Managed private connectivity and Agent preparation make the resource reachable. The assigned desktop opens from CerberusD.
Gateway without Agent A gateway runs from a network location that can reach the resource. The assigned RDP, VNC, or terminal surface opens from CerberusD.
Controlled private access The resource stays reachable inside the deployment’s private-network policy. The person uses only the approved resource path.

In every model, the network team operates resource-side firewall and reachability boundaries. CerberusD presents a managed work surface instead of handing the person a resource address or broad network membership.

Relationship to Zero Trust

Zero Port narrows the network surface. Resource authorization separately uses the Identity, scope, and assignment contract. A network-reachable resource therefore does not automatically become a launchable user session.

Evaluation checklist

  • Does the resource port become an internet-facing user sign-in surface?
  • From which network boundary does the Agent or gateway reach the resource?
  • Does the person’s device join a broad network or open an assigned work surface?
  • Which readiness state appears when the connection path closes?