Security
Zero Trust / Zero Port Model
How CerberusD combines identity, assignment, readiness, and session decisions without making resource ports the normal user-facing access surface.
Zero Port removes the resource port from the person’s everyday sign-in path. The person opens an assigned work surface through CerberusD while resource-side reachability is prepared according to the connection model.
Connection models
| Model | Resource-side path | Person experience |
|---|---|---|
| Windows Agent | Managed private connectivity and Agent preparation make the resource reachable. | The assigned desktop opens from CerberusD. |
| Gateway without Agent | A gateway runs from a network location that can reach the resource. | The assigned RDP, VNC, or terminal surface opens from CerberusD. |
| Controlled private access | The resource stays reachable inside the deployment’s private-network policy. | The person uses only the approved resource path. |
In every model, the network team operates resource-side firewall and reachability boundaries. CerberusD presents a managed work surface instead of handing the person a resource address or broad network membership.
Relationship to Zero Trust
Zero Port narrows the network surface. Resource authorization separately uses the Identity, scope, and assignment contract. A network-reachable resource therefore does not automatically become a launchable user session.
Evaluation checklist
- Does the resource port become an internet-facing user sign-in surface?
- From which network boundary does the Agent or gateway reach the resource?
- Does the person’s device join a broad network or open an assigned work surface?
- Which readiness state appears when the connection path closes?