Aller au contenu
Pays France
Contacter Silurian

Silurian Docs

All documentation Security and performance

Zero Trust and workspace security

What Zero Trust actually means for securing your team's access to internal apps and the internet, the building blocks that make it up, and a sensible way to roll it out without disrupting your team.

Public guideReviewed 2026-07-19
01

What "Zero Trust" actually means

Instead of trusting someone just because they're connected to your office network or VPN, Zero Trust checks identity, device and context on every single request before granting access. In practice, that means a stolen password alone usually isn't enough to get in, and a compromised device can be blocked from reaching sensitive applications even if its user has valid credentials.

02

The building blocks, and what each one does

These pieces work together under one control plane, and you don't need all of them on day one:

  • Access - controls exactly who can reach your private or SaaS applications.
  • Tunnel - connects your private resources to the outside world without opening inbound firewall ports.
  • Gateway - filters DNS, network and HTTP traffic your team generates, including outbound requests to the wider internet.
  • A device client - confirms a device meets your security requirements (posture) before it's trusted.
  • Specialised add-ons (DLP, CASB, Browser Isolation, Email Security) - for data-loss prevention, SaaS visibility, safer browsing and phishing protection.
03

A sensible way to roll this out

Don't try to protect everything on day one. Start with a single application or a small group of devices, decide your identity and account-recovery requirements up front, then review the access logs before expanding your policies further. The Free plan covers your first 50 active users at no cost, so you can pilot this properly before deciding whether to scale it up - paid pricing is always shown clearly before you order.

04

How this differs from protecting your public website

Zero Trust is about your team's access to internal tools and their outbound internet use. Protecting your public-facing website - firewall, CDN and authoritative DNS - is a related but separate service (see Web security and performance), even though both run on the same underlying network.