Skip to content
Beta

Zero Trust Data

Last updated on

Zero Trust Data focuses on protecting sensitive information by default, regardless of where workloads run or how traffic is routed.

  • Data-centric protection: Security controls follow data classification, not infrastructure boundaries.
  • Encryption by default: Data at rest and in transit is encrypted with managed and governed key life cycles.
  • Least-privilege data access: Access is scoped to role, purpose, and operational context.
  • Verifiable handling: Access, key usage, and policy changes are observable and auditable.
  • Classify and tier data: Define protection levels for business, personal, and regulated data classes.
  • Centralize key governance: Use managed key services and documented key ownership responsibilities.
  • Separate secret and key duties: Distinguish secret life cycle handling from key life cycle governance.
  • Minimize broad data grants: Prefer short-lived, explicit access over persistent wide permissions.
  • Data protection baseline: Mandatory encryption and key rotation policies per data class.
  • Secrets operating model: Standardized secret creation, rotation, revocation, and emergency access process.
  • Access traceability: Audit paths for data access and cryptographic key operations.
  • Retention and deletion rules: Enforced life cycle policies aligned with legal and contractual obligations.

Use the Secrets Manager capabilities below to implement the secrets operating model. Define owners, access reviews, rotation, and emergency revocation separately; service features alone do not establish those governance controls.

From the STACKIT docsFeatures, use cases and service plans › FeaturesSource updated 26.08.2026 · copied 06.10.2026
  • Storage of secrets in accordance with security requirements (e.g. separation of source code and secrets)
  • The customer can order a Secrets Manager quickly and easily via the self-service user interface in the STACKIT Portal
  • Secrets can be managed via a user-friendly configuration interface and API
  • Traceability of changes through versioning of individual secrets
  • Preconfigured auto-update functions keep components up to date
  • High availability ensures the secure operation of the Secrets Manager
  • Temporary authentication lockouts protect userpass and AppRole logins against repeated failed attempts
What is this?

This section is copied from the STACKIT docs automatically, several times a day. It cannot be changed here. Changes belong in the STACKIT docs.

  • Encryption without governance: Keys exist, but ownership and life cycle are undefined.
  • Secrets in code and pipelines: Sensitive values are handled outside managed secret controls.
  • One-size-fits-all retention: Data classes with different obligations share the same life cycle rules.