---
title: Zero Trust Data
description: Protect data through encryption, key governance, and least-privilege data access patterns independent of network location and runtime placement.
sidebar:
  label: Zero Trust Data
  order: 17
source_url: "https://framework.stackit.cloud/migration/design-and-mobilize/security-and-compliance/zero-trust-data/"
source_file: "docs/migration/design-and-mobilize/security-and-compliance/zero-trust-data.mdx"
---

## Purpose

Zero Trust Data focuses on protecting sensitive information by default, regardless of where workloads run or how traffic is routed.

## Control objectives

- **Data-centric protection**: Security controls follow data classification, not infrastructure boundaries.
- **Encryption by default**: Data at rest and in transit is encrypted with managed and governed key life cycles.
- **Least-privilege data access**: Access is scoped to role, purpose, and operational context.
- **Verifiable handling**: Access, key usage, and policy changes are observable and auditable.

## Design recommendations

- **Classify and tier data**: Define protection levels for business, personal, and regulated data classes.
- **Centralize key governance**: Use managed key services and documented key ownership responsibilities.
- **Separate secret and key duties**: Distinguish secret life cycle handling from key life cycle governance.
- **Minimize broad data grants**: Prefer short-lived, explicit access over persistent wide permissions.

## Implementation checkpoints

- **Data protection baseline**: Mandatory encryption and key rotation policies per data class.
- **Secrets operating model**: Standardized secret creation, rotation, revocation, and emergency access process.
- **Access traceability**: Audit paths for data access and cryptographic key operations.
- **Retention and deletion rules**: Enforced life cycle policies aligned with legal and contractual obligations.

## STACKIT references

- **KMS**: <LinkChip href="https://docs.stackit.cloud/products/security/kms/">Documentation</LinkChip>
- **Secrets Manager**: <LinkChip href="https://docs.stackit.cloud/products/security/secrets-manager/basics/features-use-cases-and-service-plans/">Documentation</LinkChip>

Use the Secrets Manager capabilities below to implement the secrets operating model. Define
owners, access reviews, rotation, and emergency revocation separately; service features alone
do not establish those governance controls.

> From the STACKIT docs: [Features, use cases and service plans › Features](https://docs.stackit.cloud/products/security/secrets-manager/basics/features-use-cases-and-service-plans/#features) (Source updated 26.08.2026, copied 06.10.2026)

- Storage of secrets in accordance with security requirements (e.g. separation of source code and secrets)
- The customer can order a Secrets Manager quickly and easily via the self-service user interface in the STACKIT Portal
- Secrets can be managed via a user-friendly configuration interface and API
- Traceability of changes through versioning of individual secrets
- Preconfigured auto-update functions keep components up to date
- High availability ensures the secure operation of the Secrets Manager
- Temporary [authentication lockouts](https://docs.stackit.cloud/products/security/secrets-manager/how-tos/handle-authentication-lockouts/) protect `userpass` and AppRole logins against repeated failed attempts

## Anti-patterns to avoid

- **Encryption without governance**: Keys exist, but ownership and life cycle are undefined.
- **Secrets in code and pipelines**: Sensitive values are handled outside managed secret controls.
- **One-size-fits-all retention**: Data classes with different obligations share the same life cycle rules.
