Cigent extends Zero Trust directly to data at rest by pairing independent authentication with encrypted protection before sensitive data becomes available to the system or user.
Schedule a DemoZero Trust assumes that access should not be inherited simply because a user has physical access, a device is known, or a connection originates from a trusted environment. At the endpoint, the same principle should apply to the data stored on the system.
Cigent applies Zero Trust principles directly to data at rest by treating every power-on, pre-boot, and protected-data access attempt as untrusted until identity and authorization are verified. Both Cigent PBA and Cigent FDE support multi-factor authentication options, while pairing the two solutions creates independent authentication and encryption layers for defense in depth. Protected data remains locked until the applicable authentication requirements are satisfied.
Cigent PBA and Cigent FDE verifies users before the operating system loads and before protected data is made available. Access is not assumed simply because a device powers on.
Cigent limits data exposure by separating access based on user, role, or mission need. This supports least-privilege access on shared systems, multi-user devices, and platforms carrying multiple data sets.
Tamper-resistant logs record authentication and protected-data access events, providing visibility into user activity and supporting investigation, oversight, and lifecycle control.
Manage users, authentication settings, policies, configurations, and protection states through repeatable workflows across distributed endpoints.
Possession of a device, connection to an approved network, or successful access to an operating system should not automatically determine whether protected data becomes available.
Cigent begins from an unauthenticated state and requires explicit authorization before encrypted protection is lifted.
Layered protection is strongest when one authentication event does not automatically satisfy every protection boundary.
Cigent’s DAR architecture establishes independent authentication for the outer and inner layers so each layer must authorize access before its protected data becomes available.
Authentication determines whether access should be granted. Encryption provides the mechanism that keeps protected data inaccessible until that decision is successfully made.
Together, authentication and encryption create a stronger data boundary than either capability provides by itself.
Once access is authorized, additional controls can further limit exposure based on users, roles, protected storage areas, and mission requirements.
Cigent SSDs can be partitioned into up to eight independent drives, each with its own access controls. This enables mission-specific data separation and ensures users can only access the partitions relevant to their role.
Authentication by itself does not protect stored data, and encryption alone does not determine who should be allowed to unlock it. A stronger architecture connects the two: validate access, then allow the corresponding encryption protection to be removed.
That relationship is built directly into the CSfC DAR model. For full-drive encryption, NSA distinguishes between Authorization Acquisition, which handles the authentication and authorization process, and the Encryption Engine, which performs cryptographic protection. Together, the two functions establish the complete protection boundary.
Cigent is prepared to support your mission, navigating the complex compliance requirements to protect data at the edge. Its solutions were developed for and with US Federal agencies with deep expertise in data protection. Read our extensive eBook to learn more.
Learn how to secure mission-critical and classified data across the battlespace.
Download eBookLearn more about how Cigent can help you achieve your mission and protect data at rest and data on the edge from all forms of attack.
Schedule a Demo