Zero Trust Security: The Journey Ends at the Data
While zero trust is widely adopted in principle, it is unevenly implemented in practice, with most deployments stopping at the boundary. That gap is increasingly where risk concentrates.
Identity, endpoint, network, and cloud controls have transformed how organizations secure access. They help answer essential questions like who is requesting access, what device or workload is acting, what application is mediating the request, and what policy applies within context.
But one question often remains unanswered: What controls persist after the data moves?
In most architectures, the answer is none. Policy is enforced at the point of access and then surrendered at the point of egress. Once a file is downloaded, shared, forwarded, or synced into someone else's environment, the controls that governed it no longer apply; the data keeps moving while the policy stays behind.
In order to gain true zero trust controls, policy should travel with the data itself, so that permissions, restrictions, and revocation remain enforceable wherever the data lands. Only then do organizations and individuals have genuine agency over their information, rather than agency that expires the moment the data leaves the perimeter.
The Control Gap
Security architectures have long concentrated protection at the places where data is stored and accessed, treating controlled environments as the primary unit of assurance. That model becomes less effective as sensitive data moves through cloud platforms, APIs, supply chains, analytics systems, vector databases, and autonomous agents.
This new reality requires an object-level approach.
Most zero trust controls operate around data. They enforce policy at an identity provider, endpoint, network segment, application, or cloud boundary.
Those controls remain essential, but they may no longer govern information once it is downloaded, forwarded, shared with a partner, or introduced into an AI workflow.
AI widens the control gap into a chasm. As Booz Allen’s Imran Umar explained in his recent article, Data Security in the Age of AI: Why Policy Must Travel with Your Data, a system’s ability to access information does not mean every user, workload, or agent is authorized to use it. AI can compound this risk by combining information from multiple sources to reveal sensitive insights that no single document contains. And worse, feeding it to those who shouldn’t have access.
Authorization therefore cannot depend exclusively on the repository or application holding the data. It must remain connected to the data itself.
Extending Zero Trust to the Data Layer
Imagine a world where a sensitive file carries its own encryption, access policy, and authorization requirements. Not as a label beside the data, or a rule that only one application understands, but as cryptographically bound protection that remains with the object.
When the data moves, the policy moves. When someone requests access, authorization is evaluated using current identity, attributes, and context. If conditions change, access can be revoked without attempting to retrieve every copy of the information.
In case you didn’t know; that world already exists. And it’s made possible through the Trusted Data Format, or TDF. The OpenTDF standard provides an interoperable approach for binding security policies to individual pieces of data. Its architecture supports object-level encryption, attribute-based access control, policy integrity, federated key management, and auditability across organizational and technical boundaries.
Just as Kubernetes transformed application architecture with microservices, TDF brings "micro-security" to data, enabling precise control and protection no matter where the data travels.
TDF does not replace identity, endpoint, application, or downstream security controls. Instead, TDF closes the chasm by keeping authorization enforceable while protected data is in motion and outside its original system.
Why Open Standards Matter
Persistent data protection cannot depend on every recipient using the same proprietary ecosystem. We know that for sure.
Information may need to move among government agencies, coalition partners, regulated enterprises, disconnected environments, and AI platforms. Protection must therefore be interoperable, programmable, and independently verifiable.
OpenTDF provides that foundation. It gives developers and organizations a common specification and open-source building blocks for implementing data-centric security without tying protection to a single repository or transport system.
That openness is fundamental to building trust across organizational boundaries.
Virtru and Booz Allen: Advancing the Zero Trust Data Exchange
We’re thrilled to help bring this approach into Booz Allen’s Zero Trust Data Exchange, or ZTDX.
ZTDX is Booz Allen's multi-domain implementation of data-centric zero trust at the edge: an all-encompassing framework for protecting information from the first mile to the last, regardless of where it travels.
Virtru's platform is the core data protection layer of ZTDX. It enables the identity-centric model for secure data collaboration that regulated enterprises, federal agencies, and intelligence community organizations require. TDF applies protection that persists across boundaries, policy that travels with every object, and revocation that works in seconds when conditions change.
Booz Allen contributes deep mission, architecture, and implementation expertise. Virtru contributes an open, programmable data-protection layer built for interoperable, cross-boundary enforcement.
Together, these capabilities create a foundation for secure partner collaboration, multi-domain policy enforcement, governed AI pipelines, and other workflows in which information must move quickly across complex and distributed environments.
Completing the Zero Trust Journey
For security leaders, it’s a simple test.
-
If sensitive data leaves your environment, does its policy travel with it?
-
Can access be evaluated using the recipient’s current identity and attributes?
-
Can access be revoked after the data has been shared?
-
Can you audit access after information crosses a boundary?
-
Can those controls extend into AI retrieval, analysis, and agent workflows?
If the answer to any of these questions is no, your zero trust journey is not complete.
The identity, endpoint, network, and application layers remain indispensable. But zero trust cannot stop there. It must extend to the information those layers were built to protect.
We stopped trusting the network. Now, it’s time to make security travel with the data.
See Virtru In Action
Sign Up for the Virtru Newsletter
Dive Deeper
/blog%20-%20Cymphony/cymphony-ai-workforce.webp)
Cymphony, AI Agents, and the Case for Security That Travels With Data

Nikesh Arora Is Right: It’s Time to Rethink Your Cyber Security Architecture

IBM’s Breach Report Makes the Case for Object-Level Data Security

Should You Go Against the Flow? Virtru vs. FlowCrypt PGP Encryption

The DoD SAFE Alternative Your Team Will Actually Use

Are Google Workspace and Microsoft 365 HIPAA Compliant? What to Know in 2026
/BLOG%20-%20BLACK%20HAT%202026/black-hat-2026-learnings.webp)
Notes from Black Hat 2026: Data Sovereignty, the AI Harness, and a Billion-Dollar Signal

Google Client-Side Encryption for Workspace: A Guide to Your Options with Virtru

How to Encrypt Email in Outlook: Your Full Guide

AI Sovereignty isn't Something You Buy. It's Something You Build.
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.