Capability

Zero-Trust Architecture

Deny-by-default fabric operators keep

Deny-by-default fabric for operators who already run production under real constraints. Identity, devices, networks, applications, data, and agents — each with a named owner and a verification path. Same security bar for private and commercial clients; dense federal mappings live on the Federal Buyers path.
Target Sectors:DefenseFederal GovernmentCritical Infrastructure

Mission impact

Implicit trust is a design choice adversaries exploit. Raising the cost of lateral movement after compromise shrinks blast radius and makes posture legible to operators who have to defend it. We implement controls with owners and runbooks, then leave the environment defensible without a permanent vendor in the middle.

Implicit trust on the network is a design choice adversaries exploit. Zero trust is the counter-design — and it is not a product. No single tool achieves it. It is a set of principles, codified in NIST SP 800-207 and matured through models like CISA ZTMM, that must be engineered into infrastructure and workflows across identity, devices, networks, applications and workloads, and data.

Wilkes & Liberty is a company of forward-deployed engineers for that last mile. We sit with operators who already run production under real constraints, map what is actually trusted today, implement deny-by-default controls with owners and runbooks, and leave the environment defensible without a permanent vendor in the middle. Every control we implement for you is one we operate on our own estate.

Private and commercial clients get the same engineering security bar we design for mission environments: least privilege, fail-closed defaults, continuous posture, and audit-ready evidence. Dense federal strategy mappings, CUI handling, and acquisition artifacts live on the Federal Buyers path; the delivery discipline is universal.

What we implement on the ground

  • Deny-by-default network policy as code — encrypted mesh networking with explicit, group-based access grants managed in version-controlled Terraform, validated by policy tests before every apply. No device reaches a service without a reviewable rule; no traffic, internal included, moves unencrypted.
  • Boundary and segment isolation — split DNS that keeps internal service names unresolvable from outside the boundary, public ingress confined to hardened reverse proxies in a separate segment, and VLAN segmentation that blocks lateral movement between trust zones — including egress-only zones for untrusted devices — across IPv4 and IPv6.
  • Continuous device inventory and posture — a dynamic inventory of every asset that can touch the network, including hardware, software, firmware, configuration, and known vulnerabilities, with continual patching rather than intermittent remediation.
  • Layered authorization — network-level access control, identity-aware proxy gates that evaluate group claims per host, per-environment authentication clients, and local credentials so a single compromised layer does not grant access.
  • Secrets under your key material — full-lifecycle secrets management with encryption machine-enforced before commit, runtime-only decryption, and push-blocking secret scanning in the delivery pipeline.
  • Governed agent access — least-privilege, auditable control over what AI agents may read, write, and never do inside your systems of record.

Tenets that resolve to owners

NIST SP 800-207's seven tenets are worth taking literally: every data source and computing service is a resource; all communication is secured regardless of network location; access is granted per session by dynamic policy; authentication and authorization are enforced before access, never after; asset integrity is continuously monitored; and the enterprise collects and uses state about its assets and communications to improve posture. In most strategy decks these read as aspirations. In our practice each tenet resolves to a specific control with a named operator and a verification path.

Identity that enforces least privilege

Network controls govern how traffic flows; identity governs who may authenticate and what they may reach once connected. We design identity and access-management architectures on customer-controlled OIDC infrastructure with multi-factor enforcement, group-based authorization evaluated at the proxy layer, and strict per-environment client isolation — a credential issued for staging is structurally useless against production. Because clients are isolated and secrets rotate on defined procedures, revocation is routine: retiring a client invalidates every credential ever issued against it. Single sign-on makes the compliant path the convenient one for operators and non-person entities alike.

Devices you can account for

A device is any asset that can connect to your network — servers, workstations, printers, mobile phones, IoT hardware, networking equipment, and authorized personal devices. Zero trust requires each to be identified, inventoried, authorized, and authenticated on a regular basis, not vetted once and trusted thereafter. Managed devices hold explicit, revocable grants; devices that are authorized but not enterprise-controlled are risk-managed with constrained access; unrecognized devices are confined to egress-only zones. Because the inventory tracks configuration and vulnerability state as it changes, patching is continuous rather than periodic.

Secrets under your key material

Credentials embedded in repositories or passed as plaintext are a persistent source of risk. We implement secrets management across the full credential lifecycle using SOPS with AGE encryption — a self-hosted, vendor-independent pattern that requires no third-party vault or cloud key-management service and keeps encrypted secrets under key material you hold. Encryption is machine-enforced before a secret can enter version control; runtime decryption keeps plaintext off disk and out of configuration at rest; secret scanning with push protection blocks credentials from entering the repository; defined key-lifecycle procedures govern generation, access, rotation, and compromise handling.

Applications that assume a hostile network

Applications can no longer rely on perimeter protections. The working assumption is that every application is internet-accessible from a security perspective, whether or not it is today. Operators log into applications, not networks: identity-aware gates evaluate authorization per request, and security controls sit close to the application, the workload, and the data. Workloads — including containers and virtual machines — are continuously monitored and secured. Delivery follows DevSecOps practice with immutable workloads where possible through our DevSecOps capability. Adversaries test continuously; so do we — robust internal testing, independent perspectives when warranted, and a coordinated path for vulnerability disclosure.

Data on a need-to-know basis

Data is the asset every other pillar exists to protect — structured and unstructured, live and backed up, on-premises and virtual, along with its metadata. Protection starts with knowing what you hold: inventory, categorize, and label so isolation becomes possible and access is granted on a genuine need-to-know basis, whether the requester is an operator or a workload. Data is encrypted at rest and in transit; mechanisms detect and stop exfiltration; data-governance policies are crafted and reviewed so lifecycle security is enforced, not only written down. Controlled delivery of sensitive documents pairs with patterns such as file_gate and our Enterprise Content Management practice.

Zero trust for AI agents

AI agents are a new class of privileged actor, and most organizations grant them more access than they would grant a contractor. We extend zero trust to the agent plane: agents authenticate with scoped, revocable OAuth credentials; per-role policy profiles gate every operation against entity allowlists and field-level redaction; publishing and other one-way-door actions remain structurally reserved for accountable operators; every agent action is recorded in a tamper-evident, hash-chained audit log whose integrity can be verified on demand. We build and maintain this governance tooling as open source (mcp_sentinel, field_guard, audit_chain), and it runs in production on our own platforms. Building the agents is Agentic AI Development; the control plane is AI Governance & MCP Integration.

Security as an operational condition

A defensible posture is an operational condition, not a project state. We establish an honest baseline of what is actually running and where the gaps are, execute hardening by priority — configuration, patching, access-control tightening — with documented evidence, and run vulnerability management as a continuous function with defined remediation windows, including same-day response for critical advisories. Incident-response readiness is engineered: severity-tiered playbooks, triage procedures operators can execute under pressure, and structured exercises that validate the response before an incident makes the gaps visible.

Visibility and analytics feed policy decisions and response. Automation and orchestration connect security response across products so defenses orient in real time — with operator oversight retained where irreversible actions matter. Governance is the policies, procedures, and enforcement that keep operators, process, and technology aligned to mission, risk, and compliance objectives across every pillar. Continuous signal without action is noise — pair this practice with Observability & Monitoring.

Controls you can inspect and operate

Components we operate and publish include field-level policy (field_guard), controlled document delivery (file_gate), hash-chained audit (audit_chain), and governed agent access (mcp_sentinel). They substantiate specific controls without dictating the customer architecture. Paladin is the related identity and access platform for environments where that integrated approach fits.

Not compliance paper alone, not private infrastructure alone

Authoring assessor-facing control narratives and living SSP/POA&M discipline is Compliance & Security Governance. The environments beneath the fabric are Private Infrastructure. Pipeline and release control are DevSecOps.

Engagement path

Unsure where implicit trust still lives in your environment? Start with the AI & Sovereignty Readiness Assessment when AI exposure is part of the map, or Open a ticket for a zero-trust baseline — structured intake (problem, systems, constraints, desired outcome) lands in our private queue for triage into assessment, implementation, or managed ops. Prefer continuous hardening inside your boundary? That is managed ops.

Where implicit trust is creating exposure

Security, identity, infrastructure, application, and data owners use this capability to replace inherited trust with explicit verification and accountable access. It becomes urgent when remote and on-premises boundaries no longer match, privileged access is difficult to explain, service or agent credentials are too broad, sensitive data is reachable through multiple paths, or modernization needs security designed in rather than reviewed afterward.

From trust-path map to enforced policy

Identities, devices, workloads, networks, applications, data, secrets, logging, and operator procedures are examined as one trust system. We map assets and access paths, prioritize high-consequence flows, design enforceable policies, implement controls in increments, test allowed and denied paths, and transfer ownership through diagrams, evidence, runbooks, and a sequenced roadmap. The result is an operating model for continual verification, not a product installation.

What becomes verifiable

  • A trust-boundary and privileged-access map with named control owners.
  • Implemented identity, segmentation, secrets, data, and agent-access controls in the agreed scope.
  • Verification evidence, exception handling, incident procedures, and a prioritized maturity roadmap.

Key capabilities

  • Mesh VPN design and ACL engineering

    Encrypted mesh VPN architecture with node-level ACL enforcement defining exactly which nodes may communicate with which, on which ports, using which protocols — with no implicit trust between nodes on the same network.

    Mission benefit: Lateral movement following a node compromise is constrained by the ACL design, not by the adversary's self-restraint.
  • Split DNS architecture

    Separate internal and external DNS resolution zones with authoritative servers for each, ensuring internal service names are not exposed to external resolution and external DNS does not reveal internal network topology.

    Mission benefit: Internal infrastructure is not discoverable through DNS enumeration from outside the network boundary.
  • Public-ingress isolation design

    Segmented network architecture placing public-facing services in a dedicated ingress zone — reverse proxies and load balancers — that is separated from the internal network plane by explicit ACL boundaries.

    Mission benefit: Public exposure is limited to defined ingress points; internal services are not directly reachable from the public internet under any configuration.
  • Exit-node continuity engineering

    Redundant egress path design with failover behavior, health monitoring, and defined promotion procedures that maintain outbound connectivity under individual node failure without routing traffic through unauthorized paths.

    Mission benefit: Loss of a single egress node does not break outbound connectivity for the environment or force traffic through uncontrolled paths.
  • Network architecture review and remediation planning

    Assessment of the existing network architecture against zero-trust design principles — identifying implicit trust relationships, flat network segments, and ACL gaps — with a prioritized remediation roadmap.

    Mission benefit: Your organization's actual network exposure is documented and addressed, not estimated based on intent.

Sovereignty features

Every control in this architecture runs on infrastructure you control and answers to key material you hold. The network fabric's control plane, the identity provider, and the monitoring stack are self-hosted within your boundary — no third-party vault, cloud KMS, or external identity service sits in the trust path, and no telemetry leaves your environment. Encrypted secrets remain under AGE keys you generate, rotate, and revoke; retiring a key or client severs every credential ever issued against it. The stack is built on open, vendor-independent patterns — encrypted mesh networking, OIDC, SOPS, Terraform — so the architecture survives any single vendor and operates identically in connected, partially connected, and air-gapped configurations. Zero trust that depends on someone else's cloud is a dependency, not a posture; this one is yours.

Defense & government relevance

Built for the environments defense and federal work demand. Network architecture supports air-gapped, disconnected, and partially connected configurations across IPv4 and IPv6, and aligns to least-privilege principles under NIST SP 800-171 and zero-trust guidance under NIST SP 800-207, with control-plane components running in customer-controlled infrastructure. Implementation roadmaps map to the Federal Zero Trust Strategy (OMB M-22-09) and to maturity stages across the five pillars and three cross-cutting capabilities of the CISA Zero Trust Maturity Model. Secrets management requires no third-party vault or cloud KMS and aligns secret-scanning governance to Executive Order 14028. Security assessments map findings to NIST SP 800-171 and CMMC controls in formats suitable for System Security Plan integration and ATO support, with hardening referenced to CIS benchmarks and applicable STIG guidance and CUI handled under 32 CFR Part 2002. All monitoring and telemetry remain in customer-controlled infrastructure. Dense control mappings and acquisition artifacts belong on the Federal Buyers path; the main page states the universal engineering bar.