Government & SLTT
Agency visitor networks, contractor segments, continuous diagnostics language—without claiming an ATO we do not hold.
Home · Zero Trust
ENGINE PATH · Edge · Access PEPs
Zero Trust is the Edge of the ENGINE PATH — Access PEPs: admit, isolate, deny, dual-plane. Untrusted is never enrolled. Ikaros returns acts here; the engine does not bypass enforcement. This is not a wireless SKU. Admission of untrusted identities is one Policy Enforcement Point Ikaros can actuate — one 800-207 data source, not a sister product.
Aligned to NIST SP 800-207 continuous verification concepts: never trust by network location alone; verify identity, device posture, and session context; limit lateral movement between planes.
Who this is for
Agency visitor networks, contractor segments, continuous diagnostics language—without claiming an ATO we do not hold.
Campus and facility untrusted segments vs enrolled workforce; boards care about lateral risk, not SSID marketing.
A clean access boundary that feeds fusion and PDE—not a standalone “guest Wi‑Fi box” SKU for consumers.
Two planes · one principle
Visitors, contractors, BYOD in a controlled segment. Session grant only after policy acceptance. Short-lived, isolated, instrumented. Dual-plane admission is a PEP pattern Ikaros actuates, not a consumer product.
Workforce and managed assets. Prefer 802.1X, posture, and identity-bound sessions. Content policy and selective inspection belong here—where enrollment and liability align.