ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Zero Trust · Get the basics right
Zero Trust works when
the architecture is right.
Strategy and policy are only as good as their implementation. These deep dives go to the architectural layer — how AUXO™ processes Zero Trust natively, how AI agents change the identity problem, how protect surfaces drift in cloud environments, and how to plug your ZT controls directly into your AI toolchain.
For Security Architects · DevSecOps · SOC Engineers · Cloud Architects
Architecture Difference
Every SIEM and SOAR bolts Zero Trust on after the fact. AUXO™ uses the protect surface as its native data schema — ZT context is not a report, it is the database.
Non-Human Identity
In agentic AI environments, software identities outnumber human ones 10:1. The standard CISA five-pillar model does not cover this. These deep dives do.
Toolchain Integration
AUXO™ MCP server surfaces Zero Trust controls inside Claude, Cursor, VS Code, and any MCP-compatible agent — without leaving your workflow.
Technical Deep Dives
Architectural & Operational Intelligence
For security architects, engineers, and practitioners building Zero Trust in production
5 deep dives · 4–8 min each
Canonical Reference · Definitions by John Kindervag · Updated 2026
The Zero Trust Dictionary
The authoritative Zero Trust lexicon updated for the AI era — with nine new terms covering Non-Human Identity, Ephemeral Privilege, Intent Validation, Behavioral Monitoring, and more. One shared language across board, management, and engineering. No ambiguity.
Zero TrustDAASProtect Surface Kipling MethodMaturity Model Non-Human IdentityEphemeral PrivilegeAI Era
Open Dictionary
17 core terms · 9 AI extensions
AUXO™ Platform · ON2IT
The only SIEM/SOAR built on Zero Trust architecture
Every other platform in the market was built as an event pipeline first and bolted Zero Trust reporting on later. AUXO™ was built differently — the protect surface is its native data schema. That architectural difference is what makes EventFlow's agentic AI work: it enriches events with ZT context before analysis, not after. The result is a detection and response capability that scales with Zero Trust maturity, not despite it.
69 → 3
Events to analyst investigations via EventFlow AI
24/7
Managed GSOC — detection, response, prevention
100%
ZT-native data schema — not a reporting layer

Frequently Asked Questions

What makes AUXO™ different from other SIEM/SOAR platforms?

Every other SIEM, SOAR, and MDR platform handles Zero Trust as an event pipeline first, with ZT reporting bolted on afterwards. AUXO™ uses the protect surface as its native data schema, which is what lets EventFlow's agentic AI reduce 69 events to 3 analyst investigations.

Why does non-human identity matter for Zero Trust?

In agentic AI environments, non-human identities outnumber human ones 10:1, and the standard CISA five-pillar model does not cover this. Zero Trust for AI agents maps each pillar to what it means when the actor is software.

How current does protect surface metadata need to be?

In cloud environments, protect surface metadata drifts by default. There is a five-stage maturity ladder for keeping it current, and AUXO™'s Azure API reaches Stage 5: real-time source capture.

What is the Zero Trust Dictionary?

The Zero Trust Dictionary is the authoritative Zero Trust lexicon, with definitions by John Kindervag, updated for 2026 with nine new terms covering Non-Human Identity, Ephemeral Privilege, Intent Validation, and more.

Can Zero Trust stop attacks that don't use malware or a known vulnerability?

Yes. In the SalesLoft Drift breach, 700+ organisations were hit by valid credentials used from a slightly wrong IP range, with no CVE and no IOC involved. The Kipling Method's WHERE question would have stopped it.