Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
All Projects
Interactive security labLatest release case study

ZeroTrust Gateway

Contextual Access Broker

Static network trust cannot account for changing identity, device, and resource risk at the moment access is requested.

Interactive preview
Full demo

ZeroTrust Gateway

Security platform

ZeroTrust GatewayWorkspace6 updates
ZeroTrust Gateway · Access Broker

Every request is evaluated in context, never trusted by default. Adjust the signals and thresholds below and the transparent policy engine recomputes an explainable allow, step-up, or deny decision instantly.

Device posture

OS patch level

Geo / network

MFA status

Time of day

Behavior

Resource sensitivity

Risk breakdown

total 1
  • Device posture0
  • OS patch level0
  • Geo / network0
  • MFA status0
  • Time of day0
  • Behavior0
  • Resource sensitivity+1

Bars show each signal weighted toward the aggregate risk. Green credits reduce risk.

Policy thresholds

Allow
  • Target resource is internal
  • Low risk: access granted

Decision log

No requests logged yet. Adjust the signals and press Log request.

Zain Khalil Khan

My Role

Identity and access security engineer

What I Built

Policy-based access broker that evaluates every request against device posture, geo, MFA status, and resource sensitivity to make an explainable allow, step-up, or deny decision.

Evidence

Working interface, documented system behavior, and implementation-level decisions.

Technical Architecture

From system input to explainable output.

The control gate is shown as a first-class stage, not an afterthought added around the workflow.

Five stages connect inputs to processing, security controls, stored state, and user output.SYSTEM FLOW / ZEROTRUST GATEWAYTRACEABLE PIPELINE01INPUTSIdentity,device & requestVERIFIED STAGE02PROCESSINGContext evaluationVERIFIED STAGE03SECURITY CONTROLSLeast-privilege policyCONTROL GATE04STORAGE / STATEDecision logVERIFIED STAGE05USER OUTPUTAllow, limit or denyVERIFIED STAGEINPUT TO OUTCOME / EVIDENCE PRESERVED

Technical Decisions

  • Evaluated every request against device posture, network location, identity assurance, and resource sensitivity rather than a network perimeter.
  • Produced three outcomes instead of two, adding step-up authentication between allow and deny so a borderline request is challenged, not refused.
  • Made each decision explainable by listing the specific signals that drove it, which is what lets a help desk resolve a denial.

Security Considerations

  • Produced three outcomes instead of two, adding step-up authentication between allow and deny so a borderline request is challenged, not refused.
  • Logged every decision with its inputs, giving the audit trail that a zero-trust architecture is judged on.

Outcome & Evidence

  • Enforced deny by default so an unmatched request is refused rather than falling through to allow.
  • Weighted resource sensitivity so the same device gets different answers for a public wiki and a payroll export.
  • Logged every decision with its inputs, giving the audit trail that a zero-trust architecture is judged on.
Zero TrustAccess ControlPolicy EngineMFASecurity Architecture

Working product

Try the interactive demo.

The product experience is part of this case study. Explore it here, reset its state, or switch viewport sizes without leaving the project page.

ZeroTrust Gateway

Security platform

ZeroTrust GatewayWorkspace6 updates
ZeroTrust Gateway · Access Broker

Every request is evaluated in context, never trusted by default. Adjust the signals and thresholds below and the transparent policy engine recomputes an explainable allow, step-up, or deny decision instantly.

Device posture

OS patch level

Geo / network

MFA status

Time of day

Behavior

Resource sensitivity

Risk breakdown

total 1
  • Device posture0
  • OS patch level0
  • Geo / network0
  • MFA status0
  • Time of day0
  • Behavior0
  • Resource sensitivity+1

Bars show each signal weighted toward the aggregate risk. Green credits reduce risk.

Policy thresholds

Allow
  • Target resource is internal
  • Low risk: access granted

Decision log

No requests logged yet. Adjust the signals and press Log request.

Zain Khalil Khan

Next Case Study

Sentinel Rules Studio

Read Next Case Study