Understanding Trust Zones in TripleSOC
TripleSOC enriches every security event with trust zone context — a classification that tells your team not just what happened, but who was involved and how much to trust them.
This is powered by TripleEnablement, TripleCyber's zero-trust identity layer.
The Three Trust Zones
Anonymous Zone
Color: Red
The lowest trust level. An endpoint or identity in the Anonymous zone has not been verified by TripleEnablement. This includes:
- Unrecognized devices connecting to your network
- Guest users or unauthenticated sessions
- External IP addresses with no identity validation
- Devices that have not completed TripleEnablement enrollment
What it means for security: Alerts from Anonymous zone sources require the highest scrutiny. Treat activity from this zone as potentially hostile until proven otherwise.
Verified Zone
Color: Black
A mid-tier trust level. The identity has been verified through TripleEnablement — email, phone, or social validation is confirmed — but does not hold a fully trusted certificate.
Verified zone sources include:
- Enrolled users who have completed basic identity verification
- Corporate devices that have passed standard enrollment
- Partners or contractors with validated identities
What it means for security: Alerts from Verified zone sources are lower risk than Anonymous but still require investigation. This zone is appropriate for most standard employees and contractors.
Secure Zone
Color: Green
The highest trust level. The identity and device have been fully validated through TripleCyber's PKI and OAuth infrastructure. Secure zone status is earned through:
- TriplePKI certificate enrollment
- TripleOAuth authentication
- Full TripleEnablement verification across all factors (email, phone, documents)
What it means for security: Alerts from Secure zone sources are the lowest risk, but they still appear in TripleSOC. A Secure zone user could still be the victim of a compromised session or insider threat.
Trust Zone Scores (ZTRS)
Each agent in TripleSOC carries a Zero Trust Risk Score (ZTRS) — a numerical score from 0 to 1,000.
| Score Range | Zone | Meaning |
|---|---|---|
| 0 – 499 | Anonymous | High risk, unverified |
| 500 – 799 | Verified | Moderate risk, identity confirmed |
| 800 – 1,000 | Secure | Low risk, fully trusted |
The ZTRS is calculated from multiple TripleEnablement data points, including IP reputation, device posture, identity verification status, and behavioral signals.
Trust Zones in the Dashboard
Trust zone context appears throughout TripleSOC:
- Security Overview — Trust Zone Distribution chart shows how your agents break down across zones
- Agent List — each agent shows its current zone with a color indicator
- Alert Detail — every alert shows the zone of the source agent
- Executive Report — zone distribution trend over time
Using Trust Zones for Triage
When reviewing alerts, use trust zone as a prioritization signal:
- Anonymous zone + Critical severity → Investigate immediately. High likelihood of external attack or unauthorized access.
- Anonymous zone + Medium severity → Elevate priority. Unknown source activity warrants faster review.
- Verified zone + any severity → Standard triage. Follow normal investigation procedures.
- Secure zone + High/Critical severity → Could indicate compromised trusted account or insider activity. Escalate for review.