       
Zero Trust architecture assessment tool validating ZTNA config, device posture, microsegmentation, continuous verification, and identity-aware proxy deployment.
| Check | Severity | Description |
|---|---|---|
| ZTNA Configuration | 🔴 CRITICAL | Tailscale, Twingate, Cloudflare Access, Zscaler ZPA |
| Device Posture Assessment | 🟠 HIGH | CrowdStrike, SentinelOne, Kolide integration |
| Identity-Aware Proxy | 🟠 HIGH | Google IAP, AWS Verified Access, Azure App Proxy |
| Microsegmentation | 🟠 HIGH | Illumio, Guardicore, Calico, Cilium |
| Continuous Verification | 🟡 MEDIUM | Behavioral biometrics, risk-based MFA |
| mTLS Everywhere | 🟡 MEDIUM | Service mesh, WireGuard, IPsec |
| Software-Defined Perimeter | 🟡 MEDIUM | SDP controller/gateway validation |
| Legacy App Compatibility | 🟡 MEDIUM | VPN fallback, app modernization gaps |
git clone https://github.com/ridhinva/zero-trust-assessor.git
cd zero-trust-assessor
pip install requests pyyaml
python3 zero_trust_assessor.py --config zt-config.yaml --mode assessFor authorized security assessment only.