Skip to content

Glossary

External trust boundary

The line where your controls stop and a third party’s begin.

Definition

An external trust boundary is the point at which data, credentials or control leave the domain governed by your organisation and enter one governed by someone else. Everything downstream of it is subject to that party’s controls, and most of it is not observable from your side.

The problem

Boundaries are usually drawn around the network perimeter, which is where they stopped being meaningful. A dependency call crosses a boundary wherever payload or credential leaves the domain - through a managed gateway, a resolver, a provider edge - and those crossings are frequently absent from both the dependency inventory and the security review.

Why it matters

A control that cannot be enforced at a boundary has to be enforced before it, or accepted as trust. Knowing which is which is the difference between an architecture with stated assumptions and one with unstated ones.

Practical example

Mutual TLS and workload identity establish who is calling. They establish nothing about what the callee does with the payload, which model serves it, or where inference is executed - so the enforceable controls at a model-API boundary are architectural and contractual, not cryptographic.

How RELIASTRA approaches it

RELIASTRA observes dependencies from outside both stacks, which makes the boundary itself measurable: an independent, timestamped record of what the external side did, kept separate from your own incident history so the two can be compared rather than merged.

Know what you depend on. Prove what it did.

RELIASTRA observes the external services your product relies on, attributes their failures, and produces evidence you can act on. Every new organization starts on a 14-day Pro trial.