Topic

Zero Trust Data Format

What the Zero Trust Data Format specifies, how it relates to TDF and OpenTDF, and how policy is evaluated at decrypt time.

13 posts

ZTDF is the Zero Trust Data Format, an object format that wraps a payload in encryption and binds an access policy and integrity metadata to it. Each object carries its own policy, so the decision to release a decryption key happens at open time, wherever the object has traveled. That is cryptographic enforcement: no key release, no plaintext.

The naming causes most of the confusion. TDF is the Trusted Data Format, which originated in the US Intelligence Community; OpenTDF is the open source implementation; ZTDF is the zero trust profile of that format. A second mistake treats ZTDF as equivalent to a sensitivity label, but a label is a marking a cooperating application chooses to honor, while a ZTDF policy is enforced through key release.

Posts under this hub cover what the specification defines, how policy evaluation works at decrypt time, how ZTDF diverges from Microsoft Purview sensitivity labels, and what ACP 240 specifies for coalition use. Lattix Technologies implements ZTDF objects and their policy decision path in the Lattix Security Fabric.

Frequently asked questions

What is ZTDF?

ZTDF stands for Zero Trust Data Format, a container that holds an encrypted payload alongside an access policy and integrity metadata bound to that payload. Opening the object requires a key, and the key service evaluates the attached policy before releasing one. Policy therefore travels with the data and is evaluated on every open, including copies outside the originating environment.

What is the difference between TDF, OpenTDF, and ZTDF?

Trusted Data Format is the original specification, developed in the US Intelligence Community for binding policy and integrity metadata to a payload. OpenTDF is the open source implementation of that specification, providing libraries and services. Zero Trust Data Format is the zero trust profile of the same family, and the three terms describe a lineage rather than three competing formats.

How is ZTDF different from a sensitivity label?

A sensitivity label is metadata that instructs cooperating applications how to treat a file, and an application that ignores the label still reads the content. A ZTDF object is encrypted, so the label equivalent is enforced by a key decision rather than by application courtesy. Where a label stops carrying policy, the two approaches diverge completely in what they guarantee.

Can you revoke access to a ZTDF file after someone downloads it?

Yes, because the recipient holds ciphertext and must request a key each time they open the object. Withdrawing the policy grant or changing an attribute causes the next key request to be refused, and the local copy becomes unreadable. Revocation does not reach plaintext the recipient already extracted and saved elsewhere, which is a limit worth stating plainly.

Reading on zero trust data format

Lattix branded cover for What Is Trusted Data Format: A Technical Reference. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing an encrypted payload nested inside a manifest that carries a bound access policy.

What Is Trusted Data Format: A Technical Reference

August 22, 2026

Trusted Data Format is an open specification that wraps a file in an encrypted envelope carrying its own access policy, so the policy travels with the object and is checked every time the object is opened.

Read More →
Lattix branded cover for OpenTDF, TDF, and ZTDF: How the Three Terms Relate. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box separating a format, a profile of that format, and an implementation of it.

OpenTDF, TDF, and ZTDF: How the Three Terms Relate

August 21, 2026

TDF is a data object format. ZTDF is a coalition profile of that format. OpenTDF is the open-source specification and implementation. The three names are used interchangeably in the market and refer to different things.

Read More →
Lattix branded cover for What Is Persistent Data Protection. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing one encrypted file leaving an organizational boundary while its bound policy and key request path remain attached.

What Is Persistent Data Protection

August 21, 2026

Persistent data protection keeps an access policy bound to a data object for the life of that object, including after it is copied or downloaded to an unmanaged device. Opening the object requires a fresh authorization decision, not possession of the file.

Read More →
Lattix branded cover for How TDF Enforces Access Policy at Decrypt Time. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box tracing a key request through attribute evaluation to a signed allow or deny.

How TDF Enforces Access Policy at Decrypt Time

August 19, 2026

A TDF object is opened by requesting its key, not by holding it. This reference walks the decrypt sequence from request through attribute evaluation to key release, and describes what the decision contains and what evidence it leaves.

Read More →
Lattix branded cover for TDF vs Traditional File Encryption: What Each One Enforces. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box contrasting a key held by a holder against a policy bound to an object.

TDF vs Traditional File Encryption: What Each One Enforces

August 18, 2026

Traditional file encryption enforces key possession. Trusted Data Format enforces an access policy bound to the object and evaluated at every decrypt. Both are strong cryptography; they answer different questions.

Read More →
Lattix branded cover for How Coalition Partners Share Classified Data Without Shared Infrastructure. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a labelled object crossing between two national enclaves that share no common network.

How Coalition Partners Share Classified Data Without Shared Infrastructure

August 12, 2026

Coalition partners share classified data by binding a machine-readable confidentiality label to each object and enforcing release at the object, not by building a common network. STANAG 4774, STANAG 4778 and Federated Mission Networking define how.

Read More →
Lattix branded cover for ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing a labelled data object crossing a coalition boundary intact.

ACP 240 and Zero Trust Data Format: What the CCEB Standard Specifies

August 11, 2026

ACP 240 is a CCEB allied publication covering data-centric security interoperability, and it is where Zero Trust Data Format is specified. A ZTDF object carries NATO STANAG 4774 labels and STANAG 4778 bindings. NATO has not adopted ZTDF for its own framework.

Read More →
Lattix branded cover for Microsoft Purview Sensitivity Labels and ZTDF Diverge When the Label Stops Carrying Policy. /30 section number, label metadata versus policy-bound object comparison, IBM Plex Mono on dark grid background, yellow accent on the boundary where Purview enforcement ends and ZTDF enforcement persists.

Microsoft Purview Sensitivity Labels and ZTDF Diverge When the Label Stops Carrying Policy

June 22, 2026

Microsoft Purview sensitivity labels travel with files and provide a useful classification overlay. The label is metadata; the policy lives in the Purview service. ZTDF binds policy to the object cryptographically. Compare what survives a cross-tenant transfer in each model.

Read More →
Lattix branded cover for TDF and ZTDF for Procurement Officers. /29 section number, TDF-to-ZTDF specification diff at the policy and key access layers, IBM Plex Mono on dark grid background, yellow accent on the procurement language that resolves to a configurable capability rather than a custom integration.

TDF and ZTDF for Procurement Officers: What the Specification Actually Specifies

June 17, 2026

NSA Phase Two cites ZTDF and IC-TDF as data rights management schema examples. The two specifications differ in scope, lifecycle, and required cryptographic agility. The differences matter when writing FY27 acquisition language. Walk through what each binds and how that maps to procurable capability.

Read More →
Lattix branded cover for Cross-Domain Solutions Modernize From Guard Appliances to Object-Level Release. /27 section number, twenty-year guard lineage to ZTDF/IC-TDF object-level release, IBM Plex Mono on dark grid background, yellow accent on the object-level release decision point.

Cross-Domain Solutions Modernize From Guard Appliances to Object-Level Release

June 8, 2026

Guard appliances have served twenty years of joint and coalition cross-domain release. They evaluate data at the boundary. NSA Phase Two cites ZTDF and IC-TDF as schemas that move release evaluation to the object itself, at cryptographic speed.

Read More →
Lattix branded cover for NSA Phase Two Cites ZTDF and IC-TDF as DRM Examples. Procurement Catches Up Next. /13 section number, ZIG Phase Two metadata, Data Rights Management schema callout, IBM Plex Mono on dark grid background, surgical yellow accent.

NSA Phase Two Cites ZTDF and IC-TDF as DRM Examples. Procurement Catches Up Next.

May 12, 2026

NSA's Zero Trust Implementation Guideline Phase Two, released January 30, 2026, tells participating components to standardize a data rights management schema and cites ZTDF and IC-TDF as the examples. A recommendation, not a mandate, and enough to write a requirement against.

Read More →
Lattix branded cover for Trusted Data Format evolution from IC origins to ZTDF. /19 section number, IBM Plex Mono on dark grid background, surgical yellow accent.

Trusted Data Format: From IC Origin to ZTDF Standard

May 8, 2026

The Trusted Data Format began in the intelligence community as a solution to cross-domain data sharing. Its evolution reflects the shift from network-centric to data-centric security.

Read More →
Lattix branded cover for What is Zero Trust Data Format (ZTDF) and Why Does It Matter? /08 section number, embedded-control self-enforcing metadata, IBM Plex Mono on dark grid background.

What is Zero Trust Data Format (ZTDF) and Why Does It Matter?

February 9, 2025

ZTDF creates a self-enforcing security boundary around every data object with embedded encryption, access policies, and audit capabilities.

Read More →