Zscaler & Zero Trust operations glossary ยท Products & platform

What is the Zero Trust Exchange?

Definition

The Zero Trust Exchange is Zscaler's cloud platform, the shared foundation for services such as ZIA, ZPA, ZDX and ZIdentity. It sits inline in the data stream: every connection is decrypted, checked against security policies and threat intelligence, and only then re-encrypted and forwarded, or blocked. Instead of letting users into a network wholesale, the platform checks every single connection on the zero trust principle: no implicit trust, regardless of whether access comes from the office, from home, or on the road.

Zero Trust Exchange in detail

Technically, it is a globally distributed network of data centres that users connect to through the Zscaler Client Connector or a PAC file. From there, the individual services take over: ZIA for internet and cloud access, ZPA for private business applications, ZDX for measuring the user experience. All of them share the identity, policy model and logging of the same platform.

Programmatic access to this data goes through the official Zscaler OneAPI interface, which independent cockpit solutions such as CentaurNexus also build on, without being part of the Zero Trust Exchange themselves.

Why the Zero Trust Exchange matters in Zscaler operations

As the shared foundation for all Zscaler services, the Zero Trust Exchange determines how policies, identities and logs work together across ZIA, ZPA and ZDX. Anyone responsible for IT operations needs to understand that a problem in one service often has knock-on effects on another, for example when an identity issue affects both ZIA and ZPA access.

For the evidence requirements under NIS2 and DORA, it matters that the platform logs centrally: events from different services can generally be mapped onto a shared timeline, which makes audits easier.

Common sources of error

Zero Trust Exchange in practice: what CentaurNexus contributes

CentaurNexus positions itself as a cockpit on top: through Zscaler OneAPI, it brings data from ZIA, ZPA and ZDX together in one understandable, role-based view, working purely as a read layer above the Zero Trust Exchange. Helpdesk roles get the relevant status across every service in one place this way, with no admin rights of their own needed on the platform, while changes continue to go through the official Zscaler console. The guide below describes what this cross-service view looks like in practice: Zscaler support without admin rights.

Watch the live demo to see how CentaurNexus sits as a cockpit on top of the Zero Trust Exchange.Watch the live demo

Related terms

Frequently asked questions about the Zero Trust Exchange

What is the Zero Trust Exchange?

The Zero Trust Exchange is Zscaler's cloud platform that services such as ZIA, ZPA, ZDX and ZIdentity build on. It sits inline in the data stream: every connection is decrypted, checked against policies and threat intelligence, and only then forwarded or blocked, instead of letting users into the network wholesale.

What does 'inline' mean in this context?

Inline means that traffic actually flows through the Zscaler cloud and is inspected there in real time, rather than just being read passively or analysed after the fact. Only inline can a connection still be blocked or adjusted before it reaches its destination.

Which services run on the Zero Trust Exchange?

The core services include ZIA for internet and cloud access, ZPA for private business applications, ZDX for experience measurement, and ZIdentity for identity. All of these services share the same platform, the same identity, and a common policy model.

How does CentaurNexus relate to the Zero Trust Exchange?

CentaurNexus is not part of the Zero Trust Exchange. It is an independent cockpit that brings together data from ZIA, ZPA and ZDX through the official Zscaler OneAPI interface. It is the optimal complement to your Zscaler security stack, and delivers a clear, role-based operational view.

Why is the Zscaler admin console often not enough for the helpdesk?

The Zero Trust Exchange admin console is built for configuration and administration, and requires correspondingly broad rights. For day-to-day case handling in the helpdesk, that is often too powerful and too complex, which is why many organisations want a leaner, role-based view instead.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.