Zero-Trust Data Protection Architecture for Autonomous Enterprise Systems in Multi-Cloud Environments
Main Article Content
Abstract
Autonomous enterprise systems operating across distributed multi-cloud infrastructures present a fundamentally altered threat landscape that conventional perimeter-based security cannot adequately address. This paper presents a holistic Zero-Trust Data Protection Architecture (ZTDPA) tailored for autonomous workloads across heterogeneous cloud environments, such as hybrid-edge, Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS). The proposed framework brings together continuous identity verification, machine learning based adaptive trust scoring, micro-segmentation, provisioning of access in real-time, and an end-to-end orchestrator for orchestrating encryption to a single, policy coherent system. The five major cloud providers are each evaluated in this paper using experimental testing, which shows that ZTDPA delivers 61.4% mean-time-to-remediate security incident reduction, 34.8 percentage points higher mean composite GDPR/NIST compliance scores, 0.92 AUC with anomaly detection under peak concurrent load (5,000 sessions), and a throughput overhead of 7.3%. All performance improvements are confirmed by statistical analysis using Kruskal-Wallis tests, Receiver Operating Characteristic (ROC) curves and polynomial regression confirming the significance and generalizability of all improvements. The architecture is tested for regulatory compliance in terms of GDPR requirements (Article 32) and NIST SP800-207 Zero Trust principles.