What enables zero trust to be properly implemented and enforced between an originator and the destination application?