authors
Sterling Davis
Sterling Davis articles and resources from Pomerium.
Head of Product Marketing

Topic archive
More from Sterling Davis
7 Things to Know About Kubernetes Health Checks
At Pomerium, we help organizations run secure and resilient systems on Kubernetes. Health checks are a critical part of that work, yet they’re often difficult to configure effectively. As we expand our deployment and observability practices, we’ve been refining how we think about health checks, why they’re challenging, and the patterns that lead to reliability across different customer environments.
Turning SANS Critical AI Security Guidelines Into Enforceable Agentic Controls with Pomerium
Learn how to turn SANS Critical AI Security Guidelines into enforceable controls for access, monitoring, and governance with Pomerium.
The OWASP Top 10 for LLMs and How to Defend Against Them
TL;DR — The OWASP Top 10 for Large Language Model (LLM) applications highlights prompt injection, insecure output handling, and data exposure as critical risks. This guide walks through the Top 10 and shows where Zero Trust access controls, starting free with Pomerium Zero , are most effective: LLM01 Prompt Injection and LLM02 Sensitive Information Disclosure.
Why Traditional Access Controls Fail in LLM Deployments
TL;DR: Prompt-driven apps quickly outgrow static API keys and coarse Identity Access Management (IAM) roles. OWASP’s LLM risk list shows why that model breaks. The answer is continuous, identity-aware policy applied before prompts ever reach the model. Pomerium provides that control so teams can ship GenAI features with confidence.
Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.
How Shadow AI Impacts SOC 2 and HIPAA, and What to Do About It
Shadow AI bypasses critical access and audit controls required by SOC 2 and HIPAA. Learn how per-route policy with Pomerium restores visibility, enforcement, and audit readiness.
Shadow AI Is Already in Your Org. Here’s the 5-Minute Playbook to Secure It
Shadow AI tools like ChatGPT create hidden data-leak risks. Use this zero-trust playbook to discover, govern, and secure generative AI with Pomerium.

Announcing Pomerium v0.30
Pomerium v0.30 brings powerful new capabilities to teams building for a zero trust future, including:
Asana's AI Connector Leak Exposed Sensitive Data Across Organizations: What It Means for MCP Security
When news broke that Asana's MCP server had exposed sensitive data across organizations, it wasn’t just a one-off flaw. It was a warning shot for anyone integrating AI agents into their systems without guardrails.
Secure Access for Model Context Protocol (MCP)
Learn why OAuth alone can't secure the Model Context Protocol (MCP). Discover how Pomerium enforces Zero Trust for agentic AI with per-request authorization, JWT identity, and full audit logging.
What We Heard From RedMonk Analysts—And Why Agentic Access Needs a New Security Model
Model Context Protocol (MCP) is here, and LLMs are already making requests to your internal systems. The existing security model wasn’t built for this new world of autonomous agents.
Best Model Context Protocol (MCP) Servers in 2025
The Model Context Protocol (MCP) is an open standard that connects Large Language Models (LLMs) to real-world tools and data. While static chatbots like ChatGPT and Claude can summarize and respond, autonomous agents need more—they need structured, real-time context.
Agentic Access Management for Model Context Protocol (MCP) Workflows
We’re no longer designing systems where humans are the sole decision-makers. Agentic AI changes the rules. LLMs don’t just respond to prompts anymore, they make decisions autonomously within your systems.
How To Achieve Zero Trust In Kubernetes With Pomerium
Modern Kubernetes environments don’t have a perimeter (a single, predictable network boundary). Apps span clouds. Teams work from anywhere. Legacy security models—built on assumptions of a trusted internal network—start to fall apart.
Why Per-Request Authorization Is the Foundation of Zero Trust
Most access tools treat authentication like a one-time handshake. In these models, once a user or service is validated, they’re granted broad access for the rest of their session, regardless of what changes afterward.
How Pomerium Makes Access Audit Ready and Turns It Into a Source of Truth
Ask most teams to show who accessed a sensitive system—and why—and you’ll get a long pause.
How Pomerium Secures Access for Human, Service, and Agent Identities
Legacy tools were designed for single perimeters: users in offices, apps in one environment, and static roles assigned to each.
How Pomerium Enforces Real-Time, Context-Based Access
For security engineers, compliance owners, and platform teams who need smarter policies for better security posture.
Not All Zero Trust Is Created Equal: Why Enterprises Host Their Own
That’s the starting point for Zero Trust. It’s a model built on verifying every user, securing every request, and removing trust based on network location.
How Pomerium Brings Zero Trust to Legacy, Hybrid, and Cloud-Native Environments
Enterprise infrastructure doesn't live in just one place. It spans data centers, Kubernetes clusters, cloud workloads, and SaaS tools. Some of it's old. Some of it's modern. All of it needs to be secure.
How Pomerium Secures SSH Access with Zero Trust
SSH access is often treated as a static utility, but in modern environments, implicit trust just won’t cut it. This article explores how Pomerium brings Zero Trust principles to SSH — using short-lived certificates, OAuth authentication, continuous policy enforcement, and session recording — without agents or VPNs.
