Skip to main content

authors

Sterling Davis

Sterling Davis articles and resources from Pomerium.

Head of Product Marketing

Sterling Davis

Topic archive

More from Sterling Davis

7 Things to Know About Kubernetes Health Checks
blog posts

7 Things to Know About Kubernetes Health Checks

At Pomerium, we help organizations run secure and resilient systems on Kubernetes. Health checks are a critical part of that work, yet they’re often difficult to configure effectively. As we expand our deployment and observability practices, we’ve been refining how we think about health checks, why they’re challenging, and the patterns that lead to reliability across different customer environments.

The OWASP Top 10 for LLMs and How to Defend Against Them
blog posts

The OWASP Top 10 for LLMs and How to Defend Against Them

TL;DR — The OWASP Top 10 for Large Language Model (LLM) applications highlights prompt injection, insecure output handling, and data exposure as critical risks. This guide walks through the Top 10 and shows where Zero Trust access controls, starting free with Pomerium Zero , are most effective: LLM01 Prompt Injection and LLM02 Sensitive Information Disclosure.

Why Traditional Access Controls Fail in LLM Deployments
blog posts

Why Traditional Access Controls Fail in LLM Deployments

TL;DR: Prompt-driven apps quickly outgrow static API keys and coarse Identity Access Management (IAM) roles. OWASP’s LLM risk list shows why that model breaks. The answer is continuous, identity-aware policy applied before prompts ever reach the model. Pomerium provides that control so teams can ship GenAI features with confidence.

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
blog posts

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes

TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo