Skip to main content

Clientless Zero Trust

Protocol-aware access to web apps, Kubernetes, and SSH. Pomerium verifies identity and applies access policy before connecting users to a protected resource.

Web

Clientless access to web apps

Pomerium enables clientless access to web apps and services so there's no third-party client software to install and maintain.

Reduce management overhead
Save on IT time and reduce the overhead for installing, troubleshooting, and updating third-party clients.
Reduce latency, improve speed
Deploy Pomerium close to your applications. Authorized requests pass through your own proxy to the upstream service, without a detour through a vendor-hosted data plane.
Secure your data too
Pomerium's clientless access means your data only goes where you want it to go. Run the data plane in your own infrastructure. You control where application traffic is processed, even when Pomerium Zero manages the control plane.
Browser access architecture
Browser access through Pomerium removes the steps of installing, updating, and troubleshooting a separate client.
Pomerium routes application requests through your infrastructure without a vendor-hosted relay.
Pomerium protects services in your infrastructure.

Kubernetes

Protect access to your clusters

Pomerium acts as a reverse proxy for the Kubernetes API to add zero trust access controls. Connect with kubectl and authenticate through your existing identity provider.

Fine-grained access control
Pomerium checks access to the cluster and passes the user's identity to the API server. Kubernetes RBAC controls what that user can do.
Continuous verification
Pomerium enforces authentication, authorization, and context-awareness on each individual request.
Limits lateral movement
The Pomerium proxy knows which cluster a user should have access to. It does not grant access to any other clusters.
Monitoring
Keep a shared access audit trail across protected clusters and services.
Integrate with your identity provider
Use Pomerium CLI as the authentication provider in your kubectl configuration.
Explore Kubernetes access
A user connects through Pomerium to the API servers of authorized clusters inside the corporate network.

SSH

Native SSH. Identity-aware access.

Simple zero trust SSH access without VPNs, server agents, or a custom client.

Native SSH clients
No wrappers, no custom tools. Just your standard SSH/SCP/SFTP clients.
Continuous authorization
Pomerium continuously evaluates access policy during the SSH session.
Session recording
Record and replay interactive SSH sessions with optional session recording in Pomerium Enterprise.
Explore native SSH access

Scroll horizontally to follow the connection sequence.

The SSH client authenticates through the identity provider. Pomerium evaluates policy, creates a certificate, and connects to the SSH server. Policy evaluation continues during the session.

See native SSH access in action

The original SSH demonstration: authenticate in your browser, then return to your terminal.

"Pomerium enables true zero trust security without getting in the way of workflow or productivity. The end user experience is simple and onboarding has never been easier. It solves all the problems plaguing network administration and security frameworks while being flexible enough for any tool or application."

Bri Hatch
Bri Hatch
Sr. Director of IT Operations

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo