Skip to main content

Why Pomerium

Reduce the trust implied by network access

Pomerium gives a user access to a selected private service after identity and policy checks. It does not grant general reach into the private network.

What this pattern controls

Narrow reach

Grant access to the required service, not the surrounding network.

Explicit trust

Use identity and request context instead of network location alone.

Verified context

Give the upstream application a signed user identity when required.

Access boundary

Replace network reach with named service access

A network connection can expose many reachable services. A Pomerium route exposes one selected upstream through one policy boundary.

  • Publish only the application routes that users need.
  • Prevent a direct network path around the proxy.
  • Keep application object and operation permissions in the upstream application.

Enforcement boundary

Make access decisions where the request enters

Pomerium moves access control from network location to verified identity, request context, and the selected service route.

  • Check policy for every protected HTTP request.
  • Validate tunneled TCP and WebSocket policy when the connection starts.
  • Pass a signed identity assertion when the upstream application needs verified user context.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo