Skip to main content

Zero trust access

Verify access at the application route

Pomerium verifies identity and configured context at the application route, then forwards an approved request without granting broad network access.

What this pattern controls

Explicit identity

Use an authenticated user or service identity.

Least privilege

Grant the selected application route, not the private network.

Current decision

Apply current request context where the protocol supports it.

Application enforcement

Verify access at the protected route

Pomerium acts as an identity-aware policy enforcement point for protected application routes.

  • Authenticate the user or service through the configured identity path.
  • Authorize the selected HTTP request with route policy.
  • Forward only an approved request to the private upstream.

Program boundary

Use Pomerium as one zero trust enforcement layer

Pomerium implements the access-proxy part of a zero trust architecture. It does not replace every control in a zero trust program.

  • Use Pomerium for application and service access.
  • Keep endpoint security, data classification, and application authorization in their owning systems.
  • Treat zero trust as an architecture and operating practice, not one product setting.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo