Explicit identity
Use an authenticated user or service identity.
Zero trust access
Pomerium verifies identity and configured context at the application route, then forwards an approved request without granting broad network access.
Use an authenticated user or service identity.
Grant the selected application route, not the private network.
Apply current request context where the protocol supports it.
Application enforcement
Pomerium acts as an identity-aware policy enforcement point for protected application routes.
Program boundary
Pomerium implements the access-proxy part of a zero trust architecture. It does not replace every control in a zero trust program.
Pomerium zero trust principles and architecture references.
Context-aware route policy for protected requests.
The Pomerium services that authenticate, authorize, and proxy traffic.