Pomerium Zero Trust Proxy logo

Pomerium Zero Trust Proxy

Network & Infrastructure SecurityZero Trust Network Access (ZTNA)

Identity-aware proxy for zero trust access to applications without VPN or client software.

Vendor Information

Pomerium logo

Pomerium

Solana Beach, CA, United States

Pomerium Zero Trust Proxy Overview

Pomerium is an open-source identity-aware proxy platform from Pomerium Inc., founded in 2019 by Bobby DeSimone (former founder of BeyondTrust) and headquartered in Solana Beach, California. The company has raised $18M in total funding, including a $13.75M Series A led by Benchmark in June 2024, with participation from Bain Capital, Haystack, SNR, and angel investors. The platform has achieved significant traction with over 1 billion Docker downloads and serves organizations from individual developers to Fortune 500 companies.

Pomerium provides clientless, identity-aware access to internal applications, services, and workloads by continuously verifying user identity, device state, and request context before granting access. The platform intercepts and routes traffic through an identity-aware layer, treating each connection as an ongoing series of requests where identity is verified for every action rather than session-based authentication. Available as both self-hosted open source (Apache 2.0 license) and Pomerium Zero (managed control plane with self-hosted proxy), the solution integrates identity providers, implements BeyondCorp zero trust principles, and provides context-aware access decisions based on user, device, location, time, and custom policy rules.

The platform recently introduced Model Context Protocol (MCP) security features for securing AI agent workflows, providing per-request authorization with JWT identity injection and full audit logging. Pomerium eliminates VPN complexity by operating at the application layer with reverse proxy architecture, providing 23x throughput improvement over OAuth2 Proxy while keeping data decryption and inspection within customer infrastructure. Key customers include GovTech Singapore, Traders Club, ExtraHop, and Fortune 2000 enterprises requiring secure remote access, Kubernetes security, and zero trust application access.

Key Capabilities

Standardized capabilities mapped to this product's security niche

Provides access to browser-based internal applications through a reverse proxy without requiring a device agent, enabling secure access from unmanaged or contractor devices.

Grants access to individual named applications rather than network segments, users and devices can only reach explicitly authorized applications regardless of network position.

Re-evaluates user and device trust signals throughout an active session, revoking or stepping down access when anomalous behavior is detected, not just at authentication time.

Checks endpoint health (OS patch level, EDR presence, disk encryption, certificate validity) at each access request, enforcing minimum device security standards before granting application access.

Discovers internal applications accessible via VPN or direct network routes that should be brought under ZTNA policy, surfacing unmanaged application access.

Integrations

Compatible tools and platforms

Active DirectoryAzure AD (Entra ID)GitHubGoogle WorkspaceKubernetesOktaOneLogin

Solution Details

Deployment Options

Where and how this solution can be deployed

CloudHybridOn-Premises

Support Channels

Available support and communication options

Business Hours SupportCommunity Forum

Pricing Model

How this solution is priced

Community EditionSubscription

How to buy

This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.

Is this your company?

Claim Your Profile