Security Stack Logo
Pomerium Zero Trust Proxy logo

Network & Infrastructure Security

Pomerium Zero Trust Proxy

Identity-aware proxy for zero trust access to applications without VPN or client software.

Pomerium Zero Trust Proxy Overview

What it does

Pomerium is an open-source Zero Trust Network Access (ZTNA) platform built as an identity-aware reverse proxy rather than a VPN or endpoint agent. Built on Envoy as a Layer 7 proxy, it sits in front of internal web applications, Kubernetes clusters, SSH hosts, databases, and Model Context Protocol (MCP) servers and evaluates user identity, device identity, and request context against Pomerium Policy Language rules on every request. It ships as Apache 2.0 Pomerium Core, Pomerium Zero with a managed control plane, and self-hosted Pomerium Enterprise.

How it works

Users authenticate through any OpenID Connect (OIDC) identity provider, then each request is authorized against Pomerium Policy Language rules combining email, domain, group, claim, and device criteria, with deny overriding allow. Authorized requests are proxied upstream with a JSON Web Token (JWT) identity, so applications need no separate login. Device identity comes from TPM enclaves or FIDO keys, and FleetDM posture data can feed policy. TCP services tunnel through CONNECT, native SSH uses OAuth with ephemeral certificates, Kubernetes access maps users to cluster RBAC, and a Model Context Protocol (MCP) gateway brokers upstream OAuth and per-tool allowlists for AI agents.

Credentials and traction

Pomerium holds a SOC 2 attestation published through a Vanta-hosted trust center. Published customers include Uber, Mercedes-Benz, NVIDIA, Okta, Zendesk, Writer, Ahold Delhaize, and Recursion, with case studies from Obsidian Security, Optoro, Crusoe Energy, Traders Club, Stellenbosch University, Pitt County School District, and a global CRM vendor securing more than 100,000 routes. The open-source proxy has passed 1.6 billion Docker Hub pulls, and adoption spans individual developers and homelab users through Global Fortune 2000 enterprises running self-hosted zero trust.

Key Capabilities

mapped to solution categories
Zero Trust Network Access (ZTNA)

Provides access to browser-based internal applications through a reverse proxy without requiring a device agent, enabling secure access from unmanaged or contractor devices.

Grants access to individual named applications rather than network segments, users and devices can only reach explicitly authorized applications regardless of network position.

Re-evaluates user and device trust signals throughout an active session, revoking or stepping down access when anomalous behavior is detected, not just at authentication time.

Checks endpoint health (OS patch level, EDR presence, disk encryption, certificate validity) at each access request, enforcing minimum device security standards before granting application access.

Discovers internal applications accessible via VPN or direct network routes that should be brought under ZTNA policy, surfacing unmanaged application access.

Brokers authentication, upstream OAuth token injection, and per-tool authorization for AI agents calling internal Model Context Protocol servers through the access proxy.

Fronts the Kubernetes API server and maps identity-provider users and groups to cluster RBAC through impersonation or JWT authentication, replacing per-cluster kubeconfig credentials.

Proxies SSH natively with OAuth authentication and short-lived certificates issued per session, without a custom client, optionally recording sessions for audit.

Expresses per-route access rules in a declarative, version-controllable policy language evaluated on every request, distinct from console-only policy builders.

Integrations

compatible tools
Active DirectoryAmazon CognitoAppleAuth0Azure AD (Entra ID)BambooHRDescopeFleetDMGitHubGitLabGoogle WorkspaceGrafanaKeycloakKubernetesOktaOneLoginPing IdentityTriNet Zenefits

Implementation & support

Deployment model
CloudHybridOn-Premises
Support channels
Community ForumCustomer Success Manager (CSM)DocumentationEmail SupportPhone SupportSlack (Customer Channel)

Info last updated on September 7, 2026

Buyers

Start a shortlist with Pomerium Zero Trust Proxy

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.