Pomerium
Identity- and context-aware access proxy for zero trust access

Pomerium is an identity- and context-aware access proxy that sits in front of applications to enforce Zero Trust access. It enables clientless access to internal web apps and services, applying policy to every request rather than relying on network perimeter trust.
Key Features
- Identity-aware access proxy for internal web apps and services
- Per-request authorization with continuous policy enforcement (not just session-based)
- Context-aware policies using signals like identity, time, and device context
- Works across cloud, hybrid, and on-prem environments without re-architecting apps
- Supports multiple identity types, including humans and non-human/service identities
- Audit-focused logging of access decisions to support compliance and investigations
Use Cases
- Replace or reduce reliance on traditional VPN access for internal applications
- Secure legacy apps that lack built-in authentication/authorization
- Enforce consistent, centralized access policy across mixed environments
Limitations and Considerations
- Requires integration with an identity provider and careful policy design to avoid overly-broad access
- Introducing a proxy layer may require planning for routing, certificates, and high availability in production
Pomerium is well-suited for teams that want identity-first, policy-based access controls for internal services. It provides a consistent way to secure applications and improve auditability while avoiding blanket network access typical of VPN-based approaches.
Categories:
Tags:
Tech Stack:
Similar Services

Caddy
Extensible web server and reverse proxy with automatic HTTPS
Caddy is a fast, extensible Go web server and reverse proxy with automatic HTTPS (ACME), HTTP/1.1, HTTP/2, and HTTP/3 support, and a JSON config API.

Traefik Proxy
Cloud-native reverse proxy, load balancer, and ingress controller
Traefik Proxy is a dynamic reverse proxy and load balancer that auto-discovers services from Docker, Kubernetes, and other providers, with HTTPS, routing, and observabili...

Kong Gateway
Cloud-native API and LLM gateway with extensible plugins
Kong Gateway is a high-performance, cloud-native API gateway for routing, securing, and observing API traffic, with an extensible plugin system and Kubernetes support.

Nginx Proxy Manager
Web UI to manage Nginx reverse proxy hosts and SSL certificates
Nginx Proxy Manager is a web-based admin panel for managing Nginx reverse proxy hosts, redirects, streams, and Let’s Encrypt SSL certificates via Docker.

NGINX
High-performance web server, reverse proxy, and load balancer
NGINX is a high-performance HTTP server and reverse proxy with caching, load balancing, TLS termination, and TCP/UDP proxying via a modular architecture.

Pangolin
Identity-aware VPN and reverse proxy for secure remote access
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.
Go
Docker
TypeScript