Identity-aware access security
Pomerium
Pomerium builds an open-source identity-aware proxy that lets teams control access to internal applications, servers and services. It checks identity, device state and request context, providing browser access without a corporate VPN client. Pomerium Core is the self-managed data plane; Pomerium Zero supplies a managed control plane while customers run Core in their environment. Pomerium Enterprise provides a self-hosted control plane with centralized configuration, role-based access controls and auditing. Its MCP gateway also handles OAuth authorization, token caching and injection for connections to MCP servers.
Founded in 2019, Pomerium is led by founder and CEO Bobby DeSimone, who wrote its original code after working in privileged access management at BeyondTrust. Its architecture applies BeyondCorp principles, tying access to identity and context rather than network trust. The proxy uses Envoy and supports configuration changes while services remain running. Its engineering work includes readiness checks that track initialization and synchronization across authentication, authorization, storage and proxy components, distinguishing a running process from one ready to serve traffic.
Pomerium reported reaching one billion cumulative Docker pulls in 2023. The company raised a $13.75 million Series A led by Benchmark in 2024.
1 talk
Newest first1 speaker at AIE
Affiliations reflect their AIE appearances, not necessarily current employment.
Messages from the stage
Proxy trust and authorization controls
Taylor covers the configuration behind gateway access: trusted proxy IPs, authenticated-user headers, JWTs, required headers, and policy-based authorization.
Affiliations reflect each recorded session, not necessarily current employment.
