Skip to main content

Zero Trust Academy

Learn identity-aware access from first principles

Build a clear working model of identity, policy, networks, protocols, and agent access. Start with a topic or find the exact resource that you need.

Choose a topic

Learn by topic

Review a related set of concepts, then use the Pomerium documentation to apply what you learned.

Agentic Access

Learn how to control agent identities, delegated authority, tools, and autonomous workflows.

Platform and Component Security

Learn how trusted bases, isolation, boot integrity, attestation, information flow, and shared hardware shape system security.

Privacy Engineering

Learn how to manage privacy risk through data maps, minimization, unlinkability, de-identification, telemetry design, and controlled use.

Standards and Protocols

Learn the standards and protocols that systems use for identity, policy, encryption, and transport.

Zero Trust

Learn the principles, trust boundaries, and request checks that define a zero trust architecture.

Reference library

Find a security resource

Search the full academy or filter it by the topic that you want to learn.

Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Identity and Authentication

Account Recovery

Restore account access without giving attackers an easier path than the normal authentication and enrollment process.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Adversary Model

State who can attack the system, what they want, what they can do, where they start, and what constrains them.

Learn this term
Agentic Access

Agent

An agent is a software loop that uses model output and context to select steps or tools toward a goal.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent and Tool Inventory

Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Blast Radius

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Cascading Failure

Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Credential Custody

Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.

Learn this term
Agentic Access

Agent Goal Hijack

Prevent untrusted instructions from changing an agent's objective, authority use, tool sequence, or target resource.

Learn this term
Agentic AccessAuthorization and Policy

Agentic Access Management (AAM)

Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.

Learn this term
Agentic AccessSecurity Operations and Risk

Agentic Supply Chain

Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.

Learn this term
GuideHuman Factors and Security Economics

Analyze Security Incentives

Map cost, benefit, authority, information, liability, and feedback so a control works after teams and vendors optimize their own goals.

Open this guide
Zero TrustSecurity Engineering Foundations

Assume Breach

Design as if one identity, credential, workload, route, or control will fail, then limit movement and impact.

Learn this term
Security Operations and Risk

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Attack Tree

An attack tree decomposes one attacker goal into alternate and combined paths that can achieve it.

Learn this term
Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term
Authorization and PolicyStandards and Protocols

Authorization Consent

Use consent to record a user's informed grant without treating it as proof that an action is safe or permitted.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Decision Log

Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Drift

Authorization drift is the gap that develops when effective access no longer matches intended access.

Learn this term
Identity and Authentication

Back-channel logout

OpenID Connect Back-Channel Logout lets an OpenID Provider notify a relying party through a direct server-to-server request.

Learn this term
Security Operations and RiskCryptography and Data Protection

Backup and Restore

Create isolated, complete, recoverable copies and prove they restore current service without old compromise, authority, or expired data.

Learn this term
Application and Service AccessNetwork and Infrastructure

Bastion Host

A bastion host is a hardened system that provides controlled administrative access to a more protected network or resource.

Learn this term
Human Factors and Security EconomicsIdentity and Authentication

Biometric Authentication

Use noisy, non-secret human characteristics only within a bounded authenticator, sensor, matching, privacy, fallback, and recovery design.

Learn this term
Software and Application Security

Business Logic Abuse

Protect workflow order, object state, quotas, prices, approvals, and other business invariants from valid-looking misuse.

Learn this term
Software and Application Security

Canonicalization

Convert equivalent input representations to one defined form before comparison, validation, authorization, and storage.

Learn this term
Standards and ProtocolsSecurity Operations and Risk

Certificate Lifecycle

Issue, deploy, rotate, revoke, recover, and retire certificates and private keys without breaking name or trust validation.

Learn this term
Application and Service AccessNetwork and Infrastructure

Clientless Zero Trust Access

Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.

Learn this term
Network and Infrastructure

Cloud Network Security

Cloud network security protects data, workloads, identities, and communication paths in cloud environments. It follows a shared responsibility model.

Learn this term
Software and Application Security

Command Injection

Avoid command interpreters and pass fixed executables and validated arguments through structured process APIs with narrow authority.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Complete Mediation

Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.

Learn this term
Authorization and PolicyAgentic Access

Confused Deputy

Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Zero TrustAuthorization and Policy

Continuous Verification

Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

Learn this term
Platform and Component Security

Covert Channel

Find unintended communication paths that let cooperating subjects transfer information through shared storage, timing, load, errors, or resource state.

Learn this term
Software and Application Security

Cross-Site Scripting (XSS)

Prevent untrusted data from executing as active browser content through context-aware encoding, safe DOM APIs, and constrained markup.

Learn this term
Cryptography and Data Protection

Cryptographic Agility

Inventory and replace algorithms, parameters, protocols, keys, libraries, certificates, and stored formats without hidden dependencies.

Learn this term
Security Operations and Risk

Cyber Threat Intelligence

Turn evaluated information about adversaries, behavior, infrastructure, vulnerabilities, and incidents into a time-bounded security decision.

Learn this term
Security Operations and Risk

Data Breach

A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information.

Learn this term
Cryptography and Data Protection

Data Classification

Assign data sensitivity, criticality, ownership, use, sharing, retention, and recovery requirements that drive technical controls.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Defense in Depth

Place complementary controls across distinct failure domains so one failure does not expose the protected asset.

Learn this term
Agentic AccessAuthorization and Policy

Delegation

Delegation gives an actor limited authority to act for another principal, called the subject.

Learn this term
Agentic AccessAuthorization and Policy

Delegation Chain

Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.

Learn this term
Security Operations and RiskNetwork and Infrastructure

Denial of Service

Model how traffic, expensive valid work, state, queues, dependencies, identity, and recovery controls can make a service unavailable.

Learn this term
Security Operations and Risk

Detection Quality

Evaluate whether a detection observes the intended behavior with useful fidelity, timeliness, coverage, context, response, and manageable error.

Learn this term
Cryptography and Data Protection

Digital Signature

Bind a defined message to a private signing key and verify it through an authenticated public key, purpose, and context.

Learn this term
Authorization and PolicySecurity Operations and Risk

Distributed Security State

Control policy, identity, revocation, key, context, and quota state across replicas with explicit freshness and failure semantics.

Learn this term
Network and Infrastructure

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

Learn this term
Security Engineering Foundations

Economy of Mechanism

Economy of mechanism keeps trusted security functions small, clear, and free of unnecessary shared behavior.

Learn this term
Security Operations and RiskStandards and Protocols

Encryption

Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.

Learn this term
Security Operations and Risk

Endpoint Security

Endpoint security is the set of controls used to manage and protect devices that access organizational data and services.

Learn this term
Cryptography and Data Protection

Envelope Encryption

Encrypt data with a data-encryption key and protect that key under a separately stored key-encryption key or key service.

Learn this term
Agentic AccessAuthorization and Policy

Explicit Delegation

Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Fail-Safe Defaults

Start from explicit denial and define safe behavior for missing policy, invalid input, dependency failure, and recovery.

Learn this term
Software and Application Security

File Upload Security

Validate, transform, store, scan, and serve untrusted files through bounded stages with separate names, origins, and authority.

Learn this term
Network and Infrastructure

Firewall

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

Learn this term
Security Engineering FoundationsPlatform and Component Security

Formal Methods and Security Models

Use precise models, invariants, and proofs to answer a bounded security question without confusing the model with the deployed system.

Learn this term
Identity and Authentication

Front-channel logout

OpenID Connect Front-Channel Logout uses the user's browser to load registered relying-party logout URIs from the OpenID Provider.

Learn this term
Application and Service AccessNetwork and Infrastructure

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Learn this term
Platform and Component SecurityCryptography and Data Protection

Hardware Root of Trust

Anchor a narrow security function in protected hardware while stating the manufacturing, firmware, key, lifecycle, and physical assumptions that remain.

Learn this term
Agentic AccessSecurity Operations and Risk

Hidden Trust Boundary

A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.

Learn this term
Software and Application SecurityStandards and Protocols

HTTP Request Smuggling

Prevent HTTP intermediaries from disagreeing about message boundaries, request length, transfer coding, and the start of the next request.

Learn this term
Standards and ProtocolsApplication and Service Access

HTTP Semantics

HTTP semantics define request methods, targets, fields, responses, status codes, authorities, and intermediary behavior.

Learn this term
Standards and ProtocolsNetwork and Infrastructure

HTTPS and TLS

Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.

Learn this term
Identity and AuthenticationAgentic Access

Identity Collapse

Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.

Learn this term
Identity and AuthenticationStandards and Protocols

Identity Federation

Establish trust between an identity provider and relying party without treating an assertion as universal authority.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term
Identity and Authentication

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

Learn this term
Zero TrustNetwork and Infrastructure

Implicit Trust Zone

An implicit trust zone grants authority from location, membership, or prior access without a resource-specific decision.

Learn this term
Privacy EngineeringPlatform and Component Security

Inference Attack

Derive protected facts from permitted queries, aggregates, models, correlations, errors, and repeated observations.

Learn this term
Platform and Component SecurityAuthorization and Policy

Information Flow Control

Control where information may move after access by tracking source, destination, transformation, label, release, and declassification.

Learn this term
Network and Infrastructure

Ingress and Egress

Place controls on traffic entering and leaving a workload boundary without treating direction or network location as identity.

Learn this term
Software and Application Security

Injection

Prevent attacker-controlled data from changing the structure or meaning of a command sent to an interpreter.

Learn this term
Human Factors and Security EconomicsSecurity Operations and Risk

Insider Threat

Reduce harmful action by people or partners who hold legitimate access, knowledge, proximity, or influence, whether intentional or accidental.

Learn this term
Security Operations and Risk

Intrusion Detection

An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation.

Learn this term
Application and Service AccessIdentity and Authentication

JSON Web Token (JWT)

Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.

Learn this term
Standards and Protocols

JWK and JWKS

Select trusted JSON Web Keys from an approved set, restrict algorithms and key use, and rotate without trusting token-controlled URLs.

Learn this term
Network and InfrastructureAuthorization and Policy

Kubernetes RBAC

Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.

Learn this term
Network and InfrastructureIdentity and Authentication

Kubernetes Service Account

Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term
Application and Service Access

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

Learn this term
Security Operations and Risk

Malware

Understand malicious code that steals, persists, disrupts, spies, moves, or changes systems and prepare to contain and rebuild affected trust.

Learn this term
Agentic AccessAuthorization and Policy

MCP Authorization

Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.

Learn this term
Agentic AccessAuthorization and Policy

MCP Security

Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.

Learn this term
Software and Application Security

Memory Safety

Prevent spatial, temporal, initialization, and type-safety errors that can corrupt memory, disclose data, or redirect control flow.

Learn this term
Zero TrustNetwork and Infrastructure

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

Learn this term
Security Operations and Risk

MITRE ATT&CK

MITRE ATT&CK catalogs observed adversary tactics and techniques that can guide hypotheses, detections, and investigations.

Learn this term
Platform and Component SecurityAuthorization and Policy

Multilevel Security

Enforce mandatory policy when one system processes information and users at different sensitivity and clearance levels.

Learn this term
Application and Service AccessZero Trust

Named Resource Access

Grant access to one named application or service without extending general reachability to its network or neighboring systems.

Learn this term
Network and Infrastructure

North-South Traffic

North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet.

Learn this term
Identity and AuthenticationAuthorization and Policy

OAuth 2.0

Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.

Learn this term
Identity and AuthenticationStandards and Protocols

OpenID Connect (OIDC)

OpenID Connect is an identity layer on top of OAuth 2.0. It lets a client verify an end user's authentication and receive identity claims in an ID token.

Learn this term
Network and InfrastructureStandards and Protocols

OSI Layers

The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability.

Learn this term
Identity and Authentication

Passkey

Use WebAuthn public-key credentials bound to a relying party and understand sync, recovery, and device boundaries.

Learn this term
Software and Application Security

Path Traversal

Prevent attacker-controlled file names and paths from escaping an approved storage root after decoding and canonical resolution.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Network and Infrastructure

Perimeter

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.

Learn this term
Privacy EngineeringCryptography and Data Protection

Personal Data and Metadata

Treat identifiers, device facts, access events, relationships, timing, locations, and derived attributes as personal when context can link them to people.

Learn this term
Human Factors and Security EconomicsIdentity and Authentication

Phishing

Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.

Learn this term
Platform and Component Security

Platform Attestation

Appraise fresh signed evidence about a platform through explicit attester, verifier, reference-value, policy, and relying-party roles.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term
Authorization and Policy

Policy as Code

Treat access policy as a versioned, reviewed, tested, and observable decision artifact with controlled deployment.

Learn this term
Authorization and Policy

Policy Decision Point (PDP)

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.

Learn this term
Cryptography and Data Protection

Post-Quantum Cryptography

Prepare public-key systems for quantum-resistant key establishment and signatures through inventory, standards, testing, and migration.

Learn this term
Privacy Engineering

Privacy Risk

Assess data actions that can create problems for people, then combine likelihood and impact without reducing privacy to breach risk.

Learn this term
Platform and Component SecuritySoftware and Application Security

Privilege Separation

Split a service into components with different authority so compromise of one parser or workflow does not grant the complete service privilege.

Learn this term
Agentic AccessAuthorization and Policy

Prompt Injection

Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.

Learn this term
GuideCryptography and Data Protection

Protect the data lifecycle

Control collection, use, sharing, storage, logging, backup, recovery, retention, deletion, and sanitization for one data class.

Open this guide
Privacy Engineering

Pseudonymization

Replace direct identity with a controlled reference while treating the mapping, stable links, attributes, and auxiliary data as remaining privacy risks.

Learn this term
Software and Application Security

Race Condition and TOCTOU

Prevent security decisions from becoming stale before the protected state change, resource use, or authorization commit completes.

Learn this term
Security Operations and Risk

Ransomware

Ransomware is malware used to deny access to data or systems and demand payment. Many operators also steal data and threaten disclosure.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Reference Monitor

Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.

Learn this term
Standards and ProtocolsIdentity and Authentication

Refresh Token

Use refresh tokens only at the authorization server, bind them to a client, rotate or sender-constrain them, and detect replay.

Learn this term
Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term
Agentic Access

Rogue Agent

A rogue agent acts outside its declared goal, approved policy, expected identity chain, or authorized operating boundary.

Learn this term
Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term
Software and Application Security

Same-Origin Policy

Understand how scheme, host, and port define a browser origin and limit cross-origin reads, script access, and storage.

Learn this term
Identity and AuthenticationStandards and Protocols

SCIM Provisioning

Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.

Learn this term
Security Operations and Risk

Secure Enclave

Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave.

Learn this term
Software and Application Security

Secure Error Handling

Fail safely without bypassing controls, exposing sensitive internals, duplicating effects, or leaving partial security state.

Learn this term
Application and Service AccessStandards and Protocols

Secure Route Selection

Select a route from trusted authority and path data so an attacker cannot redirect policy or credentials to the wrong upstream.

Learn this term
Security Operations and RiskCryptography and Data Protection

Secure System Decommissioning

Remove a system, route, identity, key, dependency, and data without leaving reachable shadow service or breaking another security control.

Learn this term
Security Operations and Risk

Security Alert Triage

Qualify, categorize, prioritize, enrich, assign, and escalate a potential incident from evidence, asset criticality, identity, scope, and impact.

Learn this term
Security Operations and Risk

Security and Compliance

Security protects stated assets and properties, while compliance evaluates obligations against defined criteria and evidence.

Learn this term
Platform and Component Security

Security Kernel

Understand the small privileged mechanism that implements a reference monitor and controls access to system resources.

Learn this term
Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term
Software and Application Security

Security Misconfiguration

Prevent unsafe defaults, unnecessary features, exposed diagnostics, excessive authority, and configuration drift across environments.

Learn this term
Security Operations and Risk

Security Postmortem

A security postmortem turns an incident timeline, contributing conditions, and response evidence into owned system changes.

Learn this term
Security Engineering Foundations

Security Properties

Distinguish confidentiality, integrity, availability, authenticity, accountability, and privacy in a system claim.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Security Risk

Connect a credible threat, likelihood, consequence, uncertainty, and stakeholder impact to an explicit risk decision.

Learn this term
Security Operations and Risk

Security Telemetry

Security telemetry uses logs, metrics, traces, and events to answer defined detection, investigation, and control questions.

Learn this term
Standards and ProtocolsAuthorization and Policy

Security Time and Freshness

Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Security Understandability

Make the system, its authority, dependencies, state, failure behavior, and evidence clear enough to change and operate safely.

Learn this term
Authorization and Policy

Separation of Duties

Split incompatible authority across independent people or roles so one actor cannot complete a sensitive process alone.

Learn this term
Security Engineering FoundationsAuthorization and Policy

Separation of Privilege

Require independent conditions, authorities, or actors before the system permits a sensitive action.

Learn this term
Platform and Component SecurityCryptography and Data Protection

Side-Channel Attack

Analyze information leaked through time, caches, memory access, power, emissions, sound, faults, resources, and error behavior.

Learn this term
Application and Service AccessStandards and Protocols

Signed Header

Pomerium's signed header is the X-Pomerium-Jwt-Assertion header.

Learn this term
Identity and Authentication

Single Sign-On (SSO)

SSO lets a user authenticate through one identity service and then access several relying applications without entering credentials at each application.

Learn this term
Human Factors and Security Economics

Social Engineering

Model deception and influence that cause a person or process to disclose information, change identity state, or perform an unauthorized action.

Learn this term
Network and InfrastructureStandards and Protocols

Software-Defined Networking (SDN)

Software-defined networking separates programmable control functions from the packet-forwarding plane through defined abstractions and interfaces.

Learn this term
Software and Application Security

SQL Injection

Keep untrusted values separate from SQL structure with parameterized queries, allowlisted identifiers, and narrow database authority.

Learn this term
Standards and ProtocolsApplication and Service Access

SSH Protocol

SSH authenticates a server and client, then multiplexes sessions, commands, and forwarding channels over one transport.

Learn this term
Application and Service Access

Stateless

A stateless service does not keep server-side session state between requests.

Learn this term
Platform and Component SecuritySecurity Operations and Risk

System Hardening

Reduce a deployed system to required services, identities, interfaces, privileges, configurations, and recovery paths, then keep it there.

Learn this term
Security Operations and Risk

Threat Hunting

Proactively test a bounded threat hypothesis in existing evidence when no alert has yet confirmed the activity.

Learn this term
Application and Service AccessStandards and Protocols

Token Exchange

Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.

Learn this term
Agentic Access

Tool

In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema.

Learn this term
Agentic AccessAuthorization and Policy

Tool Misuse

Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.

Learn this term
Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term
Privacy EngineeringNetwork and Infrastructure

Traffic Analysis

Infer participants, relationships, activity, protocol, content class, and events from communication timing, direction, size, frequency, and routes.

Learn this term
Platform and Component SecuritySecurity Engineering Foundations

Trusted Computing Base

Identify every component whose correct behavior is necessary for a stated security property, then reduce and verify that trusted set.

Learn this term
Software and Application Security

Unsafe Deserialization

Treat serialized objects as untrusted data and prevent input from selecting executable types, constructors, hooks, or object graphs.

Learn this term
Application and Service AccessNetwork and Infrastructure

Upstream and Downstream

Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.

Learn this term
Human Factors and Security EconomicsSecurity Engineering Foundations

Usable Security

Make the secure action effective, efficient, understandable, accessible, recoverable, and compatible with the person's real task.

Learn this term
Network and Infrastructure

Virtual Private Network (VPN)

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.

Learn this term
Identity and AuthenticationStandards and Protocols

WebAuthn

WebAuthn is a W3C API for creating and using public-key credentials scoped to a relying party.

Learn this term
Application and Service AccessStandards and Protocols

WebSocket Access

WebSocket access starts with an HTTP upgrade and then carries long-lived bidirectional messages on one connection.

Learn this term
Network and InfrastructureIdentity and Authentication

Workload Attestation

Use platform evidence to select a workload identity without treating mutable labels or network location as proof.

Learn this term
Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo