What is Secure Access Service Edge (SASE)?
SASE is an architecture that converges wide-area networking and security functions and delivers them as a distributed cloud service. Common functions include SD-WAN, secure web gateway, CASB, firewall as a service, and zero trust access. SASE is an architecture, not proof that one vendor's bundle has consistent policy, low latency, or lower cost. Evaluate identity context, enforcement location, failure behavior, data handling, interoperability, and service coverage.
Why it matters
Users and services can work from many locations. A SASE design can bring network steering and security policy closer to those connections, but teams must still evaluate each control and trust boundary.
How it works
- WAN components steer branch and remote traffic to distributed service locations.
- Cloud-delivered security functions evaluate the traffic with identity, destination, content, and policy context.
- A central control layer distributes policy and collects operational data across the service.
Example
A company sends branch traffic through SD-WAN, applies an SWG to internet traffic, and uses ZTNA for access to private applications.
Pomerium boundary
Pomerium can provide identity-aware access to private applications and services within a broader SASE design. Pomerium does not provide SD-WAN path control, internet web filtering, CASB, or firewall-as-a-service functions.
Limits and non-claims
- SASE has no single implementation that guarantees consistent policy or service quality.
- A consolidated provider can create shared outage, data-handling, and vendor-dependency risks.
- Traffic and applications outside the SASE service coverage still need suitable controls.
Evaluation checklist
- Which access, web, network, and security functions run at each service edge?
- Are identity, resource policy, inspection, and evidence consistent across regions and paths?
- Can provider outage, control-plane compromise, direct access, or local breakout bypass the service?
