Skip to main content

Software Defined Perimeter (SDP)

A software-defined perimeter hides protected services from unauthorized requesters and establishes identity-controlled connectivity.

What is Software Defined Perimeter (SDP)?

SDP is an identity-centric access architecture that makes protected services unavailable to unauthorized requesters and establishes authorized connectivity through software-controlled components. It is not a physical air gap because approved endpoints still communicate over a network. SDP reduces reachability and attack surface, but it cannot eliminate unauthorized-access risk. Identity, policy, endpoint, implementation, and operational failures still matter.

Why it matters

A conventional private network can expose many reachable services after one connection. SDP limits visibility and connectivity to the specific services that policy permits for a requester.

How it works

  1. A requester proves its identity and, when required, device context to a policy component.
  2. Policy evaluates whether that requester can reach a named protected service.
  3. Software-controlled enforcement components create only the approved connection and keep other services unreachable.

Example

A contractor can reach one internal administration dashboard through an identity-aware proxy but receives no route to the rest of the private network.

Pomerium boundary

Pomerium can act as an application-layer policy enforcement point in an SDP-style design. It authenticates requesters, applies route policy, and proxies approved traffic to specific private services.

Limits and non-claims

  • SDP is not a physical air gap because approved endpoints still exchange network traffic.
  • Compromised identity, unsafe endpoints, weak policy, or enforcement defects can still permit harmful access.
  • An approved connection does not remove vulnerabilities or authorization duties inside the protected application.

Evaluation checklist

  • Which controller, gateway, client, identity, and named resource form the protected path?
  • Does resource authorization remain narrow after the network path becomes reachable?
  • Can a direct endpoint, controller compromise, stale grant, or gateway failure expose the resource?

Sources and further reading

Keep learning

Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo