What is Software Defined Perimeter (SDP)?
SDP is an identity-centric access architecture that makes protected services unavailable to unauthorized requesters and establishes authorized connectivity through software-controlled components. It is not a physical air gap because approved endpoints still communicate over a network. SDP reduces reachability and attack surface, but it cannot eliminate unauthorized-access risk. Identity, policy, endpoint, implementation, and operational failures still matter.
Why it matters
A conventional private network can expose many reachable services after one connection. SDP limits visibility and connectivity to the specific services that policy permits for a requester.
How it works
- A requester proves its identity and, when required, device context to a policy component.
- Policy evaluates whether that requester can reach a named protected service.
- Software-controlled enforcement components create only the approved connection and keep other services unreachable.
Example
A contractor can reach one internal administration dashboard through an identity-aware proxy but receives no route to the rest of the private network.
Pomerium boundary
Pomerium can act as an application-layer policy enforcement point in an SDP-style design. It authenticates requesters, applies route policy, and proxies approved traffic to specific private services.
Limits and non-claims
- SDP is not a physical air gap because approved endpoints still exchange network traffic.
- Compromised identity, unsafe endpoints, weak policy, or enforcement defects can still permit harmful access.
- An approved connection does not remove vulnerabilities or authorization duties inside the protected application.
Evaluation checklist
- Which controller, gateway, client, identity, and named resource form the protected path?
- Does resource authorization remain narrow after the network path becomes reachable?
- Can a direct endpoint, controller compromise, stale grant, or gateway failure expose the resource?
