Pomerium's Avatar

Pomerium

@pomerium.io.bsky.social

Pomerium is an open-source identity and context-aware access proxy for building secure connections to internal resources

63 Followers  |  3 Following  |  96 Posts  |  Joined: 18.11.2024  |  1.6815

Latest posts by pomerium.io on Bluesky

Post image Post image

Congratulations to @nickyt.online for giving a successful talk on Agentic Access at Black Hat USA!

Missed the talk? You can come talk to Nick at Booth #6216, right next to Startup City Theater.

#BlackHat #BlackHatUSA #cybersecurity #agenticai #mcp

06.08.2025 19:25 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image Post image Post image

Attending Black Hat USA?

Pick up free swag, enter our raffle, watch a demo, and talk to the Pomerium team at Booth #6216. We're located right next to Startup City Theater.

#cybersecurity #blackhatusa

06.08.2025 19:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Secure your stack before autonomous AI agents ship code for you | Netlify Realize the speed, agility and performance of a scalable, composable web architecture with Netlify. Explore the composable web platform now!

On August 12, our CEO Bobby DeSimone will join other security experts to speak about AI agents at Netlify's virtual event.

Working in security, AI/AX, or trying to stay ahead of the curve? This session is for you.

Join the live or sign up to receive the recording afterwards:
ntl.fyi/4mMLR7l

05.08.2025 17:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes

No AuthZ. No identity checks. No context-aware policy.

The MCP spec is missing core security features, meaning teams deploying MCP-compatible tools are exposing internal APIs without realizing it.

It's time to lock down agent access before it becomes a breach vector.

Read more:
bit.ly/4of50QJ

31.07.2025 16:42 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
How Shadow AI Breaks SOC 2 and HIPAAโ€”and What to Do About It Shadow AI bypasses critical access and audit controls required by SOC 2 and HIPAA. Learn how per-route policy with Pomerium restores visibility, enforcement, and audit readiness.

"74% of organizations have already experienced data leakage through unsanctioned AI use, yet most lack visibility into when or how it happens."

Shadow AI breaks the control systems that SOC 2 and HIPAA rely on.

Identity-aware, per-route policy enforcement can help.

Read more:
bit.ly/4lpG8mR

31.07.2025 16:28 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Shadow AI Risk Playbook: Shadow AI Risk Playbook & Zero-Trust Guide (5-Minute Read) | Pomerium Shadow AI tools like ChatGPT create hidden data-leak risks. Use this zero-trust playbook to discover, govern, and secure generative AI with Pomerium.

Shadow AI Is Already in Your Organization.

Employees are pasting sensitive code, customer data, and roadmaps into public LLMsโ€”without approval, visibility, or guardrails. Blocking ChatGPT at the firewall? That wonโ€™t cut it.

ShadowAI and Why Prompt Filters and Regex Fall Short:
bit.ly/4l6dfLX

29.07.2025 17:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Weโ€™re heading to Vegas for Black Hat!
๐Ÿ“ Stop by Booth #6216 for live demos, free swag, and more.

๐ŸŽค Make sure to catch @nickyt.online's talk, โ€œAgentic Access: OAuth Gets You In, Zero Trust Keeps You Safeโ€
๐Ÿ—“๏ธ August 6 at 10:45 AM | Startup City Theater

Come say hi! We're so excited to meet you๐Ÿฅณ

25.07.2025 16:31 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

LIVE NOW!
Come hang out with @nickyt.online and @den.dev.
youtube.com/live/U9rSRnj...

23.07.2025 17:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Native SSH Access

With v0.30, Pomerium now supports native SSH access.
No agents, no tunnels, no special clients required!

Your SSH connections are:
๐Ÿ” Zero Trust-aligned
๐Ÿ”‘ OAuth-backed and centrally authorized
๐Ÿ” Ephemeral & auditable
๐Ÿ“ˆ Easy to manage at scale

Full Changelog for Native SSH Access:
bit.ly/4lIInCA

22.07.2025 16:43 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Using Pomerium as a reverse proxy - Docs - PostHog Pomerium is an identity-aware proxy that can be used to securely proxy traffic to PostHog. This guide will show you how to configure Pomerium as aโ€ฆ

You're friendly reminder that @pomerium.io makes for a great reverse proxy for third party services like @posthog.com so your analytics or tools aren't blocked. ๐Ÿ‘€

posthog.com/docs/advance...

16.07.2025 20:02 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Video thumbnail

Why expose OAuth tokens to every MCP client? @pomerium.io keeps the 'keys to the kingdom' safely locked away while still enabling seamless Google integrations #zerotrust #mcp #security #agenticai

21.07.2025 03:15 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Exclusive Hosted Evening: Food, Networking & Raffles with Founders, VCs and Builders ยท Luma Presented by: GMI Cloud, Pomerium & Singapore Global Network Date & Time: ๐Ÿ“… Thursday, July 31st ๐Ÿ•  5:30 PM โ€“ 9:00 PM PT Location: ๐Ÿ“ Location will be sharedโ€ฆ

@nickyt.online will be speaking about how AI agents need Zero Trust policies that go beyond OAuth's 'what can you do' to answer 'should you be doing this right now' with context-aware, fine-grained controls.

Apply to attend GMI Cloud's AI After Hoursโ€”spots are limited:
lu.ma/dr1t68rs

21.07.2025 16:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

And we're live! Come hang as we chat about the 0.30 release with some demos!

16.07.2025 17:03 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

...And we're live! ๐Ÿฅณ

Join @nickyt.online's livestream as he explores Pomerium v0.30!
www.youtube.com/live/Iz4fBb-...

16.07.2025 17:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Explore and deep dive into the features of Pomerium v0.30 with @nickyt.online, Developer Advocate at Pomerium.

Join us TOMORROW, July 16 at 1PM ET!

15.07.2025 16:15 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Nick Taylor and Den Delimarsky's profile pictures and description along with the theme of their livestream "MCP security and authorization"

Nick Taylor and Den Delimarsky's profile pictures and description along with the theme of their livestream "MCP security and authorization"

MCP Security & Authorization

@den.devโ€ฌ, Model Context Protocol (MCP) Steering Committee Member - Security, joins @nickyt.online to discuss MCP security and authorization.

Join us on Wednesday, July 23 at 1PM ET:
www.youtube.com/live/U9rSRnj...

14.07.2025 16:21 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 3
Video thumbnail

Model Context Protocol (MCP) lets AI agents connect to your tools, but without access control, one prompt can do too much. With @pomerium.io, we set fine-grained policies on servers, all the way down to the tool level. No cooking the books today with zero trust. #mcp #zerotrust #ai

11.07.2025 22:00 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Announcing Pomerium v0.30

Just in: Pomerium v0.30!

Pomerium now covers LLM agents, secure SSH, enterprise-grade policy enforcement, and more!

v0.30 features:
๐Ÿ›ก๏ธ ๐—ก๐—ฎ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—ฆ๐—ฆ๐—› ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€
๐Ÿค– ๐—”๐—ด๐—ฒ๐—ป๐˜๐—ถ๐—ฐ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—š๐—ฎ๐˜๐—ฒ๐˜„๐—ฎ๐˜†
๐ŸŒ ๐—–๐—ฟ๐—ผ๐˜€๐˜€-๐—ข๐—ฟ๐—ถ๐—ด๐—ถ๐—ป ๐—”๐˜‚๐˜๐—ต ๐—™๐—ถ๐˜…๐—ฒ๐˜€
๐Ÿ“ˆ ๐—ฆ๐—ฐ๐—ฎ๐—น๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† + ๐—ข๐—ฏ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜†
๐ŸŒ ๐— ๐˜‚๐—น๐˜๐—ถ-๐—–๐—น๐˜‚๐˜€๐˜๐—ฒ๐—ฟ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น ๐—ฃ๐—น๐—ฎ๐—ป๐—ฒ

Full release:
bit.ly/3IkRPx8

10.07.2025 22:09 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
When AI Has Root: Lessons from the Supabase MCP Data Leak

A Claude-based IDE with root-level database access was tricked into exfiltrating secretsโ€”just by reading a support ticket.

No vulnerability. Just a convincing prompt.

Read what went wrong, why Row-Level Security (RLS) failed, and what defenses can actually work.
bit.ly/406KwPE

08.07.2025 16:49 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Your Employees Are Already Dumping Company Data to LLMs (Hereโ€™s What To Do About It)

Your team is already sharing sensitive internal data with AI. These AI agents must be bounded by proper guardrails.

Our latest post breaks down:
โ€ข โ€œShadow AI,โ€ your biggest security blindspot
โ€ข How to build a secure, low-friction LLM gateway
โ€ข Real-world case studies

Read more:
bit.ly/3Ir3N8h

03.07.2025 16:35 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Discuss Event-Driven Architecture for AI Agents!

Abhimanyu Selvan, Head of Developer Advocacy (EMEA/APAC) at DigitalOcean, joins @nickyt.online
to discuss event-driven architecture for AI Agents.

Join us on Wednesday, July 16 at 9AM ET:
www.youtube.com/watch?v=-ai4...

02.07.2025 16:33 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Preview
June 2025 MCP Content Round-Up: Incidents, Updates, Releases, and more!

Itโ€™s been a busy month in the world of Model Context Protocol (MCP), so weโ€™ve compiled June 2025's MCP incidents, industry news, blogs, and other reports for you.

There's a lot to keep up within the space, but it's clear that MCP is here and needs to be secured.

Find it here:
bit.ly/4exZvIz

01.07.2025 17:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
5 Key Takeaways about ZTA from NIST SP 1800-35

Zero Trust is all about reducing attack surface, enforcing least privilege, and continuously reevaluating risk.

NIST SP 1800-35 is a a how-to Zero Trust manual based on real technologies, interoperable open standards, and 19 separate implementation builds.

Read key takeaways:
bit.ly/3TfcpBl

30.06.2025 16:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Asana's AI Connector Leak Exposed Sensitive Data Across Organizations: What It Means for MCP Security Stay up to date with Pomerium news and announcements.

Asanaโ€™s MCP bug exposing cross-tenant data serves as a warning that you need guardrails with AI agents.

Things can go wrong when:
โ†’ OAuth is treated as authorization
โ†’ Agent access isnโ€™t scoped or audited
โ†’ No enforcement layer stands between the agent and the system

Read more:

27.06.2025 14:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
MCP Security: Zero Trust Access for Agentic AI and Autonomous Agents Learn why OAuth alone can't secure the Model Context Protocol (MCP). Discover how Pomerium enforces Zero Trust for agentic AI with per-request authorization, JWT identity, and full audit logging.

Traditional security models weren't built for autonomous agents.

Our latest MCP guide breaks down:
โ†’ Why MCP changes the security model
โ†’ How Zero Trust protects agent actions in real time
โ†’ What you need to do before connecting LLMs to internal tools

Read the security blueprint:
bit.ly/4687OID

24.06.2025 16:43 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Model Context Protocol Security Reality Check How to close critical gaps and why proxy-enforced OAuth is essential for secure MCP architectures.

OAuth โ‰  secure by default.

Proxy-enforced OAuth is mandatory, not optional

Read the break down on what the MCP Security Best Practices actually require and where current implementations are falling short on @nickyt.online's latest @thenewstack.io piece:
thenewstack.io/the-model-co...

18.06.2025 17:23 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

๐Ÿญ:๐Ÿญ๐Ÿฑ๐—ฃ๐—  ๐—˜๐—ง:
@javasquip.bsky.social, Head of AX Architecture at Netlify discusses AX, MCPs, and using Netlify to ship ideas to production.
www.youtube.com/watch?v=cnPK...

18.06.2025 16:04 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿญ๐Ÿญ๐—”๐—  ๐—˜๐—ง:
AI Engineer @tej.as shares about the Langflow project, a new, visual framework for building multi-agent and RAG applications. It is open-source, Python-powered, fully customizable, and LLM and vector store agnostic.
www.youtube.com/watch?v=sIoc...

18.06.2025 16:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Tomorrow, we have an incredible guest speaker lineup for our livestreams hosted by @nickyt.online ! Tune in and listen to what @tej.as and @javasquip.bsky.social have to say about building and shipping LLMs and MCPs.

18.06.2025 16:04 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Video thumbnail

"How do we build these microservice architectures and serverless apps?"

@remotesynthesis.com joined @nickyt.online to discuss LocalStack, an open-core tool that lets developers run a complete AWS cloud environment on their laptop for faster, cost-effective development and testing.

17.06.2025 16:27 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

@pomerium.io is following 3 prominent accounts