Software-Defined Perimeter Architecture
Traditional network perimeters rely on implicit trust once a user authenticates over a VPN, exposing broad internal subnets to lateral movement and ransomware proliferation. Altide - PAM implements the principle of absolute least-privilege: verify explicitly, grant access contextually, and assume breach.
Architectural Highlights
- Client Connector: Runs as a native background service or lightweight mobile extension, intercepting DNS requests to resolve internal domain names to secure loopback interfaces.
- Edge Gateway Hubs: Globally distributed zero-knowledge gateways authenticate incoming requests against enterprise IdPs (Okta, Entra ID, Ping) before proxying TCP/UDP streams to protected workloads.
- Continuous Cryptographic Re-Verification: Session tokens expire automatically every 15 minutes, refreshing in the background via biometric attestation or hardware security modules (TPM 2.0 / Apple Secure Enclave).