---
title: "Cerbos PDP"
description: "The open-source Cerbos policy decision point: stateless, sub-millisecond authorization deployed alongside your services."
canonical: "https://www.cerbos.dev/product-cerbos-pdp"
source: "https://www.cerbos.dev/product-cerbos-pdp"
---

# Cerbos PDP

## Implement fast, flexible and scalable access control with ease

The Cerbos Policy Decision Point (PDP) provides a simple, yet powerful solution for authorization that can be up and running in minutes. Cerbos PDP helps you separate your authorization process from your core application code, making your authorization system infinitely scalable, more secure and easier to change as your application evolves.

- Fast and secure
- Plug and play
- Developer-friendly

[Documentation](https://docs.cerbos.dev/cerbos/latest/index.html)

## Fast and secure

- **Flexible deployment models** — Self-hosted, compatible with air-gapped, high security environments. Deploy with serverless functions or a sidecar model. [Deployment](https://www.cerbos.dev/features-benefits-and-use-cases/flexible-deployment-models)
- **Near-instantaneous response times** — Stateless design enabling sub-millisecond policy evaluation without having to synchronize application state or rely on slow network fan-out. [Stateless](https://www.cerbos.dev/features-benefits-and-use-cases/stateless-authorization)
- **Full auditing and accountability** — Compliance with ISO27001, SOC2, and HIPAA with real-time change logs. Keep track of every request and action. [Audit logs](https://www.cerbos.dev/features-benefits-and-use-cases/audit-logs)
- **Row-level authorization** — Decouple data filtering requests from the code via a query plan API, managed by the same policies as application access. [Row-level authZ](https://www.cerbos.dev/features-benefits-and-use-cases/permission-aware-data-filtering) · [Data-filtering for RAG](https://www.cerbos.dev/features-benefits-and-use-cases/access-control-for-rag)

## Plug and play

- **Bring your own identity** — Cerbos supports integration with any authentication provider. [Ecosystem](https://www.cerbos.dev/features-benefits-and-use-cases/ecosystem)
- **Designed for full stack architectures** — Cerbos PDP uses an API-first approach. Seamlessly integrate with frameworks. [Integrations](https://www.cerbos.dev/features-benefits-and-use-cases/ecosystem)
- **SDKs for multiple languages** — Including Javascript, Python, Go, Ruby, PHP, and more. [Ecosystem](https://www.cerbos.dev/features-benefits-and-use-cases/ecosystem)
- **RBAC, ABAC and more** — Cerbos offers context-aware role definitions and attribute-based access control. [RBAC](https://www.cerbos.dev/features-benefits-and-use-cases/rbac) · [ABAC](https://www.cerbos.dev/features-benefits-and-use-cases/abac)

## Developer friendly

- **Define policies in YAML** — Human readable configurations for better cross-functional collaboration and communication [YAML](https://www.cerbos.dev/features-benefits-and-use-cases/human-readable-authorization)
- **Testable with GitOps** — Manage, test and deploy fine-grained access control policies using a CI/CD/GitOps workflow. [GitOps & CI/CD](https://www.cerbos.dev/features-benefits-and-use-cases/testable-authorization)
- **Management API** — Add or update policies using the Cerbos Admin API to simplify administration functions. [Admin API](https://www.cerbos.dev/features-benefits-and-use-cases/admin-api)
- **No vendor lock-in** — As a stateless, self-hosted solution, Cerbos can run on public / private clouds, serverless platforms, or your data center [No lock-in](https://www.cerbos.dev/features-benefits-and-use-cases/no-cloud-vendor-lock-in)

## Use cases

- **Application permissions** — Fine grained context aware permissions. [Go beyond roles](https://www.cerbos.dev/features-benefits-and-use-cases/application-permissions)
- **Product packaging** — Provide trials, feature bundles and custom packages for customers. [Manage entitlements](https://www.cerbos.dev/features-benefits-and-use-cases/product-packaging)
- **Enterprise ready** — Manage complex organizational requirements. [Org permissions](https://www.cerbos.dev/features-benefits-and-use-cases/support-enterprise-organizations)
- **Multi-tenant SaaS** — Support multiple customer environments at scale. [Tailored access](https://www.cerbos.dev/features-benefits-and-use-cases/multi-tenant-saas)

- **Deploy and synchronize PDP at scale** — Save time managing and synchronizing every PDP across all your apps and services, decreasing deployment overhead.
- **Authorize anywhere** — Unlock authorization everywhere - within browsers, serverless architectures, embedded devices, and at the edge with one solution.
- **Collaborate across teams** — Collaborate, validate, and test policies real-time in an IDE environment that’s accessible to non-technical stakeholders and quickly adapt to changing app requirements.
