# Tailscale

> Ties access to servers, databases and internal services to a person's identity rather than to a network cable, a VPN account or a shared password. When someone leaves, access disappears with the account.

- Vendor: Tailscale US Inc. (Delaware) for contracts from 2024-09-03, before that Tailscale Inc. (Toronto)
- Canonical URL: https://www.convios.com/en/toolbox/tailscale
- Language version: https://www.convios.com/de/werkzeugkasten/tailscale
- Area: Governance & security · Cluster: internal system access
- Role: Off-the-shelf product · Origin: Established
- As of: 2026-07-30 · Reviewed: 2026-07-30 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: Identity-bound access does not sell a single product. No customer buys because a clean network runs in the background. Without this layer, however, a pile of debt grows out of VPN accounts, jump hosts and shared keys that nobody fully knows any more. That debt comes due the moment a larger customer sends a security questionnaire or a buyer asks to see who can reach what. The tool keeps you from falling behind, it does not create an edge.

## Suitability by company size

- Solo: suitable — The free tier covers up to 6 users, unlimited user devices and 50 tagged resources. For one person with a handful of servers that means no cost at all.
- Mid-market: suitable — Eight US dollars per user per month is predictable, and user devices are not counted. The real ceiling is not the price but the limit of 10 access groups on the Standard plan.
- Enterprise: suitable with caveats — The vendor holds SOC 2 Type II but no ISO 27001 of its own and offers no choice of an EU storage location. Anyone who needs processing confined to the EEA, or an ISO certificate held by the vendor itself, will not find that promised publicly.

## Vendor staying power

Funded: Backed by a large venture round and a meaningful customer count, but with no public figures on revenue or profitability. That is a funded position, not demonstrated self-sufficiency.

- Funding: USD 160 million Series C led by Accel, announced on 08.04.2025 (source: https://tailscale.com/blog/series-c, as of 2026-07-30)
- Customer count per vendor: 10,000 customers, a figure given in the vendor's own funding announcement (source: https://tailscale.com/blog/series-c, as of 2026-07-30)
- Certification: SOC 2 Type II; no ISO 27001 and no business associate agreement under US health law, because by the vendor's own account only metadata are stored (source: https://tailscale.com/security, as of 2026-07-30)
- Change of contracting entity: Accounts opened from 03.09.2024 contract with Tailscale US Inc., Delaware; older accounts continue with Tailscale Inc., Toronto (source: https://tailscale.com/terms, as of 2026-07-30)
- Maintenance of the subprocessor list: Public list of eight named subprocessors, last changed on 02.09.2025 (source: https://tailscale.com/dpa-subprocessors, as of 2026-07-30)

## Cost of leaving

Moderate: There is no content to export, because the vendor cannot see the traffic and holds only configuration and connection metadata. The client is open source, the protocol is WireGuard, and Headscale exists as an open-source reimplementation of the coordination server, which the vendor itself names as an independent community project. The expense is not moving data but two other things: the access rules have to be rewritten, and Headscale describes itself as aimed at self-hosters and small organisations, so it is not an equivalent substitute for a managed service.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | in place, becomes part of the contract by reference — No separately signed document is foreseen for self-serve customers. The addendum takes effect at the next payment period, at renewal, or with a new order form. | evidenced | 2026-07-30 |
| Storage location | Canada, Germany, USA and United Kingdom, further countries reserved; no choice for the customer — The privacy policy names these countries explicitly and reserves further jurisdictions. Confinement to the EEA is nowhere promised. | partially evidenced | 2026-07-30 |
| Subprocessors | eight named: AWS, DigitalOcean, Hetzner, Linode, Vultr, NetActuate, Snowflake, Jira Service Management — The list names purpose, data processed and region for each vendor. Changes are announced, with a ten-day objection window. | evidenced | 2026-07-30 |
| Third-country transfer | transfers to the USA and other third countries, based on standard contractual clauses — The addendum makes the EU clauses part of the contract and applies module two or three as appropriate. A separate version covers the United Kingdom. | evidenced | 2026-07-30 |
| Training on customer data | unclear — Neither the privacy policy nor the security page states whether connection and configuration data are used to train models. The question is defused by the fact that the vendor cannot read traffic content, by its own account and plausibly so by design. It remains open for the metadata. | partially evidenced | 2026-07-30 |
| Retention and deletion | return or deletion on request within 30 days of contract end; retention during operation unclear — The privacy policy names no concrete period, only the principle of necessity. How long connection logs are kept during normal operation is not publicly documented. | partially evidenced | 2026-07-30 |
| Certifications | SOC 2 Type II held by the vendor; no ISO 27001 and no business associate agreement under US health law — The vendor justifies the absence of a healthcare agreement by storing only metadata rather than customer content. Certificates held by the data centres it uses are not the same as a certificate of its own. | partially evidenced | 2026-07-30 |
| EU AI Act, Article 50 | not applicable on our review, with no statement from the vendor — The tool is network infrastructure and contains no AI system in the sense of the regulation that would trigger the transparency duties under Article 50. We found no explicit vendor statement on this on the security, privacy or contract pages. | evidenced | 2026-07-30 |
| Audit logging | configuration audit log available; network flow logs and streaming to your own systems only on the Premium plan; retention period unclear — The pricing page assigns network flow logs and log streaming to the Premium plan. How long logs are retained, and whether that differs by plan, was not findable in the knowledge base. | partially evidenced | 2026-07-30 |

## Cost

- Entry: Free for up to 6 users with unlimited user devices, 50 tagged resources and 3 access groups. The Standard plan costs 8 US dollars per user per month, Premium 18 US dollars. (as of 2026-07-30)
- Where it gets expensive: Not on users, since laptops and phones are free and unlimited. The infrastructure is what costs: servers, subnet routers and app connectors count as tagged resources, 50 are included on every plan, and each further one costs 1 US dollar a month. Anyone running containers passes that line quickly. On top comes the minute pool for ephemeral resources such as build runners and Kubernetes pods: 1,000 minutes a month on Standard, 10,000 on Premium, and beyond that only by talking to sales. The second cost trap is the jump to Premium, which you make not for access itself but for 300 access groups instead of 10 and for the logs.

## Three routes compared

### Classic VPN with a concentrator and jump hosts

One central appliance or instance that all traffic passes through, with jump hosts behind it for the sensitive systems. That is proven, auditable and in many companies already paid for. The price is the topology: everything runs through a single point that is both bottleneck and failure point, and rights attach to a network segment rather than to a person. Removing someone means cleaning up in several places.

### No AI-native replacement, but a serious neighbour

There is nothing AI-native in this category, and none is to be expected, because the job is cryptography and rule sets, not language understanding. Anyone looking for alternatives will find them not among AI vendors but among the identity-aware access services of the large network providers and the access servers from the developer world. Those neighbours put a broker in the data path instead of connecting devices directly, which buys more control and more logging at the cost of latency and one more place that can see the traffic.

### WireGuard by hand or running Headscale yourself

The foundation is open source, so this can be rebuilt. Hand-managed WireGuard keys work across ten devices and turn into bookkeeping nobody volunteers for across a hundred. The serious build-it-yourself route is Headscale, an open-source reimplementation of the coordination server that keeps the official clients working. That leaves the control plane in your own house, which can be the only viable path under hard sovereignty requirements. The project explicitly describes its own scope as aimed at self-hosters and small organisations, though, and directory integration, account provisioning and being on call then land on you.

Recommendation by size:

- Solo: Take the free tier and retire the jump hosts.
- Mid-market: Buy. Count your servers and containers first, not your staff.
- Enterprise: Buy, but settle storage location, log retention and certificates in writing before signing.

## Context

- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The test asks whether an obligation creates an advantage or is merely a duty, and identity-bound access answers the security questionnaires larger customers now send to every vendor alike.
- Implements method: [DORA Delivery Diagnostic](https://www.convios.com/en/methods/dora-delivery-diagnose) — Time to restore depends on how fast the right people reach the right systems, and access bound to a person shortens exactly that path without leaving shared keys behind.
- Displaces: VPN concentrator as a central gateway, Jump hosts in front of sensitive systems, Shared SSH keys and credentials, Allowlists built on fixed IP addresses

## Evidence

- Plans, per-user prices, tagged resources, access groups and the minute pool — https://tailscale.com/pricing (as of 2026-07-30)
- SOC 2 Type II, no access to traffic content, role of the coordination server — https://tailscale.com/security (as of 2026-07-30)
- Change of contracting entity on 3 September 2024 per Schedule A, New York as governing law — https://tailscale.com/terms (as of 2026-07-30)
- Data processing addendum, standard contractual clauses, 72-hour breach notice, deletion within 30 days — https://tailscale.com/dpa (as of 2026-07-30)
- Eight named subprocessors with purpose and region, as of 2 September 2025 — https://tailscale.com/dpa-subprocessors (as of 2026-07-30)
- Processing in Canada, Germany, the United States and the United Kingdom, with no EEA-only commitment — https://tailscale.com/privacy (as of 2026-07-30)
- Client open source, coordination server proprietary, Headscale an independent community project — https://tailscale.com/opensource (as of 2026-07-30)
- Series C of 160 million US dollars led by Accel, 10,000 customers per the vendor — https://tailscale.com/blog/series-c (as of 2026-07-30)
