Get started
Login
WireGuard is a registered trademark of Jason A. Donenfeld.
© 2024 Tailscale Inc. All rights reserved. Tailscale is a registered trademark of Tailscale Inc.
Multi-Cloud networking icon

Multi-Cloud Networking

A better networking solution for multiple clouds

Uniform connectivity across any cloud provider without toggling between VPNs

Multi-Cloud Networking masthead

A zero-trust overlay network that seamlessly connects resources

Subnet routers
Software defined perimeters
Split Tunneling

Optimize resource availability with Tailscale

Secure end to end encryption

Secure communications with end-to-end encryption

Modern WireGuard® encryption protocols protect every communication throughout your private networks
Use exit nodes for secure browsing, anywhere

Protect Traffic over Public Internet

Route all non-Tailscale traffic through a specific device on your private network to secure communications at a cafe, different country, or public Wi-Fi networks.
Scalability

Realize Enterprise Scalability

Achieve the high availability, load-balancing, and failover capabilities your organization requires for a hybrid or global workforce with regional routing.
Manage kubernetes across environments

Manage K8s & K3 clusters with Kubernetes operator

Connect services (north-south, east-west) across heterogeneous environments, and encrypt communications with WireGuard without exposing them to the public internet.
Simplify SSH access

Simplify SSH access throughout cloud providers

Create a common workflow for developers to SSH into resources regardless of whether they’re hosted on various clouds or on-premises without having to create, rotate, or revoke keys.
alt
We needed a solution that was compatible with everything—all of our operating systems, development environments, physical hardware and cloud gateways. We also needed it to be built on zero trust principles. We have a lot of remote employees. They need the same level of access as those in the office to complete their work without compromising security.
Guillaume Legendre, DevOps Engineer at Hugging Face
Read full story

Our WireGuard® based networks protect the most complex network infrastructures

Users Management

SSO & MFA with IdP

Users can authenticate using one of our supported identity providers to access the tailnet.

User & group provisioning (SCIM)

Sync users and group settings from one of our supported IdPs to keep ACLs up-to-date.

On-demand access

Partner integrations allow administrators to provide time-bound, elevated privileges for users.

Devices

Device approval

Require devices to be approved by an administrator before joining the tailnet.

Device Posture Management

Collect device attributes and use them as part of connectivity rules within your Tailnet to limit access for devices that do not meet security requirements

Policies

Access controls lists (ACLs)

Create RBAC policies to determine which users, roles, or groups can access, which nodes on your tailnet.

ACL tests

Verify ACLs provide sufficient coverage against unnecessary exposure.

GitOps for ACLs

Manage ACLs version control within a CI/CD workflow using GitHub or GitLab.

Tailnet lock

A predetermined trusted node must verify the trusted keys of any nodes attempting to join your tailnet.

Network Access

App Connectors

Secure third-party SaaS applications by restricting access to authorized users.

Kubernetes Operator

Connect services and encrypt communications across heterogeneous environments.

Regional Routing

Increase performance with high availability across complex networks.

Exit nodes

Route all traffic through a designated egress point, similar to a privacy VPN.

End-to-end encryption

Tailscale uses WireGuard protocols for end-to-end encryption.

Logging

Configuration audit logging

Surface what configuration-based actions occurred, by whom, and when.

Network flow logging

Surface what node-to-node interaction occurred, and when.

Log streaming

Natively stream configuration or network flow logs to our SIEM integration partners.

SSH session recording

Store any Tailscale SSH session recording long-term in any S3-compatible service or local disk.

Try Tailscale for free

Schedule a demo
Contact sales
cta phone
mercury
instacart
Retool
duolingo
Hugging Face