Tailscale's approach to data sovereignty
Tailscale’s products are designed to minimize the amount of customer data we collect. Tailscale’s VPN traffic is end-to-end encrypted so we can’t see customer data in the first place, and Tailscale PAM and Aperture can only see the data we need to make those services work as advertised.
For customers and users in the EU and elsewhere who are concerned with data sovereignty and data residency, we’ve put together this document to more thoroughly explain what we collect and why, and where we stand with respect to proposed EU data sovereignty legislation.
The EU data sovereignty push, in brief
In June of 2026, the European Union proposed a series of new measures all aimed at bolstering its “tech sovereignty,” citing the fact that the EU relies on non-EU countries “for over 80% of key digital products, services, infrastructure, and intellectual property.”
One of these tech sovereignty measures is the Cloud and AI Development Act (CADA). CADA defines four “assurance levels” to measure how committed cloud and AI service providers are to EU data sovereignty. These are based on factors like the physical location of company infrastructure, software supply chain transparency and independence, and the citizenship of company personnel.
As a Canadian company that does business all over the world, we understand the desire to reduce your reliance on another country’s technology and to control how data is stored and accessed. They inform our approach to collecting and handling data for customers worldwide, including in the EU.
Frequently Asked Questions
| Does Tailscale have infrastructure in the EU? | Yes. We have a coordination server in Frankfurt, Germany. |
| Does Tailscale guarantee EU data residency? | No, not today. |
| Can Tailscale decrypt customer tailnet traffic? | No. |
| Does user data travel over Tailscale’s infrastructure? | Tailscale VPN: Usually no, except as a fallback when direct connections aren’t possible. Even in such cases, Tailscale cannot decrypt your traffic. Read more. Tailscale PAM and Aperture: Yes. |
| Do private WireGuard® keys leave customer devices? | No. |
| Does Tailscale collect customer metadata from its control plane? | Yes, but only what is necessary for the service to function. Read more. |
| How does Tailscale handle law enforcement requests? | Varies by region. See our Privacy Policy and Data Processing Addendum. |
How Tailscale VPN works
Internally, Tailscale uses the EU’s General Data Protection Regulation (GDPR) as a global privacy baseline, because its principles are reflected in many newer data privacy regimes worldwide. We have coordination infrastructure in Frankfurt, which could satisfy the conditions for assurance level 1 in CADA. As of this writing, we make no guarantees about data residency in the EU or anywhere else.
But beyond that, we believe that the best way to safeguard customer data is to collect as little of it as possible in the first place. That’s reflected in the way Tailscale’s VPN product is built.
Tailscale VPN is built on WireGuard®, a modern protocol designed to simplify secure access and private networking. WireGuard® supplies secure, end-to-end encrypted tunnels between nodes. Tailscale operates coordination servers that allow nodes on your tailnet (a virtual network of devices running Tailscale) to find each other. No complicated network configuration, and no compromising network security by disabling or poking holes in your firewall.
To make that happen, and to continue improving Tailscale, we do collect the information necessary to run the service. This includes your IP address, your operating system version, and any connection attempts. We can see the names of devices on your tailnet, and store public encryption keys. And because Tailscale’s VPN uses your identity for logging in and for access controls, your identity is known to us. These are the things we need to operate the “control plane,” the parts of the platform that make things like direct connectivity and NAT traversal possible.
But as a rule, Tailscale’s VPN stays out of the “data plane,” the place where you and your users’ data is actually moving around. The vast majority of the time, users’ actual data never touches our servers at all; on the rare occasions when it does, we can’t see what it is, because that traffic is encrypted and isn’t decrypted until it reaches its destination. Private encryption keys never leave the device that they’re stored on.
We don’t see what sites you’re browsing, we don’t see what files you’re transferring, and we don’t see anything at all about network activity that happens outside of your tailnet. And we actively oppose efforts to make us collect more data than we need to run the service.
We also give administrators control over much of what is logged and where those logs are stored, and robust identity-based access controls ensure that users and devices do/don’t have access to all the things they should/shouldn’t. Permissions can be managed for individuals, for groups of users, and even for AI agents, based on anything from the team that they’re on to the country they’re in.
Tailscale sometimes partners with third-party services to provide additional, optional functionality. Our partnership with Mullvad makes their global network of VPN servers available to Tailscale users as exit nodes, and our partnership with ControlD enables DNS filtering to help block phishing attempts and malware. Mullvad does not receive or store any Tailscale user data. ControlD can view device names and identities, public IP addresses, and the DNS names and target IP addresses that your devices are trying to talk to. Both services are governed by their own privacy policies, which you can find here for Mullvad and here for ControlD.
How Tailscale PAM works
Tailscale PAM is a privileged access management solution used to grant and restrict access to critical resources and infrastructure, like servers, databases, and Kubernetes clusters. It uses the same identity layer and encrypted WireGuard® tunnels as Tailscale VPN, eliminating the need for shared administrator accounts with open-ended access. A client connects to a Tailscale PAM connector that you deploy onto your own local network, and that connector mediates access to private resources on that network.
At a baseline, Tailscale PAM collects the identity of the person, machine, or agent making the connection, what they’re connecting to, what they’re connecting from, when the connection happened, and whether the connection was allowed. That data also includes IP address information, the geolocation information derived from that IP, and the duration of the connection.
But Tailscale PAM also offers an optional feature called session recording. When this is enabled, the Tailscale PAM connector can record SSH terminal activity, database queries, Kubernetes API requests and interactive sessions, S3 API activity, and HTTP browser sessions. Session recording is opt-in, and exists to help customers with troubleshooting, auditing, and compliance requirements. Because it can capture clear-text input during session recordings, it can potentially capture privileged data.
By default, Tailscale stores PAM data in AWS storage and deletes it only upon customer request. This data is encrypted at rest. Customers can institute their own data retention policies for session recordings by storing their PAM data in their own Amazon S3 storage buckets.
How Aperture works
Aperture is Tailscale’s AI gateway product. It’s used for centralizing AI access across organizations—storing API keys, managing which users can access what AI models and services, and measuring and metering usage and cost. And Aperture includes guardrails designed to prevent sensitive data and personally identifiable information (PII) from being sent to AI model providers.
To enable these features, Aperture sees the traffic you pass through it, unlike Tailscale VPN. That includes the full request and response body, headers, and tool use data for every LLM request, as well as usage metrics like token counts, the model used, and the approximate cost of that usage.
Because Aperture communicates with third-party AI model providers, prompts and other information sent to those providers through Aperture will also be subject to their terms.
Aperture still provides tools to ensure that you stay in control of your data. An optional zero-retention mode can be used to ensure that prompts and responses are never written to disk. Usage data can be exported to S3-compatible storage, so you can decide where your data is kept.
Your data is yours, no matter where it goes
Discussion of data sovereignty is often about data residency—where servers and other network infrastructure are physically located. But data sovereignty is also about control. What data exists, and who can access it? Can it be decrypted and read as it travels from its origin to its destination? Where and how can access to data be compelled, by law enforcement or other authorities?
These are messy questions, made messier by just how interconnected the Internet and the world are. Companies headquartered in one country can have employees or customers in another. Rules and regulations implemented in one country can push companies to change their worldwide standards, because that can be easier than trying to enforce different rules in different places, and can inspire similar legislation in other countries.
Tailscale tries to reduce the salience of these questions for our users by collecting and keeping as little data as possible, and by locking ourselves out of our VPN users’ data plane with end-to-end encryption. That’s a different approach than the one taken by some of our competitors, who do retain the ability to decrypt and inspect user data as it moves through their infrastructure.
Tailscale’s architecture is a good foundation for anyone worried about data sovereignty or other security and privacy-related concerns. But if you have more specific questions to ask or problems to solve, we’re here to help. We can collaborate with your Security and Compliance teams, or review architecture designs on request.