DNS filtering by Control D, with one less bill.Read the blog →
  • Blog
  • Docs
  • Download
  • Contact sales
  • Meet Tailscale


    • How Tailscale Works
    • WireGuard® for Enterprises
    • Features
    • Integrations
    • Docs
    • Download
    • Compare Tailscale

    Products


    • Business VPN
    • Tailscale PAM
    • CI/CD Connectivity
    • Secure Access to AI
    • Workload Connectivity
    • Edge & IoT
    • Homelab
    aperture dashboard

    Aperture by Tailscale

    Unified AI governance for AI agents and users.

    Bring Tailscale to work

    See how Tailscale fits the systems your team already runs.

    Make the case
  • Solutions


    • Cloud Connectivity
    • Infrastructure Access
    • Zero Trust Networking
    • Remote Access
    • Kubernetes Networking
    • Secure SaaS
    • Secure AI Agent Connectivity
  • Customer Stories


    • Instacart
    • Cribl
    • Mercury
    • All Customer Stories
  • Join the Community


    • About Community
    • Tailscale Insiders
    • Community Projects
    • Bring Tailscale to Work

    Events


    • Events
    • Webinars
    • TailscaleUp

    Learn more


    • Docs
    • Blog
    • Changelog
    • Press

    Bring Tailscale to work

    Start with your own devices. Bring the same simplicity to your team.

    Make the case
  • Partner Opportunities


    • Become a Partner
    • Our Partners
    • Integrations
    • Contact Partnerships Team
  • Pricing
  • Login
  • Get started - it’s free!
  • Blog
  • Docs
  • Download
  • Contact sales
Platform

Meet Tailscale


  • How Tailscale Works
  • WireGuard® for Enterprises
  • Features
  • Integrations
  • Docs
  • Download
  • Compare Tailscale

Products


  • Business VPN
  • Tailscale PAM
  • CI/CD Connectivity
  • Secure Access to AI
  • Workload Connectivity
  • Edge & IoT
  • Homelab
Solutions

Solutions


  • Cloud Connectivity
  • Infrastructure Access
  • Zero Trust Networking
  • Remote Access
  • Kubernetes Networking
  • Secure SaaS
  • Secure AI Agent Connectivity
Customers

Customer Stories


  • Instacart
  • Cribl
  • Mercury
  • All Customer Stories
Community

Join the Community


  • About Community
  • Tailscale Insiders
  • Community Projects
  • Bring Tailscale to Work

Events


  • Events
  • Webinars
  • TailscaleUp

Learn more


  • Docs
  • Blog
  • Changelog
  • Press
Partnerships

Partner Opportunities


  • Become a Partner
  • Our Partners
  • Integrations
  • Contact Partnerships Team
Pricing
  • Login
  • Get started - it’s free!

Company

  • About Tailscale
  • Careers
  • Press
  • Open Source

Help & Support

  • Support
  • Sales
  • Partnerships
  • Security
  • Changelog
  • Tailscale Status

Legal

  • Terms of Service
  • Privacy Policy
  • California Notice
  • Cookie Notice
  • All Legal

Social

  • Discord
  • GitHub
  • LinkedIn
  • Mastodon
  • Reddit
  • YouTube
  • X (Twitter)
© 2026 Tailscale Inc.
Tailscale is a registered trademark of Tailscale Inc. | WireGuard is a registered trademark of Jason A. Donenfeld

Privileged Access Management

Streamline privileged access with Tailscale PAM Beta

The PAM solution that manages access to sensitive systems and databases through the same identity layer that secures your network.

Join the betaContact us

Trusted by companies like these

  • Perplexity logo
  • Microsoft logo
  • Corelight logo
Hero image for Tailscale PAM beta
A diagram showing a user, 'Amelie,' having her SSH activity recorded and log streaming to Panther with other observability platforms displayed as options, including Splunk and Datadog.

Access only when needed

Tailscale PAM Beta provides session-based privileged access control, built directly into the same identity-based network layer that already secures connectivity. Access control is enforced as part of the network itself, rather than through external systems. Instead of managing credentials, access is evaluated at the moment it happens with just-in-time access.

Join the betaContact us
The Tailscale PAM dashboard home screen displaying socket options including a Production SSH Server, Production Kubernetes Cluster, and Development AWS Linux. In front of the image, is a window that has a Slack logo and says "JIT access request from Dave" with two buttons--'deny' and 'approve'-- along with a message saying "Access will automatically expire in 3 hours."

Secure your database and workflow access

Granting direct access to production data, customer records, and regulated information is a high-risk action that can bypass normal application-level controls. Tailscale PAM Beta protects your production data and business-critical actions through identity-based access. Eliminate standing database access, protect your operational speed, all while retaining a clear audit trail for compliance.

Join the betaContact us

A single control plane for secure connectivity and PAM

Simplify management of both connectivity and privileged access under just one platform

Diagram of an access management workflow. An engineering group synced from an identity provider and just-in-time access approvals connect to specific AWS VPC resources, including EKS, CI runners, deploy-agent, build-server, and prod.

The simpler model you need

Security gains precise control and auditability, without adding friction or changing how engineers work

Enforce least privilege at the moment of access

Evaluate access per session using the same identity layer as the network. Enforce policy at the edge, where the connection happens.

Know exactly who did what

Every action is tied to a unique identity. Eliminate credential overhead with no more vaults, rotation workflows, or fragile proxies.

Maintain native workflows and resilience

Use existing tools and direct connections. Distributed enforcement ensures there is no single point of failure.

Streamline privileged access
with Tailscale PAM

Join the betaContact us

What our customers are saying about Tailscale

Cribl logo

“Every IT team wants to implement zero trust, but it’s always on the other side of the horizon. Tailscale’s overlay network for enterprises brings us one step closer to making it a reality. Now our teams can work on mission-critical projects without worrying about security gaps and tedious configurations.”

Clint Sharp

Co-founder and CEO

Corelight logo

“Our product teams can give themselves direct SSH access into bastion hosts without a public IP attached to it. That way, they can manage these large fleets of Kubernetes or otherwise container-based hosts that run the cloud products we offer.”

Louis Gardner

Principal Security Infrastructure Engineer

Instacart logo

“Because of its simplicity, both in architecture and end user experience, we can solve our acute problems quickly and easily. With Tailscale we don’t have to think about VPNs any more.”

Mike Deeks

Senior Staff Software Engineer

Tailscale pricing that works for everyone

Personal

For individuals who want to securely connect devices, servers, or software. Access nearly all of Tailscale’s offerings and products for free, indefinitely.

$0Free forever
Get started
Standard

For teams adopting the Tailscale platform as a secure connectivity solution and more.

$8per user, per month
Get started
Premium

For organizations wanting the most from the Tailscale platform with advanced compliance needs, heavy ephemeral resource use, and AI security.

$18per user, per month
Get started
Enterprise

For enterprises running the full Tailscale platform, extending into multiple products like PAM, AI security, CI/CD, Edge & IoT, and Kubernetes connectivity at scale, and more.

Custom
Contact sales
TEI report cover

The Total Economic Impact™ of Tailscale

2026 Forrester Consulting commissioned study

TEI report cover

What companies are saying

“For me, it was around cost, ease of deployment, and engineer and developer happiness — that’s where Tailscale edged out to us.”

CISO

Software company

What's the real business impact of Tailscale?

213%

ROI over 3 years

$1.2M

infra savings over 3 years

<6mo.

investment payback

70%

lower breach exposure