Tailscale
United States · tailscale.com · 35 vendors
Tailscale provides a Zero Trust identity-based connectivity platform that replaces traditional VPNs, SASE, and PAM. It enables secure, peer-to-peer connections between devices across various environments, including remote teams, multi-cloud setups, and IoT devices, using the WireGuard protocol.
Resilience scores
- Digital Sovereignty: 94
- Digital Resilience: 9
Technology vendors
- Anthropic, PBC — Technology — United States
- Demandware — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 32 more
Services catalogue
4 services in catalogue across 3 categories; runs on 35 sub-vendors.
- VPN/Mesh Networking
- Tailscale
- Secure Shell
Insights
Last updated 2026-05-10 · revision 7
35 direct vendors, 321 subvendors
Direct vendors by controlling owner country (sample)
- United States: 33
- Australia: 1
- Norway: 1
Subvendors by controlling owner country (sample)
- Canada: 11
- Norway: 4
- New Zealand: 1
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Tailscale exhibits very high migration readiness, primarily driven by its modern, cloud-native, and open-source-centric technology stack. The use of Go and WireGuard, combined with a mesh overlay networking architecture, inherently promotes portability and reduces reliance on proprietary cloud services. Their infrastructure leverages AWS for coordination servers, S3 for backups, and Snowflake for analytics, demonstrating a strong cloud-native posture. The implied microservices architecture (e.g., through the `tsnet` library for embedding Tailscale) and likely containerization (given CI/CD via GitHub Actions and cloud adoption) further enhance flexibility for migration across different cloud providers or environments. The adoption of Terraform for Infrastructure as Code (IaC) streamlines infrastructure provisioning and management, making migrations more automated and less error-prone. From a regulatory perspective, Tailscale's experience with managing data across multiple jurisdictions (Canada, Germany, US, UK) and reliance on Standard Contractual Clauses (SCCs) for EU/EEA data transfers indicates a sophisticated approach to data residency, which simplifies moving data to new regions or providers while maintaining compliance. While 'Vendor Lock-in Risk' is unknown, the open-source nature of key components (WireGuard, DERP server, client daemon) and the ability to embed Tailscale via `tsnet` significantly reduce proprietary lock-in. The diversity of vendor HQ countries (US, Norway, Australia) for the 84 services used also suggests a less concentrated vendor landscape, which generally eases migration efforts. The absence of financial stability data is a neutral factor, but the strong technical foundation positions Tailscale exceptionally well for any future migration initiatives.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
Tailscale processes personal data of EU/EEA residents through their global service offering and has customers in EU. They have implemented GDPR compliance measures including appointing EU and UK GDPR representatives (EDPO), providing data subject rights, and maintaining a comprehensive privacy policy. However, as a US-based company processing EU data, ongoing compliance requires continuous monitoring of data transfers and regulatory changes.
Evidence: https://tailscale.com/privacy, https://tailscale.com/dpa
ISO 27001 (source) — Assessment Required
No evidence found of ISO 27001 certification. While Tailscale has strong security practices and SOC 2 compliance, the absence of ISO 27001 certification may be a concern for enterprise customers requiring this standard. However, their security practices appear robust based on documented controls and third-party audits.
Evidence: https://tailscale.com/security
SOC 2 (source) — Compliant
Tailscale has completed SOC 2 Type II certification covering security, availability, and confidentiality. This demonstrates strong internal controls and processes. As a cloud services provider, SOC 2 compliance is essential and they have achieved this certification, indicating low compliance risk.
Evidence: https://tailscale.com/security, https://tailscale.com/legal
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.