
Tailscale puts all your devices on 1 private network, wherever they are. Your laptop in a hotel, your phone on 5G, the Mac Studio at home and a server in the cloud all see each other as if they sat on the same desk. There's no router to configure and no port to open: you install the app, sign in, and the device joins your tailnet.
It started as a better VPN for developers. Today it sells itself as connectivity for everything, including AI agents, but the personal use is still the best way in.

| Company | Tailscale Inc., founded in 2019, headquartered in Toronto |
| Founders | Avery Pennarun (CEO), David Crawshaw, David Carney and Brad Fitzpatrick |
| Funding | $160M Series C in 2025, about $275M raised in total |
| Customers | 40,000 businesses, per Tailscale |
| Protocol | WireGuard, with Tailscale's own coordination and relay layer |
| Platforms | macOS, iOS, Windows, Linux, Android, Apple TV, routers (OpenWrt, GL.iNet), NAS, Docker, Kubernetes |
| Open source | The clients are open source. The coordination server is closed, but Headscale is an open-source replacement |
What it does
| Feature | What it gives you |
|---|---|
| MagicDNS | Every device gets a name, so ssh studio works instead of an IP address |
| Subnet router | 1 device shares a whole home network, so the NAS and printers are reachable without installing Tailscale on them |
| Exit node | Route all your internet traffic through a chosen device, for example home, when on hotel Wi-Fi |
| Mullvad exit nodes | An add-on that routes traffic through Mullvad VPN servers in other countries |
| Tailscale Serve | Share a local web app, such as a dashboard on port 9000, with your own devices over HTTPS |
| Tailscale Funnel | Publish a local service to the public internet through Tailscale, without opening a port |
| Taildrop | Send files between your devices, like AirDrop across platforms |
| Tailscale SSH | SSH into machines with your Tailscale identity instead of managing keys |
| Access controls | Rules in 1 policy file decide which device or user can reach what |
For business people
The problem: classic VPNs send all traffic through a central gateway. They're slow, fiddly to set up, and once you're in, you can usually reach everything.
What Tailscale changes: devices connect directly to each other, encrypted, and each connection is checked against your identity and your rules. Remote staff, servers in different clouds and office equipment join the same private network in minutes. That's what the industry calls zero trust: nothing is trusted just because it's on the network.
Where it fits: remote access to internal tools, admin access to servers without a bastion host, connecting cloud and on-premise systems, and more and more, giving AI agents controlled access to internal data.
Pricing
| Plan | Price | For |
|---|---|---|
| Personal | Free | Up to 6 users, unlimited devices, nearly all features |
| Standard | $8 per user per month | Teams: unlimited users, SCIM, device posture checks |
| Premium | $18 per user per month | Just-in-time access, advanced SSH, network flow logs |
| Enterprise | Custom | Contracts, SLAs, invoicing |
The limits:
- A North American service. Your traffic is end-to-end encrypted between devices, but the coordination servers that manage keys and devices belong to Tailscale. For full control, Headscale replaces them with a server you run yourself.
- It's not a privacy VPN by default. Your traffic only leaves through another country if you add exit nodes.
- Corporate networks can block it, which is a common reason it fails on a work laptop.
For technical people
How a connection works:
- Coordination: each device registers its WireGuard public key with Tailscale's coordination server, which distributes keys and policy to the other devices.
- NAT traversal: devices punch through firewalls and NAT to connect peer to peer. Most connections end up direct.
- DERP relays: when a direct path is impossible, traffic goes through Tailscale's relay servers, still end-to-end encrypted.
Typical commands:
tailscale up # join the tailnet
tailscale status # list devices and how they connect
tailscale up --advertise-exit-node # offer this machine as an exit node
tailscale serve --bg 9000 # share localhost:9000 with your tailnet over HTTPS
tailscale funnel 9000 # publish it to the internet instead
tailscale file cp report.pdf phone: # Taildrop a file to another device
- Identity: sign-in goes through an existing provider: Google, Microsoft, GitHub, Apple or an OIDC provider.
- Access rules: a JSON-based policy file with grants, groups and tags.
- Tagged and ephemeral devices: for servers and CI jobs, which join without a person's identity and disappear when done.
- On a router: the GL.iNet Brume 2 runs Tailscale natively, so the whole LAN can sit behind 1 subnet router.
Value
My home setup is a set of machines that only make sense together: the Mac Studio running NicAI and my local apps, the NAS, the Linux mini PC, and the GL.iNet gear. Tailscale is the simplest way to reach all of it from my phone or a hotel without opening a single port.
The first use I'd set up: tailscale serve for my local app dashboard on port 9000, so I can start and stop my tools from the phone. The second: the Brume 2 as subnet router, so the NAS is reachable without installing anything on it (see GL.iNet Brume 2 (GL-MT2500) ). For remote control of machines, the same idea sits behind the IP-KVM setup in GL.iNet Comet KVM .
Further Reading


