Full-Time
WireGuard-based VPN for secure remote access
No salary listed
Remote in USA
Remote
Remote within the United States.
Find people who can refer or advise you
Tailscale provides secure remote access by offering a WireGuard-based VPN that lets teams and individuals reach private resources such as virtual machines, containers, and databases from anywhere. The product works by creating a secure, encrypted network between devices so users can access private resources as if they were on a local network; setup is designed to be simple, and the service includes many integrations (over 100) to fit into various tech stacks. The company differentiates itself with a freemium model that lowers the barrier to entry, a focus on ease of use with minimal setup, and strong data security to protect all connections, along with features that support cross-cloud and multi-resource environments. Tailscale’s goal is to make secure remote access easy to deploy and manage for both organizations of any size and individual users, enabling safe data transfer and collaboration across diverse infrastructure.
Company Size
201-500
Company Stage
Series C
Total Funding
$275M
Headquarters
Toronto, Canada
Founded
2019
Find people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Flexible Work Hours
Remote Work Options
Unlimited Paid Time Off
Parental Leave
Professional Development Budget
Home Office Stipend
Phone/Internet Stipend
Company Equity
TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access. By jervant Tuesday, July 14, 2026 Hacker News Front Page Tailscale has patched a critical vulnerability in its SSH implementation where insecure argument handling allowed authenticated users to gain unauthorized root access. This underscores a rare lapse in the company's "zero trust" architecture; the bug effectively bypassed intended permission layers, highlighting that eve Hacker News Front Page
For Tailscale, good feedback is private feedback. Turns out the Insider badge is a leash and one word is enough to get you kicked. Note: This post is not meant to hate on Tailscale or its members. It's just my own thoughts about my experience being an Insider. I am not going to share any of the people's names I interacted with nor its private chats. Tailscale is an amazing product. I have been using it for almost 4 years and I can't go back to the traditional Wireguard setup. I really don't have anything negative to say about the product itself. I am generally a person that likes to socialize online, specifically chat and sometimes argue with strangers about things I am interested in. I like joining the communities of the projects I use and that's what I did with Tailscale. I had been interested in becoming an insider for a long time but unfortunately my original application didn't get accepted. However after a random chat with one of their Community Managers, I got in the Insider program. The Insider program was cool, a lot of cool people that were actually interested in helping you try out new Tailscale features. Genuinely a fun experience. Unfortunately due to my other projects I didn't have time to contribute code but I did try to help as much as possible by testing out new features and providing feedback. One day, Tailscale released their border0 integration (quite a cool product) and announced their free trial waitlist. Sounded cool, so I went to sign-up and noticed something weird. The sign-up form had the following note in the bottom: By continuing, I agree to receive news, offers, information about Tailscale products and services, and invitations to surveys, webinars and events from Tailscale. You can unsubscribe at any time. For more information, please see its Privacy Policy. Now, I am generally not a crazy privacy advocate, but I was surprised since I have only seen such practices being utilized by less trusted companies in order to achieve some cheap advertising. Turns out that under GDPR Article 7 paragraph 4 this small note may be illegal. The GDPR states: When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. Which in other words means that if a company is forcing you to share your personal data to get access to a service and that data is not needed by the company to provide you that service, then the company essentially forces you to either agree to the advertising or prohibits you from using the service. Now for Tailscale, I trust that they are an honest company and that they would use the email only for their own marketing but, since they link their privacy policy, they can very much state that they may share the data with whoever they want (not saying they do, but that doesn't mean that it's not possible). First instinct was to let them know about it, so I shared the following messages in their new border0 channel: * form text quote I get the marketing part but to be honest I would like for this to be a checkbox. * It's a bit...sneaky? What I didn't expect was getting messaged by a moderator. The moderator instead of focusing on the feedback, focused on the word "sneaky" stating that it violates the Insider CoC and that it can reputational harm for Tailscale. I couldn't really believe what I was reading because...why would I want to cause any kind of damage to Tailscale? There are a lot of ways to make such a small issue a big fuss and actually cause reputational harm, but my message wasn't that. I generally text in a very lax style and my messages never intend to be harsh or aggressive, just more to the fun side (maybe I should start using /s more). In any case, I answered to the moderator that I of course don't intend to cause any damage to Tailscale - why would I be an Insider if that was my plan? - but at the same time I don't believe that simply sharing my feedback publicly is bad. Sure, I am an Insider, but that doesn't say anything about me. I don't work at Tailscale, I am not part of their staff, I am just a guy with a badge that happens to try out new features faster than others. Never got a reply so I thought that it was just a bad day for the moderator and left it there. In the following days I received a message from one of their Community Managers saying that I had been removed from their Insider program because my idea of an Insider didn't align with theirs...what? This message caught me off guard, I never expected this to escalate to such level for a simple feedback message. Is that really a basis to remove someone from an Insider program? Is sharing its opinion publicly suddenly bad because Doesmycode.work has a stupid badge next to its purple name? Are Doesmycode.work supposed to praise Tailscale for their every move and do damage control for free? These are the questions I asked the responsible Community Manager but I unfortunately never got an answer. The saddest thing is not that I got removed from the Insider program, but rather that they didn't even fix the issue. Raised the issue on 2026-06-25 and to this day (2026-07-04) they haven't changed a single thing. These are not the kind of issues you let collect dust for weeks, especially when the law might be involved. This isn't a post targeting the Community Manager or the moderator but rather it criticizes the way the entire Insider program works. Doesmycode.work shouldn't focus on the way feedback is being communicated (as long as its purpose is not to cause harm) but rather on the feedback itself. Just because Doesmycode.work get access to an Insider program doesn't mean Doesmycode.work lose the right to communicate its thoughts publicly.
Highflame, an AI security company, has partnered with Tailscale to provide real-time security evaluation of AI agent activity at the network layer. The integration allows organisations to monitor AI interactions and assess risks across prompts, tools and outputs without altering developer workflows. The solution combines Tailscale's Aperture gateway, which routes and captures AI traffic telemetry, with Highflame's platform that analyses interactions to detect prompt injection, credential leakage, PII exposure and policy violations. The system operates without requiring SDKs or instrumentation, enabling developers to continue using preferred tools whilst security teams gain centralised visibility. Aperture is currently in alpha and available to early users. Highflame is backed by leading investors and headquartered in the San Francisco Bay Area.
Today I’m excited to share that Border0 has been acquired by Tailscale.When we started Border0, the goal was simple: make infrastructure access secure without making it painful.Anyone who has worked in infrastructure knows the problem. Engineers are often forced to juggle multiple VPNs, bastions, static credentials scattered across systems, and tools that were never really designed to work well together.We believed there had to be a better way.So we built Border0, a modern approach to Privileged Access Management (PAM), designed specifically for modern engineering teams and focused on making secure access simple and practical.Over the past few years we’ve been fortunate to see Border0 grow beyond what we initially imagined. Teams around the world now rely on Border0 for secure access to SSH, Kubernetes, databases, web apps, and RDP.Today marks the beginning of the next chapter.
Tailscale makes first acquisition with Border0 purchase. Corporate VPN startup will expand Vancouver footprint as it absorbs entire Border0 team. Toronto-based corporate virtual private network (VPN) startup Tailscale has made its first acquisition as it aims to improve its application security layer. Tailscale announced on Tuesday morning that it has purchased Border0, a Vancouver-based privileged access management (PAM) security platform. PAM helps companies manage who or what has access to sensitive digital infrastructure, like production systems or databases. Border0's entire seven-person team is joining Tailscale, which is expanding its engineering footprint in Vancouver with a larger office. Tailscale spokesperson Will Moore told BetaKit in an email that the company already had "foundational PAM-style capabilities," but that Border0 adds deeper application-layer access and authorization on top of that foundation. "The acquisition helps us move faster on building out a more complete and modern PAM offering," Moore said. The terms of the deal were not disclosed. Border0's entire seven-person team is joining Tailscale, including Border0 founder Andree Toonk, who becomes the director of engineering to focus on building out Tailscale's privileged access management capabilities, Moore said. Moore added that, with the acquisition, Tailscale is expanding its engineering footprint in Vancouver with a larger office. While Moore said Tailscale doesn't have a hiring target for the city, the company is looking to increase its headcount globally from 250 to 400 employees over the next year. Founded in 2019 by former Google software engineers, Tailscale helps companies and individuals secure and control their data with its zero-configuration VPN, which can be installed on any device, manages firewall rules for users, and works from anywhere. One of Tailscale's key selling points is its software's accessibility, which enables people and teams to securely access network services without the long setup times and complexity of traditional VPNs. It's this accessibility that meshes so well with Border0, Tailscale CEO Avery Pennarun said in a blog post. While Tailscale's platform handles system access features like connectivity, identity-based permissions, and network layer auditability, Pennarun said that Border0 brings protocol-aware controls, session visibility, and approval workflows. Once you move from 'Can this machine reach that machine?' to 'Who should be allowed into this database, cluster, or admin interface, for how long, and with what visibility into what happened after they got there?', the problem changes shape a bit," Pennarun wrote. "Those are exactly the kinds of things that are hard to bolt on later, and even harder to do well without making the whole system miserable to use," Pennarun added. Tailscale's customer base has grown rapidly since 2024, partly due to the explosion of agentic AI. The new market has found significant value using Tailscale's platform to act essentially as an air traffic control system for agents accessing and acting on corporate data. Last April, Tailscale raised $160 million USD ($230 million CAD) in Series C funding to grow its team and keep up with the "surprising number" of AI companies using its software. Following the purchase of Border0, Moore didn't rule out future acquisitions from Tailscale, but said the company is focused on building with the Border0 team for the time being. Feature image courtesy Tailscale.