Full-Time
Updated on 9/4/2026
WireGuard-based VPN for secure remote access
CA$134k - CA$174.2k/yr
Remote in Canada
Remote
See people who can refer or advise you
Tailscale provides secure remote access by offering a WireGuard-based VPN that lets teams and individuals reach private resources such as virtual machines, containers, and databases from anywhere. The product works by creating a secure, encrypted network between devices so users can access private resources as if they were on a local network; setup is designed to be simple, and the service includes many integrations (over 100) to fit into various tech stacks. The company differentiates itself with a freemium model that lowers the barrier to entry, a focus on ease of use with minimal setup, and strong data security to protect all connections, along with features that support cross-cloud and multi-resource environments. Tailscale’s goal is to make secure remote access easy to deploy and manage for both organizations of any size and individual users, enabling safe data transfer and collaboration across diverse infrastructure.
Company Size
201-500
Company Stage
Series C
Total Funding
$275M
Headquarters
Toronto, Canada
Founded
2019
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Flexible Work Hours
Remote Work Options
Unlimited Paid Time Off
Parental Leave
Professional Development Budget
Home Office Stipend
Phone/Internet Stipend
Company Equity
Tailscale expands from VPN into full connectivity platform. Application Infrastructure August 31, 2026 Highlights. * Tailscale is expanding beyond its original VPN product with new services introduced at its Tailscale Up conference. * The new offerings include DNS Filtering by Control D, Tailscale PAM, Aperture, Aperture Plus, Tailcat, and developer APIs and SDKs. * Tailscale said its identity-based access model now supports services for DNS control, privileged access, AI agents, and software development. Tailscale, which began in 2019 as a VPN provider based on open-source WireGuard technology, is moving beyond its original VPN pitch with a series of new products. The company raised $160 million last year to expand its WireGuard-based VPN platform and used its Tailscale Up conference last week to introduce new services built on identity-based access. Tailscale ties access to a device or user identity rather than to an IP address and applies policy based on that identity to determine what can be reached. The company said that model now underpins a broader set of tools, including DNS Filtering by Control D, Tailscale PAM, Aperture, Aperture Plus, Tailcat, and developer APIs and SDKs. DNS Filtering by Control D is sold and managed through existing Tailscale policy to block malicious and unapproved destinations. Tailscale PAM, now in beta, adds credential injection and just-in-time access for sensitive infrastructure. The company said it acquired Border0 in March 2026, and that Tailscale PAM lets teams grant one-click access to servers, databases, Kubernetes clusters, and web applications without handing out standing passwords or API keys. Aperture is Tailscale's AI gateway and reached general availability at the event. It gives AI agents an identity on a tailnet and routes their model calls and tool use through Tailscale's private network rather than the open internet. Aperture Plus extends the same access model into a browser, works without installing Tailscale as a system-level VPN, and isolates each session. Tailscale also introduced SDKs for Rust, Python, C, C++ and Elixir, along with a Tailnet Creation API and declarative tailnet sharing. company spotlight SoftIron. SoftIron makes the products that underpin the next evolution of IT infrastructure. Its blueprint is radical. Taking full control over design and manufacture of platforms optimised to transform IT infrastructure, its highly integrated products reduce space and energy footprints while delivering extraordinary performance. Challenging traditional IT manufacturing & organisational strategy, IT Infrastructure has developed a model that enables IT Infrastructure to create a more resilient and connected business for the customers IT Infrastructure serve. A commitment to openness, transparency, and simplicity helps address emerging multi-faceted threats while eliminating the vendor "lock-in" so common elsewhere.
Tailscale Open sources Tailcat, WireGuard netcat alternative. 1h ago Open Source Tl;dr. Tailscale releases Tailcat, a userspace tool combining WireGuard encryption and NAT traversal without requiring Tailscale's control plane, enabling encrypted peer-to-peer connections via simple token exchange. Key points. * Tailcat reuses Tailscale's magicsock (NAT traversal), userspace WireGuard, and gVisor netstack without requiring control plane or root access * Connection tokens encode server's WireGuard key and DERP relay info; clients bootstrap through DERP, upgrade to direct P2P UDP when possible
Tailscale launches DNS filtering add-on with Control D. Thu, 27th Aug 2026 (Today) Tailscale has launched a DNS filtering add-on for business customers in partnership with Control D. The product is called DNS Filtering by Control D. The add-on lets organisations block malicious, phishing and unwanted domains across users and devices, while applying different filtering profiles through Tailscale policy. Customers can buy the service through Tailscale instead of managing a separate purchasing process. The launch expands the companies' existing relationship and targets a growing security concern for distributed workforces. DNS filtering works when a device requests the address of an internet destination, giving administrators a way to block access before a connection is established. The issue has grown more important as staff connect from home networks, public networks and mobile devices rather than only through office infrastructure. The companies also pointed to automated workloads and AI agents as another area where organisations want tighter control over which outside destinations systems can reach. The Anti-Phishing Working Group recorded more than 970,000 phishing attacks in the first quarter of 2026, up 14% from the previous quarter, according to figures cited by the companies. They also pointed to recent attacks in which compromised home and small-office routers were used to hijack DNS requests. How It Works Organisations can create filtering policies in Control D and assign them through Tailscale policy based on user groups, tags and device attributes. A company could apply one rule set to employees, another to contractors and another to tagged machines running automated tasks. The filtering follows devices connected through Tailscale rather than relying on traffic passing through a central office network. DNS queries are sent directly from the device to Control D using DNS-over-HTTPS, an encrypted method for handling requests. Customers continue to manage blocklists, category filters, exceptions and DNS activity through the Control D dashboard. Organisations that already buy Control D separately can continue using the existing integration. Tailscale placed particular emphasis on DNS controls for AI systems that can browse the web, call application programming interfaces or download software without direct human action. In that setting, administrators may want to limit external destinations for the same reasons they do for employees. "AI agents are just another thing on the network, except they can make a lot of decisions very quickly," said Avery Pennarun, Co-founder and CEO, Tailscale. "If they can browse the web, call APIs, or download software, you need clear limits on where they can go. Tailscale provides the identity and policy context, and Control D can stop connections to known malicious or unapproved domains before they start. That gives organizations a practical guardrail for both people and agents without inspecting the contents of encrypted traffic." Control D said the combined approach brings identity and network policy together in one framework for customers already using Tailscale to manage access. "Tailscale already knows who a user or agent is, what device they're using, and what policy applies to them. Control D is really good at deciding which destinations should and shouldn't be reachable. Putting those together means customers don't have to maintain two separate policy worlds. The same identity that decides what you can connect to can also help decide where you're allowed to connect," said Catt Garrod, COO, Control D. Market Position Tailscale said it is used by more than 30,000 businesses globally, including large technology groups and media companies. Founded in 2019, the company focuses on private network access and identity-based controls built around WireGuard. Control D was spun out of Windscribe in 2021 and is based in Toronto. It sells DNS filtering and security tools to businesses, schools and managed service providers, and said its platform applies policies across major operating systems. The new add-on is available to existing Tailscale business customers through their account teams. Organisations new to Tailscale can register interest to be contacted.
TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access. By jervant Tuesday, July 14, 2026 Hacker News Front Page Tailscale has patched a critical vulnerability in its SSH implementation where insecure argument handling allowed authenticated users to gain unauthorized root access. This underscores a rare lapse in the company's "zero trust" architecture; the bug effectively bypassed intended permission layers, highlighting that eve Hacker News Front Page
For Tailscale, good feedback is private feedback. Turns out the Insider badge is a leash and one word is enough to get you kicked. Note: This post is not meant to hate on Tailscale or its members. It's just my own thoughts about my experience being an Insider. I am not going to share any of the people's names I interacted with nor its private chats. Tailscale is an amazing product. I have been using it for almost 4 years and I can't go back to the traditional Wireguard setup. I really don't have anything negative to say about the product itself. I am generally a person that likes to socialize online, specifically chat and sometimes argue with strangers about things I am interested in. I like joining the communities of the projects I use and that's what I did with Tailscale. I had been interested in becoming an insider for a long time but unfortunately my original application didn't get accepted. However after a random chat with one of their Community Managers, I got in the Insider program. The Insider program was cool, a lot of cool people that were actually interested in helping you try out new Tailscale features. Genuinely a fun experience. Unfortunately due to my other projects I didn't have time to contribute code but I did try to help as much as possible by testing out new features and providing feedback. One day, Tailscale released their border0 integration (quite a cool product) and announced their free trial waitlist. Sounded cool, so I went to sign-up and noticed something weird. The sign-up form had the following note in the bottom: By continuing, I agree to receive news, offers, information about Tailscale products and services, and invitations to surveys, webinars and events from Tailscale. You can unsubscribe at any time. For more information, please see its Privacy Policy. Now, I am generally not a crazy privacy advocate, but I was surprised since I have only seen such practices being utilized by less trusted companies in order to achieve some cheap advertising. Turns out that under GDPR Article 7 paragraph 4 this small note may be illegal. The GDPR states: When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. Which in other words means that if a company is forcing you to share your personal data to get access to a service and that data is not needed by the company to provide you that service, then the company essentially forces you to either agree to the advertising or prohibits you from using the service. Now for Tailscale, I trust that they are an honest company and that they would use the email only for their own marketing but, since they link their privacy policy, they can very much state that they may share the data with whoever they want (not saying they do, but that doesn't mean that it's not possible). First instinct was to let them know about it, so I shared the following messages in their new border0 channel: * form text quote I get the marketing part but to be honest I would like for this to be a checkbox. * It's a bit...sneaky? What I didn't expect was getting messaged by a moderator. The moderator instead of focusing on the feedback, focused on the word "sneaky" stating that it violates the Insider CoC and that it can reputational harm for Tailscale. I couldn't really believe what I was reading because...why would I want to cause any kind of damage to Tailscale? There are a lot of ways to make such a small issue a big fuss and actually cause reputational harm, but my message wasn't that. I generally text in a very lax style and my messages never intend to be harsh or aggressive, just more to the fun side (maybe I should start using /s more). In any case, I answered to the moderator that I of course don't intend to cause any damage to Tailscale - why would I be an Insider if that was my plan? - but at the same time I don't believe that simply sharing my feedback publicly is bad. Sure, I am an Insider, but that doesn't say anything about me. I don't work at Tailscale, I am not part of their staff, I am just a guy with a badge that happens to try out new features faster than others. Never got a reply so I thought that it was just a bad day for the moderator and left it there. In the following days I received a message from one of their Community Managers saying that I had been removed from their Insider program because my idea of an Insider didn't align with theirs...what? This message caught me off guard, I never expected this to escalate to such level for a simple feedback message. Is that really a basis to remove someone from an Insider program? Is sharing its opinion publicly suddenly bad because Doesmycode.work has a stupid badge next to its purple name? Are Doesmycode.work supposed to praise Tailscale for their every move and do damage control for free? These are the questions I asked the responsible Community Manager but I unfortunately never got an answer. The saddest thing is not that I got removed from the Insider program, but rather that they didn't even fix the issue. Raised the issue on 2026-06-25 and to this day (2026-07-04) they haven't changed a single thing. These are not the kind of issues you let collect dust for weeks, especially when the law might be involved. This isn't a post targeting the Community Manager or the moderator but rather it criticizes the way the entire Insider program works. Doesmycode.work shouldn't focus on the way feedback is being communicated (as long as its purpose is not to cause harm) but rather on the feedback itself. Just because Doesmycode.work get access to an Insider program doesn't mean Doesmycode.work lose the right to communicate its thoughts publicly.