{
  "slug": "tailscale",
  "category": "mesh-vpns",
  "name": "Tailscale",
  "description": "Mesh VPN built on WireGuard that connects devices into a private network using a hosted coordination server for key exchange and access control, with open-source clients.",
  "website": "https://tailscale.com",
  "source": "https://github.com/tailscale/tailscale",
  "license": "BSD-3-Clause",
  "platforms": [
    "windows",
    "macos",
    "linux",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "CA",
    "name": "Canada",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": null
  },
  "pick": true,
  "pick_reason": "A WireGuard mesh for Windows, macOS, Linux, Android and iOS, with NAT traversal and DERP relays when a direct connection fails. Keys are created on each device, so the coordination server and relays never see traffic. The clients are open source under BSD-3-Clause, ACLs and SSO come built in, and the open-source Headscale server can replace the hosted coordination server for full self-hosting.",
  "disclosure": null,
  "grade": "D",
  "score": 50,
  "coverage": 100,
  "summary": "Tailscale scores 50 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: keys stay on devices. It partly meets open source, no ads or data sales, independent audit, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry. It is based in Canada: Five Eyes member.",
  "url": "https://privacyratings.com/mesh-vpns/tailscale/",
  "markdown": "https://privacyratings.com/mesh-vpns/tailscale/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://tailscale.com/opensource",
      "note": "The client daemon is BSD-3-Clause, but the Windows, macOS and iOS GUIs and the hosted coordination server are closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://tailscale.com/privacy-policy",
      "note": "The website uses third-party analytics and advertising cookies, and client logging is on by default with an opt-out."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://tailscale.com/pricing",
      "note": "Funded by paid plans with no ads in the product, though the website shares cookie data with ad partners for Tailscale's own marketing."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://tailscale.com/security",
      "note": "Latacora conducts regular security audits, but the reports are only available on request."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "device_keys": {
      "title": "Keys stay on devices",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://tailscale.com/blog/how-tailscale-works",
      "note": "Each device creates its own WireGuard key pair. The private key never leaves the device, and DERP relays only forward encrypted packets."
    },
    "self_hosted_control": {
      "title": "Self-hosted coordination server",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://tailscale.com/opensource",
      "note": "Tailscale's coordination server is closed source. The clients can use the open-source, community-maintained Headscale server instead."
    },
    "no_connection_logs": {
      "title": "No connection logs by default",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://tailscale.com/kb/1011/log-mesh-traffic",
      "note": "Clients send logs to Tailscale by default, including connection open and close events. The --no-logs-no-support flag or TS_NO_LOGS_NO_SUPPORT turns this off."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:38:30.978Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}