Privacy Ratings

Mesh VPNs and private networks

Headscale privacy rating

Our pick

Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service.

License: BSD-3-ClausePlatforms: Linux

Summary

Headscale scores 82 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices and self-hosted coordination server. It partly meets no connection logs by default. It does not meet independent audit.

Score 82 out of 100. How scoring works

Criteria

  • Yes

    Open source Weight 3 of 3

    Is all the source code needed to run the product public?

    BSD-3-Clause.

    github.com

  • Yes

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    No telemetry or analytics in the source code, and the website loads no trackers.

    github.com

  • Yes

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Free community project with no ads or data sales.

    github.com

  • No

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    No independent audit is published.

  • Yes

    Keys stay on devices Weight 3 of 3

    Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?

    Works with the official Tailscale clients, which create WireGuard keys on each device. The control server only exchanges public keys.

    github.com

  • Yes

    Self-hosted coordination server Weight 2 of 3

    Can the coordination or control server be self-hosted with open-source software?

    The whole control server is open source and self-hosted.

    github.com

  • Partial

    No connection logs by default Weight 2 of 3

    Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?

    Headscale tells clients not to upload logs by default, but official Tailscale clients still contact log.tailscale.com at startup until TS_NO_LOGS_NO_SUPPORT is set.

    github.com

Other mesh VPNs and private networks

All 17 mesh VPNs and private networks