Mesh VPNs and private networks
ionscale privacy rating
Open-source, self-hosted Tailscale control server with support for multiple tailnets, OIDC login, ACLs and DNS, used with the official Tailscale clients.
Summary
ionscale scores 76 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices and self-hosted coordination server. It does not meet independent audit. Still needing evidence: no connection logs by default.
Score 76 out of 100. How scoring works
Criteria
- Yes
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
No third-party trackers. The documentation site's Plausible analytics are cookieless and aggregate-only.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Free community project with no ads or data sales.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
Yes
Keys stay on devices Weight 3 of 3
Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?
Works with the official Tailscale clients, which create WireGuard keys on each device. The control server only exchanges public keys.
-
Yes
Self-hosted coordination server Weight 2 of 3
Can the coordination or control server be self-hosted with open-source software?
The whole control server is open source and self-hosted.
-
Unknown
No connection logs by default Weight 2 of 3
Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?
Needs evidence. Add it