Self-hosted · zero-trust · agentless

Privileged access management.
No credentials handed out.

Scoped, time-boxed access to any server, cluster or database: granted per session, never standing. The credential stays sealed on the broker, and every session is recorded.

One broker for SSHKubernetesDatabasesRDPOIDC SSOSCIM

ssh app-prod-01.tessera.local

→ connecting to app-prod-01 …

Last login: Sun Aug 17 16:04:11 2026 from 10.0.0.4

[tessera] Read-only session — the following commands are blocked:

apt, chmod, chown, dd, mv, rm, shutdown, systemctl, useradd

also blocked: scripts, output redirection (> / >>), sftp/scp.

root@app-prod-01:~$ rm -rf /var/log/api

[tessera] blocked — 'rm' is not allowed in read-only mode

root@app-prod-01:~$

Runs on your infrastructure — wherever it lives

How it works

How Tessera brokers SSH, Kubernetes, database and RDP access

Most teams run a bastion host, SSH keys handed out by configuration management, and a spreadsheet of who holds which key that stays accurate until somebody leaves. Tessera replaces all three with one broker, and changes nothing about how engineers connect.

Engineer SSH · k8s · DB · RDP
Tessera broker roles · approval · injection
Target server · cluster
  1. 01

    Connect like always

    Click Connect and keep using your normal SSH, kubectl, SQL and RDP tools. No new workflow to learn.

  2. 02

    Tessera grants & injects

    The broker checks the user's role and any just-in-time approval, then injects the real credential on the wire. For SSH, Kubernetes and databases the secret never touches the laptop.

  3. 03

    Every session is on the record

    Commands, queries and full replay land in an append-only log and stream to your SIEM as they happen — compliance evidence, automatically.

Live demo

Try the live demo: sample infrastructure, real sessions

The same console a customer gets, loaded with sample infrastructure: fourteen targets, nine people, sixty past sessions and six real recordings. Two engineers are connected to production in it right now, and you are the administrator.

  • Take write access away from an engineer who is typing, and watch the next write get refused — same connection, no reconnect.
  • Open session shadowing on a live terminal and read along, including what the broker stopped.
  • Revoke a grant and watch the sessions it justified close themselves, then find it in the audit.
Open the demo
The Tessera console with two active SSH sessions and a live terminal open on one of them Open it
For your ISO 27001 or SOC 2 audit

The evidence an auditor asks for, not a compliance claim

Tessera is not certified against ISO 27001 or SOC 2, and self-hosting a tool does not make your company compliant. Both frameworks ask an auditor to test whether specific controls operated across the review period, on evidence rather than a policy document. That evidence is what the audit log produces.

  • Who had access, on a date you name Grants and revocations are recorded as events when they happen, not merely reflected in the current state. A question about last March gets answered about last March.
  • The approval, not the policy A just-in-time request carries its reason, its decision and its approver into the log. The artefact is the grant itself, not a document saying that approval is required.
  • The session, not a summary Commands, database queries and full replay of a named session. Enough to answer what was actually run, rather than only who connected and when.
  • A copy outside the broker Events are posted to your SIEM as they happen, putting a copy outside the broker. Delivery is best-effort and never blocks a session, so it is a second copy rather than a replacement.

The per-command and database query logs are in every edition, Community included. Just-in-time approval and session replay start at Pro, the SIEM stream at Ultimate. Full split in the editions table.

Capabilities · SSH · Kubernetes · Databases · RDP

RBAC, just-in-time access and session recording, in one broker

Keyless SSH

One click to any server. The broker injects the credential, so nothing sits on a laptop to lose or rotate.

Kubernetes, brokered

Add a cluster once. Your team keeps its existing kubectl workflow, and every call is audited.

Databases, brokered

PostgreSQL and MySQL, credentials injected. Read-only is enforced at the SQL layer, not merely requested.

Windows over RDP

Brokered RDP to Windows hosts. The credential goes to the native client over stdin, never shown and never written to disk.

Just-in-time access

No standing access. Engineers request what they need, you approve in one tap, and the grant expires by itself.

Recorded & watched live

Full replay and per-command history. Shadow a live session and force-close it the moment something looks wrong.

Live roles, audited to SIEM

Downgrade a live session to read-only with no reconnect. Every login, command and approval streams to your SIEM.

Built to be trusted

How Tessera protects credentials and enforces least privilege

Tessera is the control point between your engineers and production, so it is built to earn that position.

Self-hostedOffline-licensedAES-GCMThreat-modeled
Read the security model →
  • Credentials stay on the brokerEncrypted at rest and injected on the wire for SSH, Kubernetes and databases: nothing to leak, screenshot or forward. RDP is the exception, because the protocol needs the credential before the session exists, so it goes to your local client, never appears in the UI, and every issuance is audited.
  • Read-only where it countsKubernetes and SQL read-only are enforced at the protocol layer: writes and DDL are rejected before they reach the cluster or the database. On SSH, command filtering is a guardrail rather than a hard guarantee, so for that, point Tessera at a read-only OS account. An admin can downgrade or kill a live session instantly.
  • Self-hosted, nothing phones homeOne Go binary plus Postgres, on any cloud or on bare metal, inside your perimeter and agentless on your targets. The audit log is append-only, and even licensing is verified offline.
Why Tessera

Tessera vs Teleport, StrongDM and Boundary

Most access tools control who can connect. Tessera also controls what happens once you're inside the session.

Tessera Teleport StrongDM Boundary
Where Tessera goes further
Kill write access mid-session — no reconnect flip a live session RW → RO in one tap — on SSH, Kubernetes and SQL alike
Nothing installed — and nothing reconfigured — on your targets your servers, clusters and databases stay exactly as they are
Fully self-hosted control plane no vendor cloud anywhere in the access path
One read-only switch across SSH · Kubernetes · SQL same policy, every protocol — not a per-protocol reimplementation
And everything you'd expect
Credentials injected on the controller — never on the user's machine SSH · Kubernetes · SQL
Session recording + live watch & force-close
Just-in-time access · RBAC · SSO · SCIM
Audit export to your SIEM

Checked against each vendor's own published documentation on 14 August 2026; products change, so verify before relying on it. A cross means the vendor does not document the capability, not that we tested it and it failed. A half-circle means partial: supported with limits or with extra setup. Capabilities vary by edition, and the edition-by-edition detail for each vendor is on its own comparison page below.

Row by row, with where each of them beats us: Tessera vs Teleport Tessera vs StrongDM Tessera vs Boundary

Pricing

Community, Pro, Ultimate and Enterprise pricing

Free to self-host, forever. Pay per seat only when you need the team controls: predictable, and an easy win against tools that charge per server.

Community

$0 self-hosted · 1 seat · free forever
Get started
  • Single seat — one admin account; add seats on any paid plan
  • 5 SSH · 1 Kubernetes · 1 database · 5 RDP targets
  • Keyless connect with credential injection
  • TOFU host-key pinning · stable target names
  • Audit log — events & commands (no session replay or live watch)
  • Governance controls unlock in Pro
Most popular

Pro

$19 / seat / mo · $15 billed annually · from 3 seats
Start with Pro
  • Everything in Community
  • RBAC + live RW/RO · just-in-time access
  • Session recording + live watch & force-close
  • SSO (OIDC) · Telegram alerts · bastions
  • Up to 100 targets · 50 concurrent sessions
Launch · $30 annual

Ultimate

$40 / seat / mo · $36 billed annually · from 3 seats
Go Ultimate
  • Everything in Pro
  • SCIM provisioning & white-label branding
  • SIEM / audit export + database query audit
  • Configurable Kubernetes & database policies
  • Unlimited targets & connections

Enterprise

Custom contact sales · volume pricing
Talk to us
  • Everything in Ultimate
  • Custom features & integrations built for your environment
  • Dedicated SLA & priority support
  • Procurement & security review · volume pricing

Pay yearly and save up to 20% vs. monthly. Launch offer: start an annual Ultimate plan within the first 6 months and lock in $30/seat/mo instead of $36. Bigger teams and multi-year terms get deeper discounts.

Self-hosted privileged access management,
free to start.

Deploy Tessera in minutes and broker your first connection today.